Responsibilities
- Assist the CISO with annual and periodic risk assessments for audit and compliance purposes
- Oversee the risk register by ensuring it is accurate, complete, and updated on schedule
- Perform risk evaluations, including analysis of risks and the effectiveness of controls
- Monitor remediation efforts, track deadlines, escalate overdue items, and report progress to leadership
- Engage with subject matter experts to collect data for risk assessments
- Work with teams across functions to create strategies for reducing risk
- Evaluate third-party vendor security through questionnaires, documentation reviews, and audit reports
- Determine security gaps, assign risk levels, and define necessary mitigation actions for vendors
- Develop, carry out, and oversee control testing to verify compliance with internal policies, regulations, and contracts
- Coordinate with IT and business control owners to clarify roles and responsibilities
- Compile and submit documentation for internal and external audits
- Track and report compliance and risk metrics to senior management
- Enhance security operations by streamlining and automating processes in collaboration with teams
- Perform additional duties as assigned; this list is not exhaustive
Work Arrangement
Hybrid — Southfield, MI
Other
- Contract duration is approximately 6 months, with possible extension
- Paid relocation and benefits are not provided
- The organization follows a hybrid model requiring office presence on Tuesday, Wednesday, and Thursday, with remote work allowed on Monday and Friday
- Standard working hours are 8:30 AM to 5:30 PM, Monday through Friday
- Applicant must have current authorization to work in the United States. No visa or immigration sponsorship is available at any time
Not available. Candidate must be currently authorized to work in the United States. No visa or immigration sponsorship is offered for this role, now or in the future.