Description The Opportunity: We are seeking a skilled and dedicated IT Specialist to join our team in the petroleum industry. In this role, you will be responsible for managing IT regulatory compliance efforts across various agencies including the Sarbanes-Oxley Act (SOX), United States Coast Guard (USCG), General Data Privacy Regulation (GDPR) NIS Directive, and Transportation Security Administration (TSA). Your expertise will ensure that our IT systems and practices align with regulatory requirements, maintaining the highest standards of security and compliance.
Responsibilities: - Regulatory Compliance Management:
- Monitor, interpret, and ensure compliance with IT regulatory requirements from SOX, USCG, TSA, GDPR, and other relevant agencies regulating critical infrastructure operators.
- Develop and maintain comprehensive knowledge of cybersecurity standards, guidelines, and best practices applicable to IT and operations. Policy and Procedure Development:
- Develop, update, and enforce IT policies, procedures, and controls to align with regulatory requirements and industry standards.
- Collaborate with stakeholders to ensure policies are implemented effectively across the organization.
- Risk Assessment and Mitigation:
- Conduct regular risk assessments and audits of IT systems, identifying vulnerabilities and recommending mitigation strategies to ensure compliance and security.
- Implement controls and measures to address identified risks and improve overall IT security posture.
- Audit and Compliance Reporting:
- Coordinate and support IT audits conducted by internal and external auditors to assess compliance with regulatory requirements.
- Prepare documentation and evidence and assist in remediation efforts based on audit findings.
- Training and Awareness:
- Provide training and awareness sessions on IT regulatory compliance, policies, and procedures to IT staff and other relevant stakeholders.
- Foster a culture of compliance and security awareness throughout the organization.
- Continuous Improvement and Innovation:
- Stay updated on emerging technologies, cybersecurity threats, and regulatory changes affecting the petroleum industry and critical infrastructure operators.
- Recommend and implement improvements to IT infrastructure and processes to enhance regulatory compliance and cybersecurity resilience.
Education: - Bachelor's degree in computer science, Information Technology, Cybersecurity, or a related field.
Requirements: - 2-5 years of experience including 3+ years of experience in IT regulatory compliance, cybersecurity, or a similar role within the petroleum industry.
- Strong understanding of regulatory frameworks and standards such as SOX, USCG, NIST, and TSA.
- Experience in conducting IT audits, risk assessments, and implementing IT controls.
- Professional certifications such as Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), or equivalent certifications preferred.
- Excellent communication and interpersonal skills, with the ability to collaborate effectively across departments and levels of the organization.
- Strong analytical and problem-solving skills, with attention to detail and accuracy.
- Ability to work independently, prioritize tasks, and manage time effectively in a dynamic environment.
Humble. Hungry. Smart. Does this sound like you? Do others describe you as being a down-to-earth achiever? Someone who thinks outside the box and always strives to do more than what is required? Someone who sees the bigger picture? You sound brilliant to work with!
We Want You To Shine: