Security Governance Resume Sample
Work Experience
- Ensure completeness and validation of all risk assessments
- Consult with process and control owners on how to remediate open findings
- Develop relationships with each of the process and control owners supported and ensure that ownership of controls are understood and managed
- Manage milestones and timelines for IT Security Governance and Compliance efforts pertaining to NY DFS cybersecurity regulations
- Support attestation and sub-attestation processes
- Ensure GRC platform functionality meets Pearson’s needs during the initial platform build-out to steady-state and beyond
- Maintain a corporate governance structure for institutionalizing security governance within all levels of the organization
- Experience in I/T or Security including 5 years of experience directly managing a team
- Understand complex technical information
- Superior written and oral communication skills; ability to express complex thoughts clearly, know how to listen and contribute in a team environment
- Strategic thinker, leader and high achiever
- Work successfully in a matrixed IT and business team environment
- Prioritize tasks in order to meet deadlines and deliver measurable results
- Experience building and leading a high performing team and establishing strong working relationships with business partners
- Build teams, mentor team members, identify process improvements, and lead enterprise wide security initiatives
- Information Security background including an understanding of the basic security best practices, standards and methodologies
- Demonstrated ability to work across organizational boundaries, and influence others
- Define and manage internal projects and milestones, and demonstrated leadership skills
- Proven problem solving, critical thinking and business risk analysis skills
- Both lead and partner in a team environment
- Strong investigative, analysis, conflict resolution and negotiation skills
- Relative experience in a global information technology environment with a background in GRC
- Strong knowledge of security and risk frameworks including: ISO 2700x, NIST 800
- Proven project management skills and experience are required
Education
Professional Skills
- Strong organizational skills, ability to effectively manage multiple, competing projects/priorities while achieving targeted completion results
- Strong verbal and written communication skills - experience in Audit/Compliance/Regulatory discussions
- Experience with GRC applications. LockPath Keylight skills are desirable
- Excellent organizational, people, written and verbal skills
- Skills in documenting risk and compliance activities
- Experience in information security, and 5-10 years’ experience in information technology
- Providing guidance on how to build cohesive security and compliance programs to effectively address regulatory requirements
How to write Security Governance Resume
Security Governance role is responsible for compliance, security, database, travel, credit, training, auditing, architecture, analysis, reporting.
To write great resume for security governance job, your resume must include:
- Your contact information
- Work experience
- Education
- Skill listing
Contact Information For Security Governance Resume
The section contact information is important in your security governance resume. The recruiter has to be able to contact you ASAP if they like to offer you the job. This is why you need to provide your:
- First and last name
- Telephone number
Work Experience in Your Security Governance Resume
The section work experience is an essential part of your security governance resume. It’s the one thing the recruiter really cares about and pays the most attention to.
This section, however, is not just a list of your previous security governance responsibilities. It's meant to present you as a wholesome candidate by showcasing your relevant accomplishments and should be tailored specifically to the particular security governance position you're applying to.
The work experience section should be the detailed summary of your latest 3 or 4 positions.
Representative Security Governance resume experience can include:
- Maintain Hyatt’s PCI compliance program, working with diverse teams throughout Information Technology and the Global Operations Center to ensure that Hyatt handles cardholder data in an appropriate way
- Technical skills necessary to support and manage MS SQL Server 2008 and above, MS SQL Integration Services 2008 and above and Tableau
- Data protection and 5 years of leadership experience
- Experience in scripting languages like C# and VBscript
- Provide regulatory compliance support, scope management and communication, defining evidence requirements and program management as required
- Experience in Data Management in both technical and analytics roles
Education on a Security Governance Resume
Make sure to make education a priority on your security governance resume. If you’ve been working for a few years and have a few solid positions to show, put your education after your security governance experience. For example, if you have a Ph.D in Neuroscience and a Master's in the same sphere, just list your Ph.D. Besides the doctorate, Master’s degrees go next, followed by Bachelor’s and finally, Associate’s degree.
Additional details to include:
- School you graduated from
- Major/ minor
- Year of graduation
- Location of school
These are the four additional pieces of information you should mention when listing your education on your resume.
