Job Number: 25-03721
Ready for a rewarding opportunity in the Financial Services Industry? ECLARO is looking for a Risk Management and Policy Specialist for our client in Canton, MA.
ECLARO's client is a market-leading insurance company, providing property, casualty, and specialty insurance services within the United States. If you’re up to the challenge, then take a chance at this rewarding opportunity!
Responsibilities:
- Develop and document Cyber Risk Management Program and related procedures:
- Develop Risk Management Program.
- Revise and update existing Risk Inventory.
- Define Risk Management Escalation.
- Define Risk Management Principles.
- Integrate corporate parent Risk Tolerances.
- Define Risk Appetite as compared with Canada and get agreement on alignment.
- Define operational approach to risk management.
- Define Tactical / Operational approach to risk management.
- Incorporate Client risk assessment processes (PL-02. PL-05).
- Define Risk Impact and Likelihood from NIST 800-53v5.
- Review and update Cyber Risk Management methodology.
- Define methods of ongoing review tying to NYDFS Amendment 2.
- Replace COSO with Parent Company Recommendations.
- Define criticality levels for assets / system etc.
- Define Risk levels using parent company recommendations as a start but ensure alignment to US Business Requirements.
- Upgrade current WISP to latest version of NIST800-53v5:
- Continue evaluation comparison of current WISP which is at NIST800-53v4 to newer NIST800-53v5.
- Revise comparison document of WISP and applicability matrix.
- Upgrade applicability matrix (policies and evidence) to new WISP version matching NIST800-53v5.
If hired, you will enjoy the following ECLARO Benefits:
- 401k Retirement Savings Plan administered by Merrill Lynch
- Commuter Check Pretax Commuter Benefits
- Eligibility to purchase Medical, Dental & Vision Insurance through ECLARO
If interested, you may contact:
Lea Enriquez
leafer.enriquez@eclaro.com
646-695-2941
Lea Enriquez | LinkedIn
Equal Opportunity Employer: ECLARO values diversity and does not discriminate based on Race, Color, Religion, Sex, Sexual Orientation, National Origin, Age, Genetic Information, Disability, Protected Veteran Status, or any other legally protected group status, in compliance with all applicable laws.