Information Security Risk Specialist – Group Technology recruitment
85607BR
The Information Security Risk Specialist ? Group Technology (IT) is a member of the Group Information Security Office organization, works closely with the Group Technology ISO in establishing the Information Security control framework within Group Technology and identifying information security risks, acts as a subject matter expert in the field of information security, drives information security initiatives, and fosters the exchange of information with IT and within the GISO organization.
The primary responsibility of the Information Security Risk Specialist ? IT is to act as the point of contact to the Information Security Officer for Group Technology, reporting to the Group Information Security Officer:
Supports IT ISO and IT Risk Management with the implementation of the operational risk framework and ensures alignment with Data Protection risk taxonomy
Ensures consistency of IT internal controls and operational risk assessments with ORC standards and agrees on control monitoring requirements (positive affirmation of effective performance)
Identifies the key information security risk scenarios related to technology and supports the identification of the critical controls required within the function
Assesses known information security weaknesses and the adequacy of associated remediation activities
Builds close links with Group Technology teams in relation to Information Security risks and issues
Supports the definition of the Information Security Framework for IT in alignment with Group Information Security Policy Framework
Oversees the development of the information security framework and governance within IT, ensuring completeness of functional and geographical coverage
Establishes and maintains strong links within the industry to ensure that Information Security related industry news and regulatory developments are embedded within the Framework and provides a view on future developments
Supports the definition of Information Security training requirements and mechanisms to promote and instill a culture of Information Security risk management and awareness within Group Technology
Supports the analysis of root causes on information security risk events and, where deemed relevant, provides benchmarking analyses on events that occurred in the industry
As a member of the GISO organization, the Information Security Risk Specialist:
Acts as an advisor and Subject Matter Expert for information security related risk assessments, incident analysis and strategic initiatives as well as in the development and introduction of relevant business initiatives
Ensures steady information flow between ORC, Group Technology, other DISOs and further information security stakeholders as well as within the GISO organization
Facilitates the implementation of sustainable information security risk remediation programs
Experience
5+ years substantial experience within Information Technology, ideally in the Financial Industry, with a particular focus on Information Security relevant aspects
Solid understanding of Information Technology, Information Security Frameworks, Risk Management and IT Security
Substantial experience in the analysis of Information Security Risk issues and their business impact
Ability to setup operational models for security technologies including organization, operational processes and key performance indicators
Leadership Skills
Excellent problem solving and analytical skills.
Team player with the ability to work independently to organize, manage and complete projects within tight deadlines.
Persuasive oral and effective written presentation skills.
Has a strong understanding of available resources available and leverages and uses them effectively.
Interacts well with all levels of employees within a global organization.
UBS can offer you an environment geared towards performance, attractive career opportunities, and an open corporate culture that values and rewards the contribution of every individual. Together we will shape and strengthen the UBS brand.
Want to further your career in an organization where your contribution can make a difference? Apply now at www.ubs.com/careers. We look forward to hearing from you.
Corporate Center
Information Technology
UBS
HR Recruiting Switzerland
Ms. S. Marcilly
+41-44-234 75 51