Location:
USA-Houston
Job SummaryThe Cybersecurity Risk Management Specialist is responsible for governing changes that could introduce cybersecurity risk into the environment, via IT and OT changes. They operationally govern the environment, following the enterprise's cybersecurity policies and standards, via defining and enforcing operational processes for cybersecurity risk assessment and remediation covering the organization's IT and OT environment. They establish operational risk management processes and operational playbooks, aligned to corporate cybersecurity policy and agreed upon risk management frameworks and enterprise risk management guidelines, to ensure secure IT and OT changes, while providing enterprise-wide cybersecurity risk visibility.
They serve as the focal point and technical consultant to the business units and IT and OT project team and management to assess and identify cybersecurity risks related to environment changes. They establish risk remediation approaches based upon corporate policies and standards, steering and facilitating implementation of any needed cybersecurity controls with the appropriate control owners.
They are responsible for planning, managing, and coordinating various cybersecurity risk management activities, focused on identifying, assessing, and mitigating unacceptable risks while enabling the underlying business goals and objectives. They also oversee and manage all 3rd-party risk management and act as a gatekeeper for enabling integrations with 3rd-party partners, suppliers, and vendors, overseeing TPRM assessments and specifying controls needed to protect the organization's data and connectivity with 3rd-parties.
Job Responsibilities- Maintain enterprise risk management operational frameworks and risk scoring criteria in accordance with company cybersecurity policies, standards, and frameworks and enterprise risk management guidelines.
- Perform cybersecurity risk assessments for all qualifying IT and OT environment changes.
- Coordinate with the cybersecurity architecture senior specialist to validate risk assessment findings, and to request guidance when pre-approved risk mitigation strategies are not available for identified risks.
- Establish and track risk remediation plans for all identified risks.
- Coordinate with the cybersecurity assurance specialist to ensure ongoing verification of mitigated risks are effective over time.
- Implement, manage, and maintain risk-related workflows, including coordination with the appropriate risk owners and authority functions to obtain approval for risk exceptions and policy deviations.
- Act as a gatekeeper between Implementation Phase and production go-live (Manage & Measure phase) to ensure all identified risks have been addressed via closure of risk remediation plans.
- Ensure all 3rd-party / external partner, vendor, and supplier interactions have undergone an appropriate risk assessment to verify the safety, security, and risk mitigation of all 3rd-party integrations and interactions.
- Maintain a register of approved 3rd-parties, including the controls required to ensure safe and secure interactions, and the approved use case(s) of each 3rd-party
- Establish and maintain a 3rd-party re-verification program to verify that usage, risks, and risk mitigations are updated as needed, if any 3rd-party relationships change over time
- Coordinate with the cybersecurity Assurance team to ensure on-going operational validation of 3rd-party integrations and interactions
- Review all third-party contracts for IT / OT services and solutions to ensure all required risk-mitigating controls and clauses are included and enforced contractually.
- Oversight and management of the enterprise cybersecurity risk register to facilitate the monitoring and reporting of risks.
- - Management of the operational risk assessment methodology covering the organization's IT , OT, and 3rd-party integration components related to secure, compliant and resilient operations.
- Oversight of the managed services providers performing risk assessments to ensure they are following the methodology in compliance with company policies, standards, processes, and expectations.
- Provide evidence to Assurance function, Legal, approved stakeholders, and contribute to internal and external audits and assessments as needed in regard to cybersecurity risks.
- - Ensure feedback from cybersecurity Assurance role and similar stakeholders are used to improve risk assessment methodologies and processes
- Identifies gaps and needs in regard to risk assessment, working with the cybersecurity architect role to ensure needs are incorporated into the cybersecurity strategy and roadmap.
- Manages control implementations and improvement projects in the area of risk management, following the organization's project management and project execution processes.
- Drives operational risk assessment maturity and process improvements and automation for processes and controls in-scope of role.
Job Requirements- BS or MA in computer science, information security, cybersecurity or a related field
- Cybersecurity certification in risk assessment (or appropriate on-the job experience)
- 5+ years of experience in a cybersecurity, enterprise (ERM), or IT risk management role
- 5+ years of experience with regulatory compliance, risk management frameworks and information security management frameworks (e.g. ISO, NIST, etc)
- Strong understanding of Zero Trust principals
- Cybersecurity principles and practices, including IT and OT cybersecurity risk assessment, cybersecurity risk mitigation, and third-party risk assessment.
- Cybersecurity frameworks and standards, such as the NIST CSF, Secure Controls Framework, ISO/IEC 27001, and OT cybersecurity standards (62443, ...).
- Strong background in conducting Business Impact Analysis (BIA) to evaluate the potential impact of cybersecurity risk on critical business processes and functions.
- Third Party and Vendor Risk
- Regulatory and Compliance alignment
- Strong communication skills
- Planning and organizing
- Personal Leadership
- Analytical and Risk Based decision making.
Eligibility Requirements (Regional Specific)- You must submit your application for employment online to be considered. Please submit your resume using the "Apply Now/Apply" option on this page.
- You must be 18 years or older
- Applicants must be currently authorized to work for SABIC in the United States on a full-time basis.
Work AvailabilityRegular, predictable attendance is an essential function of this position. Applicants must be regularly available and willing to work (e.g. Monday - Friday)] during assigned hours of operation and such other hours as the company determines are necessary or desirable to meet business needs
We are proud to be a diverse and an equal opportunity employer .We are fully committed to a culture of respect and inclusion.