Cybersecurity Governance Analyst supporting Aviva's Cybersecurity program. Leading compliance activities and stakeholder collaboration in a fast-paced environment.
Responsibilities
Be the subject matter expert at a high level and respond to client/regulatory requests regarding Aviva’s Cybersecurity program.
Develop and enhance Key Risk Indicators and Key Performance Indicators in support of cybersecurity risk management initiatives and executive reporting.
Perform annual cybersecurity controls reviews and manage issues and actions for the Cybersecurity department.
Perform periodic NIST CSF self-assessments and support the development and implementation of remediation activities to resolve control deficiencies.
Support compliance with industry frameworks and standards such as PCI-DSS and ISO27001.
Work with the security education team to facilitate the execution and reporting for the phishing program and manage security awareness training assignments for our colleagues.
Generate and review content regularly for our Security Education and Awareness program.
Coordinate and lead cybersecurity awareness campaigns.
Review and update Security Policies annually, as well as draft new policies and standards where required.
Manage Aviva’s GRC solution overall and implement enhancements for Cybersecurity Governance workflow.
Ensure timely completion of assigned tasks and reporting schedules.
Promote effective security practices, technologies, and processes with stakeholder groups.
Address requests from IT and business users on security related matters and take ownership of the same to conclusion and satisfaction.
Requirements
3-5 years of experience in cybersecurity governance programs and processes, risk management and reporting.
Good knowledge of cybersecurity and technology concepts.
Knowledge and practical experience in applying security standards and frameworks (e.g. NIST, ISF, ISO, PCI DSS).
Strong written and verbal communication skills; ability to communicate cybersecurity and risk-related concepts to technical and non-technical audiences at various levels.
Demonstrated ability to establish effective working relationships and collaborative work approaches with both internal and external contacts.
Strong attention to detail and problem-solving skills.
Experience with using GRC platforms and data platforms (e.g. Archer, IBM OpenPages, Qlik).
Good understanding of the insurance or banking industries.
University degree or college diploma in Computer Science, Information Security Management, Cybersecurity Risk Management, or equivalent professional experience within Cybersecurity.
Professional designation relating to cybersecurity or IT risk (e.g. CISSP, CISA, CISM, CCSP/CCSK, GIAC, CompTIA Security+) is an asset.
Benefits
Compelling rewards package including base compensation, eligibility for annual bonus, retirement savings, share plan, health benefits, personal wellness, and volunteer opportunities.
Outstanding Career Development opportunities.
We’ll support your professional development education.
Competitive vacation package with the option to purchase 5 extra days off per year.
Employee driven programs focused on gender, LGBTQ+, origins, diversity, and inclusion.
Corporate wellness programs to support our employees’ physical and mental health.
Internship role developing skills in Information Security at Atlantic Union Bank. Engaging in real assignments and gaining practical work experience with mentoring and training.
Information Security Intern participating in security monitoring, threat analysis, and policy development. Engaging in hands - on projects to develop skills in information security operations.
Corporate Security Intern at Atlantic Union gaining practical work experience in security and safety management. Involvement with physical security systems and contributing to security strategy.
Sr. Product Cybersecurity Engineer responsible for safeguarding GM vehicle platforms against cyber threats. Collaborating with teams to implement and validate intrusion detection capabilities within vehicle architecture.
IT Security Specialist ensuring the security and stability of IT operations in Ahrensburg, collaborating with Corporate IT and Security teams to mitigate risks.
Lead management and oversight for Networks Cybersecurity Delivery Train at ESB. Collaborate with stakeholders to ensure alignment with cybersecurity strategies and regulatory compliance throughout the organization.
Cyber Security Intern at Berkshire Hathaway GUARD supporting security operations, alerts review, and vulnerability assessments. Involved in hands - on learning within a Cyber Security team environment.
Senior Principal Data Security Software Engineer developing common security software for Dell’s server and storage products. Collaborating with engineers to integrate cryptography and enhance product security.
Project Manager overseeing security systems and operations at JetBlue, directing access control and CCTV functions. Leading projects and mentoring security analyst teams throughout the process.
Manager of Security overseeing compliance with DRS Security policies at a cleared facility. Responsible for ensuring site - specific physical and Proxy security compliance and advising leadership.