The Director of Security and Continuity serves as the process owner of all activities related to the availability, integrity and confidentiality of client, Firm and employee information in compliance with the organization's information security policies. This position is responsible for establishing and maintaining a firm-wide information security management program to ensure that information assets are adequately protected. The Director of Security and Continuity is being established to ensure we cultivate a security-conscious workplace culture throughout our firm. This role is responsible for creating, implementing, managing, and enforcing security and compliance strategies and policies relating to information security, physical security, business continuity planning, crisis management, privacy, and compliance. This position works closely with senior leadership in IT and Risk Management to establish security and compliance practices, oversee day-to-day matters relating to security and compliance, and to address any security or compliance related challenges. Essential Job Functions - Develop, implement and oversee an information security vision and strategy that is aligned to organizational priorities and enables and facilitates the organization's business objectives.
- Actively participate in the firm’s crisis management strategic planning.
- Oversee the development, management and testing of business continuity, emergency-preparedness and disaster recovery plans and policies.
- Facilitate regular crisis drills and post action reviews. Ensure all associated plans and policies remain current and the proper tools are in place to house our crisis management documentation.
- Coordinate the development and implementation of incident response plans and procedures and manage the lifecycle review of related documentation and processes.
- Oversee the development and testing of a comprehensive incident response plan to ensure business-critical services are recovered in the event of a security event.
- Provide proactive reporting on the status of our information security program and regular threat briefings to enterprise risk teams, senior business leaders and the Board.
- Ensure access to systems and information are governed by strong identity and access management protocols.
- Collaborate with Risk Management to develop and maintain a document framework of continuously up-to-date information security policies, standards and guidelines. Oversee the approval and publication of these information security policies and practices.
- In conjunction with Risk management, develop and manage a targeted information security awareness training program for all employees, contractors and approved system users, and establish metrics to measure the effectiveness of this security training program for the different audiences.
- Liaise with external agencies, such as law enforcement and other advisory bodies, as necessary, to ensure that the organization maintains a strong security posture and is kept well-abreast of the relevant threats identified by these agencies.
- Oversee security and compliance planning and implementation for new or existing enterprise system(s) and ensure that the design of hardware, operating systems and software applications adequately address security and compliance controls.
- Ensure that information security requirements are included in all vendor contracts.
- Lead a team of security professionals that are results-oriented and that maintain appropriate certifications and a relevant skill-set.
|