Risk Management Specialist

Posted 1hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Risk management specialist strengthening Prosci’s information security, privacy, and PCI compliance programs. Coordinating ISO 27001 audits, risk assessments, privacy operations, and client assurance.

Responsibilities:

  • Support and strengthen risk management and information security programs
  • Support deployment and continuous improvement of information security policies, standards, and technical controls
  • Coordinate Prosci’s ISO 27001:2022 certification and audit activities, including scheduling, evidence collection, and external auditor coordination
  • Administer compliance tooling such as Vanta
  • Facilitate ISMS Governance Council activities, maintain the enterprise risk register, and report on risk posture
  • Conduct information security risk assessments for vendors, projects, and business changes
  • Track, report, and support remediation of control gaps and audit findings
  • Define and monitor information security metrics
  • Advise stakeholders and partner cross-functionally on secure business practices
  • Support implementation and management of Prosci’s global data privacy program
  • Monitor alignment with GDPR, CCPA, PIPEDA, LGPD, and other applicable privacy regulations
  • Partner with Legal and stakeholders to apply privacy requirements to business operations
  • Coordinate data subject request processes and responses
  • Maintain privacy policies and external privacy notices
  • Support employee privacy training and awareness
  • Support PCI DSS compliance for outsourced, card-not-present payments under SAQ A scope
  • Maintain PCI scope documentation and SAQ A eligibility
  • Oversee third-party service providers, vendor inventories, and compliance status
  • Support PCI assessments, evidence collection, remediation tracking, and reporting
  • Provide PCI guidance and training
  • Coordinate PCI compliance activities with internal and external parties
  • Support client assurance activities, including security questionnaires and compliance documentation
  • Develop and execute structured risk evaluation for projects and business changes
  • Review initiatives for information security and data privacy risks and escalate findings
  • Provide governance forums with updates on risk posture and emerging concerns

Requirements:

  • Fluent/Native English
  • Ability to work independently and prioritize multiple risks and adapt to needed changes
  • Ability to work with all levels of management/team members
  • Ability to assume responsibility for work
  • Ability to pull together disparate pieces of information to analyze risk
  • Attention to detail and strong organizational skills
  • Analytical thinking
  • 4–7 years’ experience in Risk Management
  • Knowledge of US/international data privacy regulations
  • Experience with implementation for/maintenance of ISO 27001 certification
  • Experience with risk evaluation of new projects and vendors
  • Experience creating risk management solutions
  • Experience reviewing client DPA and security agreements
  • Bachelor’s degree
  • CIPM Certification
  • Applications and CVs must be submitted in English