Risk, policy and third party. Run the information security risk register as a decision-making tool, own the policy lifecycle and exception register, and assess the vendors and partners we integrate with.
Incident response and regulatory notification. Own breach assessment and the notification decision across the jurisdictions we operate in, alongside Legal. In healthcare this is the highest consequence judgement in the role.
Finding what is broken before someone else does. Go looking. Read the infrastructure code, pull the access review output, check that the alert a policy promises is actually configured. When you find a gap, bring it quantified, costed and sequenced.
...
Develop, maintain and implement compliance policies, guidelines and training to keep the group compliant with applicable laws, regulations and industry guidelines.
Drive the communication and consistent implementation of applicable policies and procedures across the business.
Keep abreast of industry developments, emerging trends and new product/service launches, and assess their regulatory and compliance implications.
...
Develop, maintain and implement compliance policies, guidelines and training to keep the group compliant with applicable laws, regulations and industry guidelines.
Drive the communication and consistent implementation of applicable policies and procedures across the business.
Keep abreast of industry developments, emerging trends and new product/service launches, and assess their regulatory and compliance implications.
...