General Purpose
Supports the implementation and maintenance of information security systems in support of ISO 27001 and ISO 27019 certification. Supports change management of changes to the information security policy and procedures and supporting IT controls. Manages continuous improvement program activities for cyber security for the one or more BHE US Affiliates. Performs risk assessments and manages remediation of risk mitigation actions. Researches, analyzes, develops and implements new strategies, programs, and / or processes in response to changing internal and external conditions. Coordinates or executes IT controls.
Responsibilities
Identify, prescribe, and implement key cyber security initiatives in support of ISO 27001 and ISO 27019 controls for the pipeline group. Act as advocate for the programs.
Support the development and maintenance of Information Security Management System (ISMS) for one or more BHE US affiliate.
Support the development and maintenance of information security policies, procedures, standards, controls and other related documents
Coordinate and lead interactions with internal and external cyber security auditors Execute control activities to evidence our compliance with IT controls
Lead cyber security maintenance and continuous improvement activity identified through internal processes or cyber security related audits.
Support the development and documentation BHE US Affiliate third party services and service levels for ISO 27001 and ISO 27019 scoping for the affiliates.
Consult with management, teams and individuals to provide strategical and tactical direction regarding enterprise information security requirements, policies, procedures and standards.
Coordinate updates to training materials that support the information security policies and procedures
Oversee and coordinate efforts to assess and mitigate cyber security risks and threats.
Coordinate with BHE IT and information security staff as well as BHE chief security officer staff to share best practices and cyber security initiatives.
Support reporting related to information security key performance indicators and status reporting Support business continuity planning, cyber security incident response and management. Coordinate incident response plan creation and updates
Support the enterprise as an information security subject matter expert.
Manage and coordinate forensic and investigation activities
Supports and / or leads special projects, studies and analyses, develops alternatives, presents recommendations to management and influences management decisions.
Researches, analyzes, develops and implements new strategies, programs, and / or processes in response to changing internal and external conditions.
Perform other duties as assigned
Requirements
Preferences
Sr Compliance Analyst • PORTLAND, OR, US