Review and validate risk assessments and treatment plans proposed by the first line, ensuring compliance with organizational and regulatory standards. * Develop and manage IT and security control frameworks, ensuring alignment with internal policies, industry best practices, and regulatory requirements (e.g., ISO 27001, NIST, SOC). * Oversee the review of IT and security contractual clauses with , ensuring they meet second line's standards for risk management. * Strong understanding of Information Security frameworks (ISO 27001, NIST, SOC) and their application in second line assurance activities. * Proven ability to conduct risk oversight, challenge the first line's risk management activities, and ensure compliance with internal and external standards.
meer