Jobs

    Governance, Risk, Compliance Technology Lead - Pennsylvania, United States - First Quality

    First Quality
    First Quality Pennsylvania, United States

    2 weeks ago

    Default job background
    Description

    First Quality was founded in 1989 and, in nearly three decades, has grown to be a global privately held company with over 4,000 employees. Its corporate offices are located in Great Neck, New York, with manufacturing facilities and offices in Pennsylvania, South Carolina, Georgia, and Canada. First Quality is a diversified family of companies manufacturing consumer products ranging from Absorbent Hygiene (adult incontinence, feminine care, and baby care), Tissue (bath and towel), and Industrial (print and packaging materials), serving institutional and retail markets throughout the world. First Quality focuses on private label and branded product lines.

    Our core business philosophy is built on a proud culture driven by safety and quality, respect, humility, integrity, customer focus, and teamwork. With leading edge manufacturing technologies and processes and visionary leadership, First Quality is positioned to continue significant growth in the coming years.

    The Information Security GRC Technology Risk Lead is responsible for the development and delivery of First Quality's Information Security Program which includes information security risk management across First Quality Enterprises. This program ensures that all physical and digital information assets and technologies, as well as employee, client and First Quality data are adequately protected. This role is responsible for defining and maturing the 2nd line of defense and providing management with updates on the overall security posture of the organization. This role currently has 1 direct report and will report to the Manager of Information Security Governance, Risk, Compliance and Strategy.

    ESSENTIAL DUTIES AND RESPONSIBILITIES

    The GRC Technology Risk Lead will be tasked with leading the following Information Security Programs; Enterprise Technology Risk Management, Data Governance, Security Awareness & Training, and Compliance. This position will work alongside the Manager of Information Security Governance and other IS team members to identify ways to innovate and mature the Information Security program. This Lead will be directly responsible for conducting IS technical risk assessment of First Quality systems and platforms against industry standards and frameworks such as the Center for Internet Security (CIS). This is a technical role where the candidate is expected to identify system misconfigurations, weaknesses, gaps, and associated risks across a wide variety of platforms.

    Enterprise Technology Risk Management

    • Directly responsible for performing technology risk assessments and control assessments to ensure systems and applications (on prem and in the cloud) are complying with First Quality policies, applicable regulatory and legal requirements, and leading industry practices.
    • Updating the Business Impact Analysis (BIAs) plans to determine key systems to assess.
    • Maturing the Information Security Risk Management Program by managing the IS risk register and ensuring appropriate risk management strategies are in place and followed up on.
    • Meet with business stakeholders to quantify risks across the organization and maintain the top board level security risks.
    • Develop and drive the implementation of security best practices and standards to mature the overall IS Risk Management Program which includes defining security system and application standards of control.
    • Provide solutions to identified issues and risks.
    • Works with the Manager of Information Security Governance, Risk, Compliance and Strategy to determine the acceptable level of risk for enterprise computing platforms.
    • Liaise with key functional teams such as HR, IT, Digital Marketing, Finance, Internal Audit, Enterprise Risk, Quality, Office of General Counsel and the Business to identify new applications and service providers in use and the associated security controls to secure the data.

    Data Governance

    • Investigates incidents and events that include potential HIPAA and other data breaches, data leakage, brand reputational risks, malware propagation, system compromises etc.
    • Assist with maturing the Data Loss Prevention Program by reviewing and enhancing security technologies such as MS Purview and Compliance Center, Crowdstrike, Palo Alto, Netskope etc.
    • Establish and maintain Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs) for the Data Governance Security Program and initiatives.

    Security Awareness & Training

    • Oversee the enterprise wide IS Security Awareness Program which includes phishing simulations, computer-based training, proactive communications on latest threats, workshops and newsletters.
    • Promote a security mindset through enterprise and functional team specific presentations and initiatives.

    Compliance

    • Work with the Office of General Counsel and both the Director and Manager of Information Security Governance, Risk, Compliance and Strategy to ensure the Information Security team stays abreast of new regulatory, legal and/or compliance security and privacy requirements to compliance against.
    • Ensure compliance with HIPAA and applicable legal and regulatory requirements.

    QUALIFICATIONS: To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform essential functions.