Professional Skills in Security Governance Resume
When listing skills on your security governance resume, remember always to be honest about your level of ability. Include the Skills section after experience.
Present the most important skills in your resume, there's a list of typical security governance skills:
- Good – Excellent writing and verbal communication skills
- Good - Excellent writing and verbal communication skills
- Strong communication and collaboration skills supporting multiple stakeholders and business operations with both technical and non-technical
- Build effective working relationships, making sound decisions, successfully making changes, initiating action and achieving results as a trusted advisor
- Experience responding to, analyzing, and communicating information security incidents
- Experience or knowledge of administering an on-going security awareness program and related tools
List of Typical Experience For a Security Governance Resume
Experience For Information Security Governance & Risk Management Director Resume
- Partner with risk management to ensure the transparent communication of risk reporting related to compliance revaluations and identified gaps
- Track remediation of any gaps to compliance with the implementation area to ensure closure and tracking to deadlines
- Best practices in information security
- Analyze potential impacts of new policy developments and existing policy gaps on the firm’s operations, develop cyber policy positions and draft consultation paper responses
- Compliance program support, scope management, along with 2nd level triage of consultative requests engaging Internal Security Assessor (ISA), Qualified Security Assessor (QSA), external auditors, security architects, and program management as required
Experience For Principal Security Governance Resume
- Analytical thinking – logically breaking problems down into essential elements, diagnosing and developing solutions
- Sound knowledge of current and emerging technologies in reporting and data analytics
- Review new regulations for security impact and document requirements for compliance
- Communicate requirements and compliance status to security leadership and impacted technical teams
- Coordinate project managers and participate in meetings to ensure the accuracy of scoping, requirements documentation, gap identification, remediation and compliance requirements are met
- Support delivery/implementation leads in promoting and consulting on the positions that help strengthen and secure the organization in alignment with regulatory requirements, by either following standards or helping direct others on technology positions
- Help facilitate review of changes in company processes, standards and technology to ensure the effectiveness of security controls to meet compliance requirements
Experience For Physical Security Governance & Policy Consultant Resume
- Help consult with stakeholders on requirements for new and existing business / technology solutions to assure compliance to regulations, compliance frameworks and internal standards and governing policies and procedures
- Provide Archer GRC tool administration for security controls assessment workflow and evidence gathering within the compliance and issues management modules
- Develop and maintain new and existing policies and standards associated with data and information security, supporting regulatory and compliance requirements
- Strong audit and compliance assessment skills, ability to effectively define gaps, evidence and remediation requirements while achieving targeted delivery results
- Responsible to establish, communicate and maintain Cybersecurity policies, standards and guidelines. Ensure that Cybersecurity requirements are practical and communicated to all relevant parties
- Work with Information Security Architecture team on emerging and new security technologies for possible adoption and update the Cybersecurity policy, standard and guidelines
- Work with Information Security Advisory and Operations team to ensure effective implementation of the Cybersecurity policy, standards and guidelines
- Ensure the ongoing alignment of InComm Security Program(s) with best practices and regulatory requirements
Experience For Director IT Security Governance & Risk Resume
- Support implementation and monitoring of policies and standards
- Perform periodic review and updates on the Cybersecurity policy, standards and guidelines
- Work with various internal stakeholders to evaluate risks associated with the creation, storage, protection and transmission of private, proprietary and non-public data, including identification of internal and external security drivers and continued alignment of risk management frameworks
- Develop portfolio views and reporting for information and data risks, supported by controls matrix in the areas of Business Resilience, Compliance, and Security
- Understanding of common security standards and regulations, and
- Maintain up-to-date knowledge and understanding of technology trends, security threats, infrastructure vulnerabilities affecting information risk
