Conduct digital risk assessments, due diligence reviews, and ongoing monitoring of third-party service providers.
Support the development, implementation, and maintenance of third-party policies, procedures and frameworks in alignment with regulatory requirements and industry best practices.
Collaborate with technology, business, and control functions to ensure effective end-to-end risk management for third-party service arrangements.
...
Take the initiative to explore and define security problems in TikTok infrastructure and products; identify the gaps between existing systems and security goals.
Define the scalable and robust security components and infrastructures evolution strategy and roadmap; lead the execution based on the company's business, industry trends and technology stack.
Lead highly motivated software engineers; interpret architectural design and goals into executable engineering plans addressing full stack security, privacy and compliance requirements; and eventually build and deliver software, which is secure-by-design.
...
The Senior Cloud Vulnerability & DevSecOps supports the Threat & Vulnerability Management operations. This role ensures that the organization’s cloud architecture, services, and workloads are secure from evolving threats by proactively identifying vulnerabilities via CI/CD pipelines and cloud security operations and driving remediation strategies.
The incumbent will define vulnerability management methodologies, mentor junior team members, and serve as a technical advisor to cross-functional teams, contributing directly to the enterprise’s overall cloud security posture.
Manage end-to-end vulnerability management for Azure and AWS environments.
...
Conduct digital risk assessments, due diligence reviews, and ongoing monitoring of third-party service providers.
Support the development, implementation, and maintenance of third-party policies, procedures and frameworks in alignment with regulatory requirements and industry best practices.
Collaborate with technology, business, and control functions to ensure effective end-to-end risk management for third-party service arrangements.
...
Support the development of a central repository for MDOT risk assessment reports that facilitates comprehensive visibility of device security status and standardized risk documentation
Support the refinement for a standard risk report template and format for use across public healthcare, aligned to Healthcare Cybersecurity & Technology Risk Management Framework (HCTRMF)
Prepare template(s), workflow(s) including access controls for implementing information sharing
...