Develop and manage IT and security control frameworks, ensuring alignment with internal policies, industry best practices, and regulatory requirements (e.g., ISO 27001, NIST, SOC). * Monitor and assess IT and cybersecurity risks across the organization, focusing on second-line oversight of the first line's risk management practices. * Conduct audits and provide oversight of IT and cybersecurity practices within the first line of defense, especially in third-party risk management. * Collaborate with the first line, providing support and challenge to enhance the effectiveness of security controls and practices.
meer