Key Responsibilities
-Review and analyze all port opening requests routed from the Information Security
team. Evaluate risks associated with data exposure, unauthorized access, and protocol
vulnerabilities from both a security and data privacy standpoint.
-Partner directly with Change Owners and Application Owners to dissect port requests
and change management requirements, gathering technical architecture diagrams
and evidence to inform risk decisions.
-Conduct comprehensive PSIA assessments for all major and minor change
management requests.
-Draft, update, and maintain meticulous documentation, templates, and evidence
repositories required by applicable data privacy, protection, and security regulations.
-Work alongside the Data Privacy Team to execute, refine, and provide expert feedback
on Privacy and Security by Design templates.
-Act as the primary bridge (SPOC) between Change/Application Owners and
Information Security stakeholders, fostering cross-functional alignment.
-Engage relevant stakeholders to execute the "Security of Processing" mandate for
personal data. Develop end-to-end implementation strategies, comprehensive project
plans, and manage stakeholder execution in alignment with the client's privacy policy.
-Provide actionable feedback and technical recommendations to engineering teams;
track the implementation of privacy controls to completion before changes go live.
-Pivot quickly to align deliverables with shifting project requirements and agile sprint
cycles at short notice.