    • B.S. in a technology discipline (Computer Science, Information Management, Computer Engineering, Cybersecurity or equivalent); Security certifications such as CompTIA Security +, CISSP, CISA, CCNA or equivalent or working towards certification is preferred
    • 6+ years' experience working directly in an Information Security or Information Technology department with experience in developing testing security frameworks for compliance
    • Hands-on experience with assessing security configurations in Windows/Mac/Linux environments, Azure and other cloud environments, SQL and Oracle databases.
    • Experience with Netskope, Azure Purview, OneTrust or similar GRC tools is a plus.
    • Experience with Operational Technology (OT) environments and securing manufacturing devices a plus.
    • Strong knowledge & understanding of endpoint, server, network design and topologies.
    • Strong understanding of a "hacker's" mentality.
    • Excellent written and oral communication skills; ability to lead discussions, present complex ideas to audiences of all sizes, and interact with all levels of the organization.
    • Ability to self-manage, work independently with little direction and/or supervision but also work collaboratively in a team environment.
    • Working knowledge of the following frameworks and regulations: ISO 27001/2, NIST 800-53, NIST CSF, CIS Benchmarks, ISF Standard of Good Practice, HIPAA Privacy Rule and Security Rule, MITTRE ATT&CK framework.
    • Ability to prioritize and multitask and a work approach that supports flexibility and adaptability is paramount.
    • Detail oriented and ability to think outside of the box to propose solutions to risks.
    • Ability to communicate security risks to non-technical business stakeholders.

    Estimated annual base salary range for this position is $110,000- $140000.

    Base pay is only part of our total compensation package, which also includes an attractive annual discretionary bonus and robust suite of employee benefits for which you are eligible to participate in starting on your first day of employment.

    Base pay offered will be determined on an individualized basis and we will consider your location, experience, and other job-related factors.

    First Quality is committed to protecting information under the care of First Quality Enterprises commensurate with leading industry standards and applicable regulations. As such, First Quality provides at least annual training regarding data privacy and security to employees who, as a result of their role specifications, may come in to contact with sensitive data.

    First Quality is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, sexual orientation, gender identification, or protected Veteran status.



  • First Quality Pennsylvania, United States

    First Quality was founded in 1989 and, in nearly three decades, has grown to be a global privately held company with over 4,000 employees. Its corporate offices are located in Great Neck, New York, with manufacturing facilities and offices in Pennsylvania, South Carolina, Georgia ...

  • Prokatchers

    Local Contract RDN

    1 week ago


    Prokatchers Philadelhphia, PA, United States Temporary

    Prokatchers is seeking a local contract RDN - Registered Dietitian Nutritionist for a local contract job in Philadelhphia, Pennsylvania. · Job Description & Requirements · Specialty: RDN - Registered Dietitian Nutritionist · Discipline: Allied Health Professional · Duration: 13 w ...


  • First Quality Pennsylvania, United States

    First Quality was founded in 1989 and, in nearly three decades, has grown to be a global privately held company with over 4,000 employees. Its corporate offices are located in Great Neck, New York, with manufacturing facilities and offices in Pennsylvania, South Carolina, Georgia ...

  • Morefield

    Network Administrator

    3 weeks ago


    Morefield Pennsylvania, United States

    Do you enjoy working with these tools? · Windows Server and PC Operating Systems · Microsoft Active Directory and Azure AD · Microsoft Cloud Solutions (O365, Azure, Intune, Sharepoint, OneDrive) · Virtualization Technologies (vSphere, HyperV) · Application Delivery Technologies l ...


  • e&e IT Consulting Services, Inc. Pennsylvania, United States

    &e is seeking a Senior Architect with .net and Azure expertise for a remote opportunity An eligible candidate must be able to attend an onsite interview and come on site the first day. · The Role: · We are seeking a highly skilled and seasoned Senior Architect to lead the design ...

  • CRED iQ®

    VP of Engineering

    4 weeks ago


    CRED iQ® Pennsylvania, United States

    Role Overview · We are actively seeking a Vice President of Engineering with a minimum of 10 years of experience to join its software development team. The successful candidate will contribute greatly as a partner to the CEO, CTO, and will be a member of the executive team. The c ...


  • Hamlyn Williams Pennsylvania, United States

    The Vice President of Engineering and Automation is a strategic leadership role responsible for overseeing the engineering, automation, and maintenance functions within our pharmaceutical manufacturing facilities. This role is critical for driving innovation, ensuring operational ...


