Information Security: GRC/ISRM Lead

1 Month ago • 5-10 Years

Job Summary

Job Description

DNEG’s expanding Information Security (InfoSec), Governance, Risk and Compliance (GRC) and Data Privacy programs require an experienced InfoSec GRC Lead. This role manages and steers the InfoSec GRC and Privacy function, ensuring confidentiality, integrity, and availability of DNEG’s and client’s data and systems. The lead will collaborate with the InfoSec team and stakeholders to align and manage GRC initiatives, meeting tactical roadmap requirements and contributing to the overall InfoSec strategy.
Must have:
  • Manage, maintain, and mature the GRC function within DNEG.
  • Work proactively with the wider InfoSec team on GRC and audit deliverables.
  • Work effectively independently and as part of the InfoSec team.
  • Utilize effective task management, communication, and leadership skills.
  • Work in close partnership and collaborate with peers and internal technical teams.
  • Lead and mature the existing GRC program to ensure CRM and InfoSec risks are within tolerance.
  • Proficiently apply Risk Management methodologies.
  • Lead assessment, evaluation, and definition of risk mitigation solutions.
  • Take ownership of the ISMS policy framework.
  • Conduct onsite security audits and gap analyses across DNEG facilities.
  • Mature and develop the audit program, tracking control deficiencies.
  • Apply mandated controls to minimize risk associated with privacy breaches.
Good to have:
  • Experience working with and customizing automated risk management platforms and services.
  • Prior experience working within either the film or media industry sector.
  • High-level knowledge of working within either a hybrid or cloud native environment and their associated risks.
  • A bachelor’s degree in IT or Computer Science.

Job Details

Position at DNEG

DNEG’s expanding Information Security (InfoSec), Governance, Risk and Compliance (GRC) and Data Privacy programs have the requirement to add an experienced InfoSec Governance, Risk and Compliance (GRC) Lead to the expanding global team. The role will be responsible for successfully managing and steering the Information Security GRC and Privacy function within DNEG. The InfoSec team are responsible for ensuring that the confidentiality, integrity, and availability (CIA) of its, and client’s, confidential data, PII and systems and services are always maintained. It’s for this reason that an experienced InfoSec GRC function is required to work collaboratively with the team, peers, and business stakeholders to ensure that all the InfoSec GRC initiatives/projects are aligned, maintained, and managed effectively to meet the requirements of both tactical roadmap requirements and to the overall successful delivery of the wider InfoSec strategy.

1. Mandatory Requirements and Expectations

An experienced individual that works in a methodical and concise manner is required to successfully manage the InfoSec GRC and Privacy function at DNEG.

  • Experience of working within a highly technical and multi-faceted InfoSec security program.
  • Have excellent interpersonal, analytical, assessment and documentation skills which can be effectively utilized to develop and deliver against highly critical and GRC and Privacy assurance requirements.
  • Working closely with the Information Security Program Manager (ISPM) to successfully prioritize, steer and deliver the GRC and privacy facets of the InfoSec program.
  • Experience of working within multi-faceted audit environment.
  • Demonstrable experience of delivering, maintaining, managing, and maturing a global GRC program to meet the requirements of a highly complex environment.
  • Excellent track record of working with both internal and client driven auditable environments and ensure that control areas are effectively managed from a risk-based methodology.

2. Duties and Operational Responsibilities

  • Manage, maintain, and mature the GRC and function within DNEG.
  • Work proactively with the wider InfoSec team to ensure that all GRC and audit deliverables are suitably communicated and documented.
  • Be able to work effectively in an independent capacity and as part of the InfoSec team.
  • Utilize effective task management, communication, and leadership skills.
  • Work in close partnership and collaborate with peers and internal technical teams.

3. Job Requirements

3.1 Mandatory Job Requirements

A successful candidate will meet the majority of the requirements listed below and will be able demonstrate suitable experience in competencies in each of the following:

  • Five to Ten years, plus/minus, of working within, or leading, a GRC, Data Privacy and audit function.
  • Have demonstrable experience with all the following key areas:
  • Lead and mature the existing GRC program to ensure that identified CRM and InfoSec risks are suitably kept within DNEG’s risk tolerance level.
  • Highly proficient with Risk Management methodologies and suitable application.
  • Lead the assessment, evaluation and define risk mitigation solutions across the business and technical environments and identify areas of improvement.
  • Take ownership of the ISMS policy framework and ensure that the control framework is suitable and meets requirements as set forth by industry and client driven audit requirements.
  • Conduct onsite security audits and gap analyses across DNEG facilities to assess alignment with security frameworks.
  • Mature and further develop the audit program and work collaboratively with peers and stakeholders to ensure that control deficiencies are suitably tracked and ultimately either mitigated or accepted.
  • Demonstrable working knowledge of data privacy legislations, e.g., GDPR, and the applicability of applying mandated controls to minimize risk associated with privacy breaches etc.
  • Highly motivated and bring a progressive and highly collaborative approach to the InfoSec GRC function.
  • Knowledge of Information/Cyber Security processes and methodologies, e.g., ISO27001, CSA CCM etc.
  • Experience of working collaboratively and effectively with a PMO function.
  • Document and create qualitative and quantitative reporting relating to the GRC / Data Privacy roadmap.

