Program Director recruitment

 Description:  

The successful candidate will lead a group of information security professionals in the areas of Application Vulnerability Assessment (AVA), Data Protection, Content Monitoring and Security Incident Response (SIRT). Candidate should have a strong track record of cultivating global relationships and developing effective teams. Technical background is important, including the ability to converse in application, network and information security-related issues. This role reports to the ICG Information Security Head.

- Accountable for the execution of technology components of the ICG Global IS program.
- Assist in the definition and delivery of key program deliverables.
- Liaise with Businesses to better understand security risks and needs in context.
- Identify opportunities for process improvement at both the Corporate and Sector level.
- Prioritize project and program deliverables and manage day-to-day team workflow.
- Coordinate SIRT and Content Monitoring events.
- Manage a virtual security operations team based offshore and a full-time team located in NY/NJ/Buffalo.
- Construct and assess high-level and detailed security designs translating business needs and requirements into cost effective and risk appropriate controls.
- Identify and evaluate business and technology risks, internal controls which mitigate risks, and related opportunities for control improvement.

  Experience:

- 10+ years experience in information security, or IT risk management, compliance and controls.
- Financial services experience strongly preferred.
- Undergraduate degree required. Masters preferred.
- Proven experience managing global IS staff, and strong matrix management expertise.
- Confident, dynamic individual capable of defining, building, and matrix managing a global program across technology and business organizations in a constantly evolving environment.
- Customer-oriented, resourceful and enthusiastic.
- Experience performing security and/or privacy gap assessments and producing executive management reports on current practices that expose an organization to privacy and/or security risks.
- Experience with an organization's privacy and security due diligence efforts when entering into third party relationships or MA activities a plus.
- Expert knowledge of information security standards: ISO 27001/27002, ITIL, NIST, SANS, etc.

- Able to develop information security strategies and plans based on generally accepted security standards, regulatory and business requirements.
- Subject matter expert on technology risk management with understanding of security methods and technical elements i.e., access controls in the operating system, application and network environment, firewall, SSL, IDS, VPN, DMZ, encryption, digital certificates, biometrics, monitoring tools, mobile data protection, enterprise DRM.
- Knowledge of ethical hacking or application penetration testing methods, tools, and techniques.
- CISSP and/or CISM required.
- Strong written/verbal communication, interpersonal, and presentation skills.
- Strong project management skills.
- Strong PC and data manipulation skills required - e.g. MS Excel, Word, Access and PowerPoint.