- Identify, coordinate, and manage new / existing projects
Experience For Director, Information Security Governance Resume
- Manage team assignments and tasking to ensure complete coverage of all assigned tasks
- Financial management of your team, which includes hardware, software, and staffing
- Standards and testing,
- Support risk management activities for third and fourth party information risks
- Manage InComm and affiliate engagements with internal and external stakeholders, including customers, business partners, auditors, regulators, and other third party entities to ensure that all security and compliance needs are appropriately addressed in a timely manner
Experience For Senior Security Governance Consultant Resume
- Effective system-wide security analysis,
- Providing leadership and project management expertise,
- Development of policies, standards and guidelines
- Ensure operational environment remains operational
- Ensure tasks are completed as planned
- Complete service and change requests on schedule
- Manage and optimize costs with close focus on under runs and over runs
Experience For Senior Analyst Cyber Security Governance Resume
- Manage all personnel needs and interact with HR when required
- Perform annual personnel write-ups and reviews
- Ensure that any technical proposal needs are supported
- Ensure personnel performance
- Awareness and education,
- Defines an ISGRM strategy, with a roadmap of key deliverables and timelines, and delivers consistently. Leads large cybersecurity initiatives with a focus on risk management and compliance. Oversees the design of best practice solutions and work plans for the University’s governance and risk management in collaboration with internal and external resources
- Engage in high level security consultancy missions such as risk and compliancy assessments. The primary deliverables of these engagements, based on Dimension Data methodology, are composed of an analysis of the client’s current situation in term of existing security vulnerabilities together with recommendations for improvement and future evolution
List of Typical Skills For a Security Governance Resume
Skills For Information Security Governance & Risk Management Director Resume
- Experience performing information security audits or risk assessments
- = Experience performing security and privacy functions in large scale, global environments and organizations
- Information security experience in Federal government
- Agile-based knowledge and skill
- Experience in conducting Threat Risk Assessments (TRAs) as per the HTRA methodology
- = Experience with security practices such as security incident response and risk management
- Understanding of leading industry guidance and best practices (e.g., NIST, ISO, COBIT, OWASP, ITIL)
- Providing guidance on the adequacy of the security controls mapped to the top-down information security strategy, policies and guidelines
- Helping clients build education and awareness programs on security issues, best practices, and vulnerabilities
Skills For Principal Security Governance Resume
- Helping clients build information technology state-of-the-art risk management through to address and mitigate security risk
- Knowledge of securing network technologies, client, and server operating systems
- Familiarity with security auditing processes
- IT strategy, strategy, networking and operations practices
- In addition to the Dallas/Fort Worth, TX area, we are open to candidates in the Charlotte, NC market to work in our offices there
- Knowledge of information security risk management frameworks and compliance practices
Skills For Physical Security Governance & Policy Consultant Resume
- Develop security standards and guidelines based on best practices and industry standards
- In addition to Charlotte, we are open to candidates in the Dallas/Ft. Worth, TX market to work in our offices there
- Evaluate systems and environments to assess security exposures
- Direct knowledge of and exposure to SOX, PCIDSS, SSAE 16/18 requirements
- IT general controls (ITGC) and development processes (SDLC)
- Develop and foster relationships and promote collaborations across multiple stakeholder groups
- Acting with integrity and commitment to Dimension Data’s core values of Pro-activity, Teamwork, Professional Excellence, Partnership, Client Commitment and Multi-Cultural Strength is essential for a successful career
- Take the full responsibility for the quality as well as the practical delivery of more complex projects (executed in virtual team) ensuring that the quality delivered in the reports adheres to both Dimension Data and the client’s requirements
Skills For Director IT Security Governance & Risk Resume
- Helping clients build a global strategy for dealing with audits, compliance checks, pen testing and assessment processes
- Actively participate to the enhancement of Dimension Data consulting methodology through the writing of use case, definition of additional best practices,….
- =Deep and broad understanding related to security encompassing control technologies, policies and standards, risk and compliance, audit, data privacy etc
- Act as a lead consultant fulfilling the role of a Single Point of Contact towards the clients
- Steer and assist colleagues
- Perform business development and presales work for opportunities within his own domain
- Evaluating client’s information security strategy, governance processes and programs and assisting him in building the strategic information security roadmap
- Supporting and assessing the development and implementation of effective policies and practices to secure information and technology systems and ensure information security and compliance with client-relevant legislation
- Experience in security solutions or related business
Skills For Director, Information Security Governance Resume
- =Excellent verbal and written communication skills with a wide range of audiences including technologists, executives, business stakeholders and IT team members
- =Experience in leading matrix global teams
- Demonstrated capacity to learn, intellectual honesty and independent thinking
- Good understanding of established security frameworks, particularly ISO 2700X
- Experience in IT security or related field. 5+ years’ management
- Serve as an effective and inspirational leader for a team of junior and senior-level information security governance analysts
- Knowledgeable in basic security auditing practices and design of security controls
- Perform or being involved in vendor and security solutions audits in accordance with industry and Technicolor established methodologies
Skills For Senior Security Governance Consultant Resume
- Familiar with web-related publishing technologies to perform basic administration of security web resources
- Familiar with process modeling and process workflow design
- Expert level in Information Security Management technology solutions and strategies
- One or more recognized industry designations
- Familiar with security policy lifecycle process
- Available for light travel (domestic and international)
- Provide active direction, periodically review team results, and identify and execute adjustments to ensure achievement of team goals and planned outcome while contributing to the overall business strategy
Skills For Senior Analyst Cyber Security Governance Resume
- Ensure alignment between business strategy and direction. Support strategic technology planning by identifying, tracking, and experimenting with new and potentially disruptive technologies
- Create compelling strategic visions for Information Security Management and see them through to fruition by influencing senior executives and other stakeholders
- Inspire and lead a team of data analysts that facilitate data-driven storytelling for CIS
- Evaluate technology and Information Security trends in order to achieve value as part of a business strategy. Combine a broad knowledge of the potential value in emerging Information Security technologies and a keen understanding of how these technologies can affect Nike’s business and Information Security processes
- Assess the compatibility and integration of products/services proposed as standards in order to ensure an integrated architecture across interdependent technologies
- Need to demonstrate a proven track record of successfully managing large technology project-portfolios in a product-driven environment and accountability of deadlines and value propositions
- Manage project budgets, scope, and conduct resource planning for risks that are proactively identified
- Lead security design and change activities by providing direction and technical assistance to functional teams throughout project and sustainment activities
- Adapt and be productive in a dynamic environment
Skills For IT Security Governance Program Manager Resume
- Integrate SAP security design, governance within the overall PepsiCo IT and business control environment through partnership with global and local control teams
- Gain alignment from senior business leadership on security strategies/ key design decisions to ensure design requirements are actioned correctly
- Own and continuously improve / enhance security role change management tools utilizing internal ticketing tools, templates and internal websites - understand /utilize project documentation tools and systems in compliance with project standards
- Assist business resources in mitigating SOD violations via the implementation of mitigating controls, removing conflicting business access
- Integrate analytics into SOD reporting processes to provide insight into actual versus potential SOD risks to the environment
- Manage Hyatt’s relationships with our credit card partners, ensuring all relevant timelines for document submissions are met
- Own and periodically update Hyatt’s Cyber Security Policies, taking into account the feedback of stakeholders and current events to craft a cohesive and readable document
Skills For Director of Information Security Governance Resume
- Review evidence submissions to ensure regulatory requirements are met and validation of gap closure
- Coordinating the Cybersecurity standards, strategies and responses across Group IT and Business Units is essential
- Taking Initiative – engaging in pro-active behaviour, seizing opportunities
- Ensure that Badging / Security Training for both Leidos and CMS in maintained in a coordinated, controlled manner
- Lead the design and implementation of Pearson’s Risk Management tool
- Drive a program to manage risk through Pearson’s transition to a cloud-based service provider
- Manage Hyatt’s Security Awareness program, continuously identifying and implementing new and innovative methods of educating our colleagues on cyber security risk
Skills For Information Security Governance Director Resume
- Track certain vulnerabilities identified by the cyber security team, ensuring remediation in a time frame that is compliant with Hyatt’s cyber security policies
- Vendor Risk Management—Develops and executes the process for managing 3rd party risk as well as validating the capabilities and compliance posture of SecureWorks’ vendors
- Working knowledge of the following (specifically as it relates to information security governance)
- Security governance and enterprise management tools (eg, RSA Archer)
- Data security standards prescribed by such standards bodies as PCI, HIPAA, NERC/CIP as well as government standards such as NIST, Fedramp, etc
- License, Certification, Registration
- SANS GIAC, GSEC, CISSP or equivalent
- Information security audit practice
- Software development standards and security (Linux, windows)