Houston, United States
Updated: 27-Jan-2014
Reference ID: 4151BR
The Risk and Controls Analyst is responsible for ensuring risks to Shell Trading information assets are identified and understood, and that appropriate action is taken to mitigate risks. The analyst will work closely with IT Delivery and Business staff. Activities include:
Responsibilities:
- Manage the risks to Trading information assets and describe risk levels in qualitative and quantitative terms
- Conduct deep-dive risk assessments in highly complex situations and recommend controls and actions to mitigate risk
- Assess IT solutions for information security weaknesses and provide authoritative advice on the secure design of applications and infrastructure
- Contribute to information security architecture and input to major improvement programmes
- Maintain a strong working knowledge of industry and regulatory control requirements and best practice
- Communicate, educate and raise awareness of IT Delivery and Business staff on information risks and controls
- Actively participate in external discussions on IRM topics
- Build a network of contacts in other teams and businesses to share experiences and lessons learned
Requirements:
- Must have legal authorization to work in the US on a full time basis for anyone other than your current employer
- Bachelor’s degree
- Minimum of five (5) years in an Information Risk Management (IRM) or Information Security related role
- Externally recognised certification (eg: CISSP/CISM/CISA) preferred
- Comfortable working with complex, ambiguous and incomplete information
- Understands the significance of commercial constraints
- Sense of realism and pragmatism, openness and approachability
- Able to plan, schedule and monitor work, within set targets
- Able to lead through influence rather than hierarchy, across organizational boundaries
- Demonstrates strong interpersonal skills
- Able to operate in virtual global environment
- Effective and persuasive in both written and oral communication
- Ideally conversant with recognised standards and methodologies for risk management
- Ideally conversant with Regulatory requirements such as FSA, SOX, Nerc/Ferc
- Demonstrated experience in staff management where influencing, developing/and or motivating people is critical to the achievement of objectives
0 comments:
Post a Comment