Director, Information Security Risk Management

4 tygodni temu


Warsaw, Polska IQVIA Pełny etat

Role Location: Poland or Portugal

Job Overview

The successful candidate will play an integral role in developing the information security Risk Management framework for IQVIA and will manage risks identified through a variety of IT and operational audits. You will be responsible for managing the development of team members and will engage with senior business stakeholders to create targeted risk assurance programs based on identified, assessed and emerging risks. You will have strong understanding of Risk and Controls, and you will have extensive line management experience, managing the workload and development of team members. As the Director for Information Security Risk Management, you’ll be responsible for (but not limited to) the following:

Leading risk-related projects Maintaining ongoing testing and development of Information Security Risk Management framework, liaising with senior stakeholders and providing regular updates to stakeholders. Producing risk reports when required Working closely with other senior leaders within the team regarding training and guidance to support the business. Working with Business Units and stakeholders to ensure adequate, cost effective and timely protection/risk transfer for business activities. Creating a Supplier Risk Management Framework

Key Responsibilities:

Own the development and integration of the Information Security Risk Management Framework, Risk Appetite Statements, and Risk Policies and Procedures across the organization. Work closely with business and senior management to identify and manage risks aligned with the organization’s strategy and risk appetite. Provides strategic and tactical guidance to business decision-makers. Contribute to a strong governance structure and risk management across all business entities. Assess the impact of emerging risks and regulations, providing input and support for pragmatic solutions. Establish a comprehensive risk reporting system and process. Assist to remediate risks identified through established processes and procedures. Provides recommendations for remediation based on the reviews and risk assessments performed. Assist key business stakeholders in identifying and responding effectively to risk. Define key risk and performance indicators (KRIs/KPIs) for evaluating risk management performance. Integrate business continuity and crisis management into the organization's risk management strategies. Support the configuration of the TPRM & Risk Management solution for consistency with local processes. Assist in reviewing third parties, including due diligence reviews. Perform review of vendor engagements, understanding the functions of effective third-party risk.

Qualifications:

Bachelor's Degree Computer Science, a related field, or equivalent experience required. 10 years of experience within the information security domain managing Risk frameworks. Deep understanding and demonstrated experience of end-to-end risk management lifecycle, including key components and their relationships with internal and external stakeholders. Experience in non-financial/operational risk - developing and implementing risk frameworks, policies, and procedures. Demonstrated experience leading risk management workshops, obtaining and synthesizing inputs from technical and non-technical stakeholders throughout the enterprise. Experience in conducting Third Party reviews is advantageous. Experience operating as a part of a GRC program in alignment with common information technology management frameworks such as NIST, ITIL, ISO 27001 etc. Security-related qualifications such as CISM or CISSP , CRISC are a plus.

IQVIA is a leading global provider of advanced analytics, technology solutions and clinical research services to the life sciences industry. We believe in pushing the boundaries of human science and data science to make the biggest impact possible – to help our customers create a healthier world. Learn more at


  • Technology Audit Director

    3 tygodni temu


    Warsaw, Polska JPMorgan Chase & Co. Pełny etat

    Are you looking for an exciting opportunity to join a dynamic and growing team in a fast paced and challenging area? This is a unique opportunity for you to work in our EMEA Audit Function and partner with the Business. We are proud of our reputation for excellence, integrity, and collaboration. Our priorities of strong governance, transparency, and...

  • Tech Risk Analyst

    1 miesiąc temu


    Warsaw, Polska Michael Page Pełny etat

    Directly responsible for performing technology risk assessments and control assessments to ensure systems and applications (on prem and in the cloud) are complying with company policies, applicable regulatory and legal requirements, and leading industry practices.Updating the Business Impact Analysis (BIAs) plans to determine key systems to assess.Maturing...


  • Warsaw, Polska IQVIA Pełny etat

    Location: Portugal or Poland This is a key role within the Global Information Security organization. The individual fulfilling this role will be a member of the Information Security Governance Risk and Compliance Program Delivery and Improvement team, tracking the delivery of all CISO programs and BAU activities through metrics and continuously looking...

  • Security Architecture

    6 godzin temu


    Warsaw, Polska Goldman Sachs Pełny etat

    Business Unit Overview Led by the Chief Information Security Officer (CISO), Technology Risk secures Goldman Sachs against hackers and other cyber threats. We are responsible for detecting and preventing attempted cyber intrusions against the firm, helping the firm develop more secure applications and infrastructure, developing software in support of our...


  • Warsaw, Polska AstraZeneca Pełny etat

    ABOUT ASTRAZENECA At AstraZeneca, we are united by a common purpose: to push the boundaries of science to deliver life-changing medicines. Every day, we make a difference by delivering potentially life-changing medicines to millions of people worldwide. Our purpose is results-oriented and so is our approach. Becoming a more agile and creative company...


  • Warsaw, Polska JPMorgan Chase & Co. Pełny etat

    You are passionate about data management, enjoy implementing solutions, interested in driving data governance and policy, this role is for you. As a Chief Data Office – Data Risk Management Associate/Senior associate in the Firmwide Finance Business Architecture team (FFBA) you will be part of a high performing team of data management professionals...

