Assists and supports the organization in complying with, as well as the ongoing preparation, testing and monitoring of conformance to, the requirements of government regulations and / or regulatory agencies specific to Information security requirements.
Leading contributor individually and as a team member, providing direction and mentoring to others. Work is non-routine and very complex, involving the application of advanced technical / business skills in area of specialization. . Ability to travel. 6 plus years' experience. BA / BS or advanced degree preferred. 5-7 years work in governance and compliance for a large corporation. Preferred candidate with certification CISA, CISM, and CISSP. Strong knowledge of IT and / or quality auditing and controls, preferable with NCA CCC, ECC, DESC, SOX, SSAE 16 - SOC 1 & SOC 2, PCI compliance, ISO 27001 & ISO 27002 and / or, ISO 9001. Knowledge and understanding of the delivery process for validated systems; specifically, Computer System Validation process or CSV. Have an understanding of security and / or quality management system standards and risk management. Experience working in Information Technology, Cloud or managed hosting services. Excellent written and verbal communication skills. Ability to adjust and adapt to changing priorities in a dynamic environment. Technical acumen and the ability to understand and interpret technical specifications. Technical knowledge of Oracle cloud infrastructure components. Project Management skills.
Performs evaluation of internal operations, controls, communications, risk assessments and maintenance of documentation as related to regulatory compliance and recommends appropriate changes. Conducts and facilitates internal and external audits to identify, evaluate, disclose and appropriately remedy risks and deficiencies. Coordinates the preparation of and may prepare document packages for regulatory submissions from all areas of company as well as for internal and external audits and inspections. May serve as point of contact for interactions with regulatory agencies for defined matters. Management systems. Review specifications. Develop training for cloud services, on industry regulatory specifications applicable to their products and services. Identify industry requirements applicable to OCI, and work with members of OCI Service teams and operations teams to incorporate applicable industry regulatory standards, Oracle security and / or quality policies and customer-contractual obligations into OCI processes and standards. Coordinate industry and regulatory certifications, including managing certification vendors (., NCA CCC ECC, ISO, GSMA, SOC). Build management level metrics and reporting for activities that are owned by the Risk Manager. Execute a vendor security and / or quality management program.
Career Level - IC4
Compliance Specialist • Saudi Arabia