Develop and manage IT and security control frameworks, ensuring alignment with internal policies, industry best practices, and regulatory requirements (e.g., ISO 27001, NIST, SOC). * Oversee the review of IT and security contractual clauses with , ensuring they meet second line's standards for risk management. * Familiarity with vulnerability management, penetration testing, and reviewing IT and security clauses in contracts. * Monitor and assess IT and cybersecurity risks across the organization, focusing on second-line oversight of the first line's risk management practices. * Conduct audits and provide oversight of IT and cybersecurity practices within the first line of defense, especially in third-party risk management. * Produce
more