  • Head of Security

    4 tygodni temu


    Warsaw, Polska Michael Page Pełny etat

    Setting the overall strategy and roadmaps for our client's Information Security and ensuring the successful deliveryEnsuring suitable security governance - Information Security Steering Group, reporting, KPIs, supplier management, risk-driven security in projects, suitable policies and standardsDriving up security knowledge, by overseeing awareness programs,...


  • Warsaw, Polska JPMorgan Chase & Co. Pełny etat

    You are passionate about data management, enjoy implementing solutions, interested in driving data governance and policy, this role is for you. As a Chief Data Office – Data Risk Management Vice President in the Firmwide Finance Business Architecture team (FFBA) you will be part of a high performing team of data management professionals focused on...


  • Warsaw, Polska JPMorgan Chase & Co. Pełny etat

    You are passionate about data management, enjoy implementing solutions, interested in driving data governance and policy, this role is for you. As a Chief Data Office – Data Risk Management Senior Associatet in the Firmwide Finance Business Architecture team (FFBA) you will be part of a high performing team of data management professionals focused on...


  • Warsaw, Polska Goldman Sachs Pełny etat

    Business Unit Overview Led by the Chief Information Security Officer (CISO), Technology Risk secures Goldman Sachs against hackers and other cyber threats. We are responsible for detecting and preventing attempted cyber intrusions against the firm, helping the firm develop more secure applications and infrastructure, developing software in support of our...


  • Warsaw, Polska J.P. Morgan Pełny etat

    Job Description You are passionate about data management, enjoy implementing solutions, interested in driving data governance and policy,  this role is for you. As a Chief Data Office – Data Risk Management Vice President in the Firmwide Finance Business Architecture team (FFBA) you will be part of a high performing team of data management professionals...


  • Warsaw, Polska J.P. Morgan Pełny etat

    Job Description You are passionate about data management, enjoy implementing solutions, interested in driving data governance and policy, this role is for you. As a Chief Data Office – Data Risk Management Associate in the Firmwide Finance Business Architecture team (FFBA) you will be part of a high performing team of data management professionals...


  • Warsaw, Polska Goldman Sachs Pełny etat

    WHO WE ARE Led by the Chief Information Security Officer (CISO), Technology Risk secures Goldman Sachs against hackers and other cyber threats. We are responsible for detecting and preventing attempted cyber intrusions against the firm, helping the firm develop more secure applications and infrastructure, developing software in support of our efforts,...


  • Warsaw, Polska J.P. Morgan Pełny etat

    Job Description You are passionate about data management, enjoy implementing solutions, interested in driving data governance and policy,  this role is for you. As a Chief Data Office – Data Risk Management Vice President in the Firmwide Finance Business Architecture team (FFBA) you will be part of a high performing team of data management professionals...


  • Warsaw, Polska Worldline Pełny etat

    The Opportunity As the People Leader of a Risk merchant monitoring Team, you'll be steering the risk assessment process for customers, both Merchants and Partners. Your leadership will ensure streamlined processes in regard to ongoing due diligence. The risk assessment done by the Merchant monitoring team could be a part of period reviews or...

  • Country Director, Poland

    3 tygodni temu


    Warsaw, Polska International Rescue Committee Pełny etat

    Requisition ID: req51610 Job Title:  Country Director, Poland Sector:  Emergency Response Employment Category:  Fixed Term Employment Type:  Full-Time Open to Expatriates:  No Location:  Warsaw, Poland Work Arrangement: In-person Job Description In Ukraine, months of escalating Russian hostility culminated in a concerted invasion...


  • Warsaw, Polska J.P. Morgan Pełny etat

    Job Description You are passionate about data management, enjoy implementing solutions, interested in driving data governance and policy, this role is for you. As a Chief Data Office – Data Risk Management Associate in the Firmwide Finance Business Architecture team (FFBA) you will be part of a high performing team of data management professionals...


  • Warsaw, Polska Balyasny Asset Management L.P. Pełny etat

    Role Overview The Commodities Risk Technology team builds large scale Cloud-native distributed systems to support risk modeling, risk calculation, risk market data processing, risk reporting, risk guidelines monitoring, and risk research for Commodities Risk Management front office teams across Balyasny. The team’s major clients include the Risk...


  • Warsaw, Polska emagine Consulting Pełny etat

    Industry: Finance / Banking Location: Gdańsk / Warsaw (Hybrid Work Model) Project Languages: English and Polish Rate: -zł/h net+VAT Duration: Long term Join dynamic team in the Finance/Banking industry! We are currently seeking a skilled Expert IT Security Specialist to contribute to our data protection and information security initiatives....

  • IT Security Architect

    4 tygodni temu


    Warsaw, Polska DSV Pełny etat

    . Your responsibilities: • Develop and maintain comprehensive security architecture blueprints, ensuring alignment with business goals and compliance requirements.• Evaluate existing security measures and recommend enhancements to protect against emerging threats.• Provide expert advice on security best practices, risk management, and compliance.•...