Job description
Position Summary
We are currently seeking a Sr. Manager, Business Unit Information Security Officer (BISO) to provide security leadership, consulting, and education consistent with the Realogy Global Information Security program, policies and standards as related to the Anywhere Integrated Services (AIS) business unit (BU). In addition, identify opportunities for security to enable the business and integrate information security into the business unit. This position serves as an advocate for the business but maintains a clear focus on information risk and security, helping to identify and assess risks to the business unit. The BISO will manage and coordinate all information security activities, programs and initiatives for the business unit as well as provide security incident support.
This position is a key member of the Realogy Information Security team, reporting directly to the Director, Risk Management with a dotted line to the Business Unit CIO.
This position is a key member of the Realogy Information Security team, reporting directly to the Director, Risk Management with a dotted line to the Business Unit CIO.
Responsibilities
-
As the single point of contact on information security and the liaison between the business and Information Security, the BISO’s role is to enable business strategies, while balancing the security risk; to articulate the security perspective to the business, helping them understand the potential risk impact and possible controls in business terms. To bring business knowledge to the Information Security organization to help ensure security is aligned with the business strategy and accelerates solutions with better communication and alignment.
-
Provide input to and support the delivery of communications and related campaigns for information security awareness.
-
Work with Realogy’s Cyber Security & Incident Response Team to remediate BU specific cyber security incidents.
-
Partner with BU to track and remediate vulnerabilities from monthly scans.
-
Represent the business unit in the development and maintenance of Realogy’s information security policies and standards; identify, develop, and maintain supplemental standards unique to the BU.
-
Provide consulting services to increase knowledge of Information Security standards, concerns, interpretation and clarification of policies as well as advise on BU plans to achieve compliance.
-
Primary point of contact for all IT internal audits, participates in scoping, deliverable requests, collaborate with IT senior leadership to clear audit reports and help ensure effectiveness/completeness of action plans .
-
Establish communication channels with other BISOs with an aim of strengthening relationships to efficiently tackle security issues that span multiple business units.
-
Ensure timely engagement on business and IT initiatives, providing guidance on the security risk aspect of projects.
-
Oversee client/banks information security compliance requirements, responding to and supporting inquiries, audits, proposals and presentations.
-
Help to ensure IT owners are held accountable for the state of their controls and understand their responsibilities as to risk mitigation and remediation as well as compliance to security policy & standards, reducing the likelihood of audit, regulatory & legal liabilities.
-
Proactively engage control owners to ensure corrective plans are developed to remediate defined risks and non-compliant activities and keeps abreast of action plans and their execution.
-
Educate management of the risk implications associated with business technology decisions and communicate the likelihood and impact of those decisions so management can fully quantify those risks and determine tolerance levels.
-
Provide leadership, direction, and guidance to ensure the internal security environment and use of 3 rd parties support Realogy policy and standards.
-
Assess compliance, identify opportunities to remediate non-compliant conditions and file exceptions where necessary.
-
Understand and report on the overall information security risk posture of the business unit, providing a holistic view of vulnerabilities and associated risks to the business and Information Security.
-
Focus on process improvements, removing deficiencies to manage risk, prevent/anticipate problems and identify opportunities for efficiencies and to move from manual to automated processes.
-
Understand, test and implement security plans, products and control techniques.
-
Attend and participate in internal/external forums and risk committees where appropriate.
Qualifications/Selection Criteria
-
Minimum 8-10 years in Information Technology with at least 7 in Information Security.
-
Bachelor degree or higher with a concentration in Information Technology or related discipline.
-
Security and control certifications preferred (CISSP, CISM, CISA, CRISC)
-
Experienced in Information Security programs including, but not limited to, Audit Reviews, Risk Assessment, Identity Access & Management, Data Protection, Secure SDLC, Incident Management, Third Party IS Assessment, Secure Configurations, Vulnerability Management
-
Ability to influence others and shape/obtain desired outcome in areas outside of direct control
-
Outstanding verbal, written and presentation skills to effectively communicate information security projects in business terms to various levels within the organization
-
Ability to see the big picture with high attention to critical details
-
Strong, proven problem-solving and analytical skills to resolve problems and conflicts and drive solutions through to completion
-
Strong facilitation skills and a clear ability to build strong relationships with business stakeholders at all levels, including executive managers and vendors
-
Results oriented, well organized with follow-up skills to meet deadlines; has a track record of effectively managing multiple tasks in a dynamic environment.
-
Knowledge of government and other regulations related to Information Security and Data Privacy (e.g., PCI, NYDFS, GLBA)
-
Strong risk management skills with audit experience or exposure
#LI-LG1
#LI-Remote
Exciting News: We are excited to announce that Realogy is now Anywhere Real Estate Inc. It will take a few months for us to transition to our new brand. For more information about this change, please click here .
EEO Statement: EOE AA M/F/Vet/Disability
Compensation Range:
$84,000 - $178,700; At Anywhere, actual compensation within that range will be dependent upon the individual’s skills, experience, and qualifications.
abouteureka.com is the go-to platform for job seekers looking for the best job postings from around the web. With a focus on quality, the platform guarantees that all job postings are from reliable sources and are up-to-date. It also offers a variety of tools to help users find the perfect job for them, such as searching by location and filtering by industry. Furthermore, abouteureka.com provides helpful resources like resume tips and career advice to give job seekers an edge in their search. With its commitment to quality and user-friendliness, abouteureka.com is the ideal place to find your next job.