Job Summary
Security Governance, Risk and Compliance Analyst
Key Responsibilities
You will execute Cyber governance, risk, and compliance activities to ensure that Wella can demonstrate that its control environment is aligned with audit, risk, industry, and regulatory requirements. Work with key stakeholders to drive consistent and continuous compliance with Cyber controls framework and coordinate internal and 3rd party assessments. • Provide subject matter expertise on industry-recognized control frameworks, such as COBIT, NIST, ISO, and similar standards • Manage the development and implementation of Cyber governance, risk, and compliance policies and procedures • Develop Cyber Security Policies and Standards including a regular review and update process with key stakeholders • Provide expert-level guidance on implementation, monitoring, and evidence collection to demonstrate alignment with industry-recognized control frameworks • Plan, schedule, track, monitor, and manage issues related to audit, compliance, and risk assessments • Own the Cyber risk management function, including maintaining the cyber risk register, raising risks with support from SMEs, identifying risk treatment opportunities, overseeing risk remediation plans and running the Risk SteerCo. • Provide guidance on company policies that affect the Cyber and IT control environment • Perform periodic reviews and evaluations of Wella Cyber governance, risk, and compliance program to validate that the program adequately aligns with Cyber, audit, risk, industry, and regulatory reporting and evidence requirements • Provide subject matter expertise and guidance to the lines of business on interpretation of Cyber requirements to ensure successful completion of internal and external assessments • Ensure strategic objectives of the Compliance & Ethics Program are met in the context of Security governance, risk, and compliance, including execution of program assessment activities, coordination of response and tracking of action items for remediation • Identify areas of potential improvement • Create reporting for Cyber governance, risk and compliance activities to the wider Cyber team and key stakeholders • Own third party due diligence Cyber review process including the decision making for each Cyber Due Diligence vendor, assist with responses to audit and customer questionnaires and identify maturity and efficiency opportunities • Prepare Wella staff for planned Cyber governance, risk, and compliance assessment activities
Skill Requirements
The Cyber Governance, Risk and Compliance Analyst is responsible for ensuring that Wella can demonstrate compliance with industry standards and regulatory obligations in the use of technology to meet business objectives, including performing, tracking, and reporting on the effectiveness of controls, compliance activities, and risk assessments
Other Requirements
Experience implementing, documenting, tracking, and maintaining technology compliance frameworks • Experience performing compliance assessments, information security, risk management, and/or technology risk management