  • e&e IT Consulting Services, Inc. Pennsylvania, United States

    e&e is seeking an Enterprise Architect Application for a hybrid (1 day on site) contract opportunity in Harrisburg, PA · The enterprise architect focuses on application architecture and is a leader for enterprise application design and development. This role sets enterprise archi ...


  • YASH Technologies Pennsylvania, United States

    We are seeking a highly experienced AWS Cloud Infra and DevOps Technical SME with over 12+ years of experience. The role involves support of AWS cloud infrastructure design, implementation, and management, and collaborating with various teams to drive automation and scalability. ...

  • Prorec Resource Solutions, LLC

    Dotnet Developer

    2 weeks ago


    Prorec Resource Solutions, LLC Pennsylvania, United States

    Join Our .NET Developer Talent Pool for Future Opportunities in Harrisburg, PA · We are not accepting unsolicited resumes or applications from recruitment agencies or third-party providers for this posting. · Location: Harrisburg, PA · Employment Type: Full-Time / Contract - Fut ...


  • Proclinical Staffing Pennsylvania, United States Full time, Freelance

    Biopharmaceutical Manufacturing Associate - Contract - Kings of Prussia, PAProclinical is seeking a dedicated and energetic Biopharmaceutical Manufacturing Associate. This is a contract position located in King of Prussia, PA. · Primary Responsibilities:This role involves perform ...

  • Central Transport

    Terminal Manager

    2 weeks ago


    Central Transport Pennsylvania, United States

    Job Description · Central Transport LLC is one of the nation's most reliable and technologically advanced LTL (Less-than-Truckload) carriers to date. We are privately owned and have been servicing manufacturing & retail companies of all sizes for almost 90 years now. With over 20 ...


  • FPC of Savannah Pennsylvania, United States

    Our client is a top-tier manufacturer of high-quality building materials. They're seeking a full-time Sr. R&D TPO Scientist based in Carlisle, PA, offering relocation assistance if needed. · This role involves working in the TPOResearch and Innovation team to develop cutting-edge ...


  • UPMC Pennsylvania, United States

    UPMC is a leader in providing life-changing medicine. Let us provide you with a life-changing career caring for our friends and neighbors in Central Pennsylvania. First and foremost, there's something truly special about the sense of community that permeates throughout our regio ...

  • Briarlake Partners

    Production Planner

    1 week ago


    Briarlake Partners Pennsylvania, United States

    Briarlake Partners is a supply chain focused recruiting firm. We are working with a Philidelphia-based manufacturing client who is searching for a Production Planner. This role is responsible for ensuring manufacturing capacity and material resources are available to meet current ...


  • University of Pittsburgh Medical Center Pennsylvania, United States

    UPMC Central PA - a growing, multisite health care system in south central Pennsylvania - has an exciting opportunity for an Adult Endocrinologist in Mechanicsburg, PA. Join a successful practice specializing in the treatment of diabetes, thyroid, pituitary, osteoporosis, and men ...


  • First Quality Pennsylvania, United States

    First Quality was founded in 1989 and has grown to be a global privately held company with over 4,000 employees. Its corporate offices are located in Great Neck, New York, with manufacturing facilities and offices in Pennsylvania, South Carolina, Georgia, and Canada. First Qualit ...

  • Hobson Prior

    VP of Product

    5 days ago


    Hobson Prior Pennsylvania, United States Full time

    Hobson Prior is collaborating with a healthcare technology company that is seeking a VP of Product based in Washington. This position offers a unique opportunity to spearhead the creation of innovative B2B data analytics products tackling complex healthcare challenges. The succes ...


  • Ophelia Health, Inc. Pennsylvania, United States

    Do you want to improve the lives of patients with opioid use disorder (OUD)? Join Ophelia and help improve patient access to evidence-based, high-quality treatment they deserve, with medication for OUD (MOUD). · When the x-waiver was still a requirement, fewer than 5% of eligible ...


  • Russell Tobin Pennsylvania, United States

    Change Management Lead · Fully Remote · 6 Months Contract · $ /hr. W2 · Overview: Seeking a skilled Change Management Lead to spearhead a Data & Analytics platform modernization initiative. This role encompasses both change management responsibilities and project management aspe ...