3.2 Desired Job Requirements

A successful candidate will have experience with the desired requirements listed below and will be able demonstrate suitable experience in competencies in each of the following:

  • Experience of working with and customizing automated risk management platforms and services.
  • Prior experience working within either the film or media industry sector.
  • Experience and demonstrable, high-level knowledge, of the following:
  • Working within either a hybrid or cloud native environment and their associated risks that are applicable within this type of environment.

3.3 Education

  • A bachelor’s degree in IT or Computer Science is desirable, but not essential.
  • Any of the following Risk Management certifications, e.g., CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer/Auditor etc.

Similar Jobs

OKX - Senior Compliance Analyst

OKX

Sliema, Malta (On-Site)
1 Month ago
Room 8 Group - Change Manager

Room 8 Group

Ukraine (Remote)
3 Months ago
luxsoft - Project Manager - Core Banking

luxsoft

Sydney, New South Wales, Australia (On-Site)
2 Months ago
Tencent - Senior Regional Manager of WeChat Overseas Payments

Tencent

Bangkok, Bangkok, Thailand (On-Site)
12 Months ago
Hololight - C/C++ Software Developer (m/f/d) on-site

Hololight

Ismaning, Bavaria, Germany (On-Site)
4 Weeks ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Nice - Product Manager

Nice

United States (Hybrid)
1 Month ago
Litmus - Business Development Representative- EMEA

Litmus

Berlin, Berlin, Germany (On-Site)
3 Months ago
Palo Alto Networks - Director, Go-To-Market, Network Security

Palo Alto Networks

Santa Clara, California, United States (On-Site)
1 Month ago
Beyond Sports - System Admin/IT Support

Beyond Sports

Alkmaar, North Holland, Netherlands (On-Site)
5 Months ago
Nice - Senior Project Manager

Nice

London, England, United Kingdom (Remote)
2 Months ago
Open Systems Technologies - Senior Pipeline Design Project Manager

Open Systems Technologies

Boston, Massachusetts, United States (Hybrid)
1 Month ago
Razer - RazerStore Retail Sales Associate (PT, San Jose)

Razer

San Jose, California, United States (On-Site)
1 Month ago
Ethos Life - Finance & Strategy, Associate / Senior Associate

Ethos Life

United States (Remote)
1 Month ago
Ubisoft - Technical Director - Level Design

Ubisoft

Bordeaux, Nouvelle-Aquitaine, France (On-Site)
5 Months ago
Penn Interactive - Executive Host

Penn Interactive

Detroit, Michigan, United States (Remote)
3 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Bengaluru, Karnataka, India

Sumo logic - Senior Technical Program Manager

Sumo logic

Noida, Uttar Pradesh, India (On-Site)
1 Month ago
level ai - Staff Software Engineer - Data Platform

level ai

Noida, Uttar Pradesh, India (Hybrid)
6 Months ago
rivos - CPU Design Verification - Full-time

rivos

Bengaluru, Karnataka, India (Hybrid)
10 Months ago
Aspire - Product Intern

Aspire

Bengaluru, Karnataka, India (Hybrid)
1 Month ago
Hitachi - D365 F&O Technical lead

Hitachi

Hyderabad, Telangana, India (On-Site)
10 Months ago
ISG - ServiceNow Developer/Implementer

ISG

Bengaluru, Karnataka, India (On-Site)
1 Month ago
Capgemini - User communication engineer

Capgemini

Pune, Maharashtra, India (On-Site)
2 Months ago
Safe security - Software Development Engineer - Frontend

Safe security

Bengaluru, Karnataka, India (On-Site)
1 Month ago
Neolytix - Team Lead – Accounts Receivable (US Healthcare)

Neolytix

Gurugram, Haryana, India (On-Site)
1 Month ago
TransUnion - Vendor Manager

TransUnion

Bengaluru, Karnataka, India (Hybrid)
1 Month ago

Get notifed when new similar jobs are uploaded

Similar Category Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

About The Company

DNEG is a world-leading visual entertainment services company for the creation of feature film, television, and multiplatform content, with worldwide offices and studios across North America, Europe, Asia, and Australia.

 

DNEG’s critically acclaimed work has earned the company seven Academy Awards® for Best Visual Effects and numerous BAFTA, Primetime EMMY® Awards and VES Awards for its high-quality VFX work. 


Visit www.dneg.com for DNEG’s current and upcoming projects on behalf of Hollywood and global studio and production company.

Los Angeles, California, United States (On-Site)

Montreal, Quebec, Canada (On-Site)

London, England, United Kingdom (On-Site)

Vancouver, British Columbia, Canada (On-Site)

Sydney, New South Wales, Australia (On-Site)

Sydney, New South Wales, Australia (On-Site)

Sydney, New South Wales, Australia (On-Site)

Sydney, New South Wales, Australia (On-Site)

Los Angeles, California, United States (On-Site)

Sydney, New South Wales, Australia (On-Site)

View All Jobs

Get notified when new jobs are added by DNEG

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug