This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Cybersecurity Risk and Controls Analyst within Amgen’s Cybersecurity and Digital Trust (CDT) organization plays a critical role in maintaining and advancing the internal controls environment by working with cross-functional teams at Amgen to assess and evaluate security risks and controls in information systems and projects. The individual will support assigned capabilities within the Governance, Risk and Compliance (GRC) team, with a focus on risk management activities like engaging and leading discussions with internal and external stakeholders, evaluating, documenting and communicating information security risks, recommending and testing IT controls and advising on improvements of IT controls.
Job Responsibility:
Advise project teams and application owners on information security risks and controls
Participate in projects or initiatives where a security risks and controls specialist is needed, with a focus on addressing risks by ensuring appropriate security controls are implemented
Evaluate compliance with security requirements
Evaluate IT controls’ design and implementation in various IT security processes
Test operating effectiveness of IT controls, including user access management, change management and computer operations for complex IT systems
Assess the risks of control deficiencies and identify mitigating controls
Clearly document and effectively communicate risks and risk mitigation actions
Understand and leverage ISO and NIST information security frameworks to establish accountability and responsibility for controls within the information systems organization
Ensure quality of work and timeliness across different functional deliverables
take ownership of issues and coordinate through to completion
Providing input and ideas based on industry best practices and actual experience to help evolve the security risk and controls areas
Keeping up-to-date with emerging technological trends, security assessment and risk management methodologies and standards
Requirements:
Bachelor’s degree and 3 years of directly related experience
Associate degree and 5 years of directly related experience
High school diploma / GED & 10 years of directly related experience
Bachelor’s degree in computer information systems or computer science
2+ years of IT audit, Information Technology / Security control assurance or enterprise IT compliance experience
Working knowledge of Information Security principles: confidentiality, integrity, and availability
Knowledge of international standards for Information Technology and Information Security (i.e. ISO 2700x, NIST CSF, COBIT, ITIL, etc.)
Exceptional ability to apply critical thinking to complex risk scenarios
Proven ability to understand new technologies and paradigms such as cloud, emerging Big Data technologies, lean methodologies to propose appropriate controls and compliance mentorship
Strong written and verbal communication, including the ability to explain technical matters to a non-technical audience
Ability to demonstrate solid sense of ownership, detail orientation, keen focus on quality and setting clear expectations