Job Description
Job Description Position Information:
Under the general guidance of the Chief Information Security Officer (CISO) and in cooperation
with the Security Team Lead, this position is responsible for providing advanced security policy
analysis. This position is responsible for developing and maintaining information security
policies and workforce training and awareness. This position serves as a resource for staff and
leaders regarding information security policy implementation, interpretation, and compliance
This position may lead projects to implement new security controls. This position will also have
daily, weekly, and monthly duties operating security control systems in place at ETF. It will
monitor compliance with security policies and procedures.
Required Skills:
• IT Security – 5+ years
• IT Professional – 8+ years
• Project leadership experience – 4+ years
• Experience evaluating and implementing vendor security offerings – 4+ years
• Strong attention to detail
• Excellent communication skills (written and verbal)
Preferred:
• CISSP or equivalent – 1 year
Regular duties may include the following representative tasks:
• Information Security Risk Assessment: Identifies, analyzes, evaluates, and documents
information security risks and controls based on established risk criteria.
• Risk Management: Measure, monitor and manage risks related to the use of Information
Technology, Information Security, Privacy, Regulatory Compliance, and Governance.
Ensures and monitors compliance with industry and government rules and regulations at
all levels.
• Control Implementation: Assist the security team to conduct gap analysis and
implements frameworks and standards such as ISO 27001, NIST, and CSC. Engage
with your stakeholders to identify issues, understand their needs and challenges to
proactively find ways the program can support those needs.
• Coordination: Provides coordination to the GRC team by setting goals, objectives,
performance metrics, and ensuring that the team is aligned with the organization’s
mission3. Develops strategies to improve the effectiveness of the GRC program.
Requirements Required Skills:
IT Security – 5+ years
IT Professional – 8+ years
Project leadership experience – 4+ years
Experience evaluating and implementing vendor security offerings – 4+ years
Strong attention to detail
Excellent communication skills (written and verbal)
Nice to have:
• CISSP or equivalent – 1 year
