Information Security Policy (ISP) Analyst at Ford Global Career Site
Dearborn, Michigan, United States -
Full Time


Start Date

Immediate

Expiry Date

29 Jan, 26

Salary

0.0

Posted On

31 Oct, 25

Experience

2 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Information Security Policies, Risk Assessments, ISO 27001/2 Standards, IT Risks and Controls, Process Improvement, Communication, Organizational Skills, Governance, Compliance, Regulatory Requirements, Quantitative Analysis, Qualitative Analysis, Policy Management Tools, Application Development, IT Security, Training

Industry

Motor Vehicle Manufacturing

Description
Facilitate the creation and modernization of information security policies, standards, procedures and guidelines Work with cross-functional and cross regional Authors and Subject Matter Experts (SMEs) with varying levels of business/technical skills Lead the Policy, Control and Risk (PCR) governance process to support risk/control changes, regulatory requirements, emerging technologies, and enterprise objectives Execute reviews to ensure proper efficacy, conciseness, and alignment Facilitate risk assessments by performing quantitative and qualitative analysis of risk data on Application and Infrastructure Risk/Control Framework Provide consultation and direction to IT and business teams pertaining to the ISP Promote ISP awareness with audience specific training and communications Partner with Authors and SMEs on communication efforts to inform Key Information Security Stakeholders of new and updated policy documents Research industry best practices and consult advisory groups Identify and implement policy process improvements, integration and automation opportunities Incorporate future policy enhancements and innovations into the Governance, Risk and Compliance (GRC) strategy Identify policy portal defects and tool enhancements Produce monthly policy operations and project metrics Support the policy exception request (PER) process, reporting and governance Established and active employee resource groups Bachelor's degree in a Technical Discipline 1-3 years of experience working with ISO 27001/2 standards, Information Security policies, or IT risks and controls Excellent verbal and written communication Strong organizational skills; able to advance multiple work streams concurrently Process improvement mindset Experience performing IT risk assessments Knowledge of application development and IT security and controls Prior experience working with GRC and Policy Management tools Understanding of Compliance and Regulatory requirements e.g. (S-Ox, HIPAA, GLBA etc.)
Responsibilities
The Information Security Policy Analyst will facilitate the creation and modernization of information security policies and lead the governance process to support risk and control changes. They will also conduct risk assessments and provide consultation to IT and business teams regarding information security policies.
Loading...