Cyber Compliance Enablement - Assistant Director
Job description
Location: Washington DC, Palo Alto, Sacramento, San Diego, San Francisco, San Jose, Irvine, Los Angeles, Denver, Stamford, Hartford, Orlando, Miami, Jacksonville, Tallahassee, Tampa, Atlanta, Indianapolis, Des Moines, Kansas City, Wichita, Louisville, New Orleans, Baltimore, Boston, Detroit, Minneapolis, St Louis, Las Vegas, Hoboken, Iselin, Buffalo, New York, Rochester, Charlotte, Cleveland, Columbus, Portland, Pittsburgh, Philadelphia, Providence, Greenville, Nashville, Memphis, Houston, Dallas, San Antonio, Austin, Salt Lake City, McLean, Richmond, Seattle, Chicago, Milwaukee
Cyber Compliance Enablement – Assistant Director
East Coast Preferred
Ethics, Compliance, and Risk Management (ECRM) supports our people in managing the risks that arise during our daily working lives. We work closely with all parts of the organization to identify, manage and monitor risk, providing coordinated advice and assistance on independence, conflicts, compliance, regulatory, policy, security issues, as well as dealing with claims and any queries regarding ethics.
The opportunity
We are operating in an increasingly connected world that is changing how to manage risk. With fast-paced technology advancements, new innovations within emerging technologies, and an ever-challenging regulatory environment, it is business critical for our organization to identify not only the risks but the opportunities these present to us. As a Cyber Compliance Assistant Director with our Americas Data Protection function, you will make educated, thoughtful decisions. Our brand depends on it. It’s all part of our long-term commitment to building a better working world and in return, you can expect plenty of opportunities to take on new responsibilities and develop your career.
Your key responsibilities
As part of EY Americas Data Protection function, you will assist in the development, implementation, and monitoring of various program initiatives. We are looking for a high performing Assistant Director to assist in the execution of strategic and operational program initiatives. This position requires in-depth subject matter knowledge to efficiently assess and manage information security risk.
Skills and attributes for success
- Drives Cyber Compliance activities, including but not limited to:
- Engaging stakeholders based on information security compliance profile and identifying mitigating controls and activities,
- Supporting information security compliance assessments to identify information security risks across our Americas environment, and
- Supporting execution of risk mitigation activities involving aspects such as, identity and access administration, application vulnerabilities, and ensuring compliance with essential norms.
- Assists with strategy formation and direction of EY US information security compliance activities,
- Assists in monitoring and analyzing related cyber regulatory developments to confirm applicable requirements,
- Assists in maintaining and updating related EY policies, guidance, training, and awareness communication plan to reflect new and/or changes to information security and data protection laws, regulations, and standards,
- Collaborates with various functions across the organization, such as EY’s Global Information Security, and members of the business and Service Line Quality, to design and implement controls in order to protect confidential/personal information,
- Creates reports on various program activities to be delivered to key program stakeholders, including senior leaders within the organization,
- Continuously maintains and expands knowledge of field of expertise and communicates new developments and resulting impact to program stakeholders and team members, and
- Participates in various ad-hoc program projects, as needs develop.
To qualify for the role, you must have
- Strong verbal and written communication skills
- Solid understanding of relevant firm business and area wide data protection issues and concerns
- Strong problem-solving skills
- Flexibility and the ability to take the initiative
- Ability to right-size risk
- Strong research skills
- Strong project management skills and the ability to successfully handle multiple tasks
- Good working knowledge of information systems and common software packages
- Bachelor’s degree or equivalent work experience; Graduate degree preferred
- 5-6 plus years related experience
Ideally, you’ll have
- Ability to reference existing firm information security and data protection policies as well as knowledge and experience to review complex situations and assist in proposing solutions
- Strong knowledge of relevant global, national, and local data protection laws, regulations, and standards, as well as familiarity with other risk management initiatives outside of their specific area
- Sound understanding of high-level information security trends
- Experience in information security
- Experience with information security frameworks (e.g., ISO, NIST)
- Information security certification from ISC2 or ISACA (e.g., CISSP, CISM, CISA)
- Knowledge of Artificial Intelligence and associated risks is preferred
What we look for
We’re interested in people that will be able to right-size risk and recommend creative solutions to complex problems, as well as make significant contributions to complex Ethics, Risk Management, and Compliance projects.
- Continuous learning: You’ll develop the mindset and skills to navigate whatever comes next.
- Success as defined by you: We’ll provide the tools and flexibility, so you can make a meaningful impact, your way.
- Transformative leadership: We’ll give you the insights, coaching and confidence to be the leader the world needs.
- Diverse and inclusive culture: You’ll be embraced for who you are and empowered to use your voice to help others find theirs.
Nearest Major Market: Washington DC