Information Risk analyst (IRPA)

Brussels  ‐ Onsite
This project has been archived and is not accepting more applications.
Browse open projects on our job board.

Description

Region: Brussels
Sector: Financial
Education: Bachelor/Master
ASAP till June 2019 minimum
Work experience: 5 years minimum
Job type: Temporary Contract Full time on site

Job description:

The Business Continuity and Assurance team within the Cyber Security Department defines, establishes and provides information assurance. The team manages regulatory adherence for security, supports security response to external RfPs, manages client queries regarding security policies/controls, provides assurance in response to client due diligence, and manages the first-line internal controls framework. These sub-functions collaborate across security capabilities, with IT and business teams and functions such as HR, Risk Management and Compliance.

What you'll do:

Based on our consolidated of IT Assets Inventory, the objective of the project is to obtain a differentiated view of business applications risk profile according to their Confidentiality, Integrity and Availability, aligned with Risk Mgt methodology:
- evaluating the inherent risk of the application from a business perspective;
- assessing separately the financial impact, the regulatory impact and the client impact in case of respectively confidentiality, integrity or availability incident;
- ultimately slotting the applications in one of the 5 buckets of different risk profile.
Assessments will be conducted through workshops with business owners of the applications, business managers, Risk Management and enterprise architects.
This project is key to support the prioritisation for the deployment of security initiatives.

Profile:

Handles standard situation by relying on existing procedures and methods, covering several but known domains of expertise.
Relies on existing processes and policies to take decisions.
Focuses on execution in his/her domain, according to defined processes and methods. Runs and maintains the operational process.
Works autonomously on standard activities or non-complex demands. Organises, co-ordinates and plans activities independently. Priorities are set by the job. Uses expertise to challenge the goals and scope of new requests and evaluates the impact of these new requirements. Knowledge of security risk management, risk governance.
Strong oral and written skills to translate complex risk requirements.
Experience with security and controls frameworks, such as ISO 27001, COBIT5, SANS Top 20 Controls and NIST Cybersecurity Framework.
Experience with audit good practice.
Knowledge of onsite risk assessments, and managing targeted risk remediation activities.

Start date
ASAP
Duration
7 months minimum
From
Harvey Nash IT Recruitment Belgium
Published at
18.10.2018
Project ID:
1651399
Contract type
Freelance
To apply to this project you must log in.
Register