PRIMARY FUNCTION:
Design, implement, audit, and maintain governance, risk management, and compliance (GRC) controls for the organization’s information security program aligned to the National Institute of Standards and Technology (NIST), the Center for Internet Security (CIS), and the International Organization for Standardization (ISO) 27000 family of frameworks. Drive policy, risk assessments, third party risk, audit readiness, and continuous compliance with regulatory and industry standards, using an organized and project managed approach.