Senior Analyst leading cybersecurity governance initiatives at Elsevier. Developing and maturing governance programs for data protection and risk management across the organization.
Responsibilities
Leading the design and implementation of a policy- and standards-driven cybersecurity governance program supported by GRC tooling
Establishing and maturing a data governance and protection program across the full data lifecycle
Defining and enforcing data classification, labeling, and handling requirements, including controls to prevent inappropriate data sharing
Establishing and maintaining enterprise security governance structures, roles, and accountability
Serving as a trusted advisor to business and technology stakeholders on governance, risk, and compliance matters
Driving identification, escalation, and resolution of cybersecurity GRC risks and issues
Supporting and maintaining cybersecurity compliance certifications and initiatives (e.g., ISO, PCI, HIPAA)
Producing metrics, KPIs, and executive-level reporting to support risk-based decision making
Requirements
Possess extensive experience in cybersecurity governance, risk, and compliance programs
Proven experience developing and managing security policies, standards, and controls
Experience building or maturing enterprise data governance and data protection programs
Working knowledge of security and compliance frameworks such as ISO 27001/27701, ISO 27017/27018, ISO 42001, HIPAA, PCI DSS, NIST 800-53/800-171, FedRAMP, and/or TX-RAMP
Experience implementing and operating GRC platforms and security programs
Possess project management, analytical, and problem-solving skills
Cybersecurity Specialist protecting DSV Contract Logistics IT platforms. Manage cybersecurity risks and embed security into IT solutions while ensuring operational continuity.
Regional Security Manager responsible for security operations at EMEA Data Centers. Collaborating with cross - functional teams for compliance and incident management.
Chargé.e d’Etudes et Travaux en systèmes électromécaniques de sécurité at RATP Infrastructures. Responsible for ensuring technical compliance and supervising project activities on - site.
Senior Infrastructure Security Engineer handling cloud security and infrastructure lifecycle for Zocks, a fintech startup. Responsible for security initiatives and compliance readiness in a rapidly growing team.
Data Center Security Officer ensuring safety and security for data center clients through patrols and monitoring. Conducting reports and maintaining client security requirements.
Cybersecurity Specialist overseeing the protection of clients' technology systems and networks. Implementing cybersecurity policies and conducting evaluations against cyber threats in a supportive working environment.
Information Security Manager responsible for steering InfoSec programs globally at ZEISS. Leading cross - functional initiatives and risk management strategies in a high - tech environment.
Senior Cybersecurity Incident Responder at ZEISS handling technical incident response activities. Collaborating with cyber defense teams to ensure effective incident management and resolution.
Providing security incident management for industrial environments at Telefónica Tech. Utilizing various monitoring platforms to enhance security posture.