Information Technology Security Officer (ITSO) - Chicago, IL
Job description
Job Description
ADM Investor Services, Inc.
This is a full-time, exempt position.
Position Summary:
The ITSO at ADMIS is a global role responsible for enhancing and executing the information security strategy. This role will be critical to ensure the firm’s security posture reflects global requirements inclusive of regulatory compliance in the US, UK/EU and APAC. The ITSO will be required to ensure the cyber-security program has clearly defined threats, risk appetites, risk thresholds, and a risk acceptance process that provides senior management with clear and transparent management information. The ITSO will be guided by the ADMIS Cyber-Security Steering Group (CSSG). The ITSO will be working directly with the ADM IT Security organization as a service taker and utilize the team and tooling wherever possible. ADMIS is a fast paced and exciting business and will be looking for a strong leader and a change agent to assist in our growth strategy.
Job Responsibilities:
- Develops, implements, and monitors a strategic, comprehensive information security program to ensure appropriate levels of confidentiality, integrity, availability, safety, privacy, and recovery of information assets owned or controlled by the organization.
- Responsible for security awareness training program for all employees, contractors, and approved system users.
- Provides clear risk mitigating directives for projects with components in IT, including the mandatory application of controls.
- Develops and enhances an up-to-date information security management framework based on the National Institute of Standards and Technology (NIST) Cybersecurity Framework or equivalent.
- Facilitates a metrics and reporting framework to measure the efficiency and effectiveness of the program.
- Creates the necessary internal network among the ADM information security team and line-of-business executives, corporate compliance, audit, physical security, legal and HR management teams to ensure alignment as required.
- Builds and nurtures external network consisting of industry peers, ecosystem partners, vendors, and other relevant parties to address common trends, findings, incidents, and cybersecurity risks.
- Collaborates and liaises with the data privacy officer to ensure that data privacy requirements are included where applicable.
- Ensures that security is embedded in the project delivery process.
- Manages information security incidents and events to protect corporate IT assets, intellectual property, regulated data and the company's reputation.
- Works with the compliance staff to ensure that all information owned, collected, or controlled by or on behalf of the company is processed and stored in accordance with applicable laws and other global regulatory requirements.
- Defines and facilitates the processes for assessments, including execution of treatment efforts to address negative findings.
- Develops and oversees effective disaster recovery policies and standards to align with the enterprise business continuity management (BCM) program goals.
- Facilitates and supports the development of asset inventories, including information assets in cloud services and in other parties in the organization's ecosystem.
- Facilitates the granting, monitoring, and reporting on access controls to data and information assets.
- Demonstrated experience and success in senior leadership roles in risk management, information security, and IT or OT security.
- Degree in business administration or a technology-related field, or equivalent work- or education-related experience
- Knowledge of common information security management frameworks, such as ISO/IEC 27001, ITIL, COBIT as well as those from NIST, including 800-53 and Cybersecurity Framework
- Able to communicate with all levels of the organization.
- Financial Industry Experience
- Promotes the ADM Way and Core Values
- Strong analytical skills
- Strong problem-solving skills
- Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC) or other similar credentials.
This position offers a complete benefit package, including 401K/ESOP, pension, health, life and dental insurance.
ADM requires the successful completion of a pre-employment drug screen and a background check.
REF: 69865BR
About ADM:
EEO
Ref ID
dudleyanddudleyllc.com is the go-to platform for job seekers looking for the best job postings from around the web. With a focus on quality, the platform guarantees that all job postings are from reliable sources and are up-to-date. It also offers a variety of tools to help users find the perfect job for them, such as searching by location and filtering by industry. Furthermore, dudleyanddudleyllc.com provides helpful resources like resume tips and career advice to give job seekers an edge in their search. With its commitment to quality and user-friendliness, dudleyanddudleyllc.com is the ideal place to find your next job.