With over 70 years of experience, our focus is on helping the most vulnerable children overcome poverty and experience fullness of life. We help children of all backgrounds, even in the most dangerous places, inspired by our Christian faith.
Come join our 33,000+ staff working in nearly 100 countries and share the joy of transforming vulnerable children's life stories!
Key Responsibilities:
PURPOSE OF POSITION:
Individuals working as a Technical Director, Cybersecurity oversee the planning, execution, and management of multi-faceted projects related to compliance, control assurance, risk management, security, and infrastructure/ information asset protection. They are responsible for developing and managing security across multiple IT functional areas (e.g., data, systems, network and/or Web) across the enterprise, developing and managing enterprise security services, and developing security solutions for critical and/or highly complex assignments to ensure the company's infrastructure and information assets are protected. They work on multiple projects or programs as a team lead.
Individuals within the Cybersecurity job family plan, execute, and manage multi-faceted projects related to compliance management, risk assessment and mitigation, control assurance, business continuity and disaster recovery, and user awareness. They are focused on developing and driving security strategies, policies/standards, ensuring the effectiveness of solutions, and providing security-focused consultative services to the organization.
IT Security professionals develop, execute and manage data, system, network and internet security strategies and solutions within a business area and across the enterprise. They develop security policies and procedures such as user log-on and authentication rules, security breach escalation procedures, security auditing procedures and use of firewalls and encryption routines. To guide enforcement of security policies and procedures, they administer and monitor data security profiles on all platforms by reviewing security violation reports and investigating security exceptions. They update, maintain and document security controls and provide direct support to the business and internal IT groups. IT Security professionals evaluate and recommend security products, services and/or procedures. They also communicate and educate IT and the business about security policies and industry standards, and provide solutions for enterprise/business security issues.
IT Security professionals require strong technical, analytical, communication and consulting skills with knowledge of IT Security and related technologies. Security certifications (i.e., Certified Information Systems Security Professional (CISSP), Certified in Risk and Information Systems Control (CRISC), Certified Information Security Manage (CISM), Global Information Assurance Certification (GIAC) and/or other certifications) may be required.
MAJOR RESPONSIBILITIES:
- STRATEGY (5%)_
- Provides strategic and tactical direction and consultation on security and IT compliance.
- POLICIES, PROCEDURES, & STANDARDS (5%)_
- Maintains an up-to-date understanding of industry best practices.
- Monitors compliance with security policies, standards, guidelines and procedures.
- Ensures security compliance with legal and regulatory standards.
- BUSINESS REQUIREMENTS (5%)_
- Engages directly with the business to gather a full understanding of project scope and business requirements.
- Assesses business needs against security concerns and articulates issues and potential risks to management.
- Consults with other business and technical staff on potential business impacts of proposed changes to the security environment.
- Provides security-related guidance on business process.
- SECURITY SOLUTIONS (5%)_
- OPERATIONS SOLUTIONS (5%)_
- RISK ASSESSMENTS (10%)_
- Works directly with the customers and other internal departments and organizations to facilitate IT risk analysis and risk management processes and to identify acceptable levels of residual risk.
- Conducts business impact analysis to ensure resources are adequately protected with proper security measures.
- Reviews risk assessments, analyzes the effectiveness of IT control activities, and reports on them with actionable recommendations.
- Evaluates security risks and identifies and defines compliance strategies in accordance with policies and standards.
- Provides management with risk assessments and security briefings to advise them of critical issues that may affect customer, or corporate security objectives.
- Communicates with multiple departments and levels of management in order to resolve technical and procedural IT security risks.
- Develops remediation strategies to mitigate risks associated with the protection of infrastructure and information assets.
- INFORMATION/DATA SECURITY (5%)_
- Defines, identifies and classifies information assets.
- Assesses threats and vulnerabilities regarding