IT Compliance Assistant Manager

وصف الوظيفة

Key Responsibilities:

1. Overseeing and managing compliance with relevant laws, regulations, and standards related to information technology (IT). This includes ensuring adherence to data privacy and protection regulations, IT security standards, and any specific compliance requirements applicable to ODE.

2. Developing and maintaining IT policies, procedures, and guidelines to ensure compliance with legal and regulatory requirements. This involves creating a framework that outlines best practices, risk management, and security measures for IT operations.

3. Conducting risk assessments to identify potential IT compliance risks and vulnerabilities.

4. Developing risk mitigation strategies, controls, and action plans. Monitoring and evaluating the effectiveness of controls to minimize risks.

5. Coordinating and managing internal and external IT audits, assessments, and compliance reviews. Collaborating with auditors to provide necessary documentation, evidence, and support. Addressing any identified issues or gaps and implementing corrective actions.

6. Developing and delivering IT compliance training programs to enhance employees' understanding of IT policies, procedures, and regulatory requirements. Promoting awareness of IT compliance and security best practices throughout ODE.

7. Participating in incident response activities related to IT compliance violations, data breaches, or security incidents. Collaborating with IT security engineers to investigate incidents, assess impacts, and implement appropriate remediation measures. Reporting incidents to relevant stakeholders, management, and regulatory authorities as required.

8. Generating regular reports on IT compliance activities, status, and metrics. Maintaining accurate documentation of compliance efforts, audit findings, risk assessments, and remediation actions taken.

9. Keeping abreast of evolving IT compliance regulations, industry standards, and emerging technologies. Continuously improving knowledge and skills in IT compliance through professional development and networking.

10. Collaborating with all IT functions to ensure they all comply with our policies and standards.

11. Working closely with the IT department, audit, and upper management personnel to assess potential risks with IT systems.

متطلبات الوظيفة

1. Bachelor's degree relevant to Information Technology, Computer Science/Engineering (or equivalent).

2. 4-7 years of experience in a similar position.

3. Deep understanding of relevant IT regulations, laws, and industry standards, such as data privacy and protection regulations (e.g., GDPR, PCI), and IT security frameworks (e.g., ISO 27001, COBIT, NIST, CIS). Stay updated on the evolving compliance landscape and best practices.

4. Experience in developing and maintaining IT policies, procedures, and guidelines to ensure compliance.

5. Strong attention to detail and the ability to translate complex regulations into clear, actionable policies.

6. Knowledge of audit processes and experience in managing internal and external IT audits, assessments, and compliance reviews. Understanding of audit methodologies, evidence collection, and working effectively with auditors.

7. Proficiency in IT infrastructure, systems, and security concepts. Familiarity with network architecture, access controls, incident response, and other IT-related areas.

8. Excellent communication skills to convey complex compliance concepts to various stakeholders, including executives, IT teams, and employees.

9. Knowledge of CISSP, CISM, and CRISC certification is a plus.

10. Fluent in English both spoken and written.