Deskripsi Pekerjaan
Join Optum as a Senior Information Security Engineer specializing in Risk Governance, Risk & Compliance (GRC), Vendor Risk Management, and Security Education, Training & Awareness. In this critical role, you'll be the driving force behind our cybersecurity risk management framework, assessing and prioritizing threats to protect our digital assets. You'll evaluate third-party vendor security postures, ensure regulatory compliance with industry standards, and translate complex security metrics into actionable business insights. Your expertise will shape our security culture by designing and delivering engaging employee awareness programs, fostering a vigilant organization that proactively defends against cyber threats. Collaborate with cross-functional teams to embed security best practices across all operations while maintaining alignment with Optum's strategic objectives.
Tanggung Jawab
- Conduct comprehensive cyber risk assessments and prioritize vulnerabilities using industry-standard frameworks
- Manage vendor risk evaluations through security audits, questionnaires, and continuous monitoring
- Develop and implement security awareness training programs tailored to diverse organizational roles
- Generate executive-level security metrics dashboards and compliance status reports
- Establish and maintain GRC documentation including policies, procedures, and audit trails
- Lead security awareness campaigns and phishing simulation exercises to reinforce security behaviors
- Collaborate with IT teams to integrate security controls into vendor onboarding processes
- Stay current with emerging threats and regulatory changes to update security strategies
Kualifikasi
- Bachelor's degree in Information Security, Computer Science, or related field (Master's preferred)
- 5+ years of experience in information security with focus on risk management or GRC
- Professional certifications (CISSP, CISM, CRISC, or equivalent)
- Expertise in vendor risk assessment frameworks and third-party management tools
- Experience developing security awareness programs and training materials
- Strong analytical skills with ability to translate technical concepts for non-technical stakeholders
- Knowledge of compliance frameworks (ISO 27001, NIST, PCI DSS, GDPR)
- Excellent communication skills with proven ability to present to executive leadership