Lead Information Security Specialist
Experian · Heredia
Description du poste
About the role
Reporting to the Head of Information Security Policy and Standards, you will lead the identification, documentation, and implementation of Experian’s security risk and controls framework across the enterprise. The role ensures a sound security posture by designing and applying risk‑based controls and collaborating with business partners worldwide.
Key responsibilities
- Lead the security risk and control modularisation strategy, working with regional business units, central security, and IT control owners to populate the controls library.
- Maintain and update the integrated risk and control framework in line with policies, standards, industry practice, and regulations.
- Review and challenge first‑line business unit control activities, ensuring alignment with control standards and goals.
- Identify, document, and report control gaps, providing remediation recommendations.
- Compile management reports, summary analyses, and detailed presentations on the risk and controls program.
- Develop and deliver workshop content for controls implementation with owners across the enterprise.
- Map information security controls to applicable risks in the Archer GRC platform.
- Monitor internal and external risk indicators and feed them into control assurance activities.
- Standardise and automate risk and controls processes, capture stakeholder feedback, and improve engagement models.
- Support strategic projects as a subject‑matter expert for the Information Security Governance team.
Required profile
- Bachelor’s degree in Computer Science, Management Information Systems or a related field, or equivalent experience.
- 5+ years of hands‑on experience designing, implementing, and evaluating security controls.
- Proven experience with GRC tools, preferably Archer.
- Strong understanding of industry best practices such as NIST, ISO, COBIT, CMMI, OWASP and ITIL.
- In‑depth knowledge of governance, risk, and controls principles.
Required skills
- Archer GRC platform
- NIST framework
- ISO 27001/ISO standards
- COBIT
- CMMI
- OWASP
- ITIL
- Security control design, implementation and evaluation
- Risk and control mapping
Questions fréquentes
Pourquoi signalez-vous cette offre ?
Aller plus loin
Salaires, guides et recherches au Costa Rica.
Postulez en 30 secondes
Entrez votre email pour postuler. Un compte sera cree automatiquement.
En continuant, vous acceptez nos conditions d'utilisation.
Deja un compte ? Connexion
Publie il y a 4 semaines
Expire dans 1 mois
30 vues · 0 interesses
Boostez vos chances
Importez votre CV : nous vous proposons les offres qui matchent votre profil.
Analyse de votre CV en cours...
Experian
Heredia
Offres similaires
-
Systems Engineer (Endpoint Vulnerability Remediation & Patch Management)
Moody's Corporation Heredia -
IT Support Specialist (Client‑Facing & Cross‑Platform Support)
BMNS Heredia -
Senior Front-End UI Engineer
HCLTech Heredia -
Senior Quality Engineer – Payments Platform
PowDevs -
Senior Project Manager
Zscaler