What are the responsibilities and job description for the GRC Consultant position at Clevanoo LLC?
Responsibilities:
Clearly identify the systems, networks, applications, and sensitive data types for assessment in collaboration within Bank
Evaluate the Bank's existing asset inventory, data classification schemes to ensure accuracy and completeness for risk assessment purposes
Identify relevant cyber threats and assess technical, procedural, and people control gaps relevant to the scoped environment
Analyze the likelihood and potential business impact based on identified control gaps
Assess design and operating effectiveness of controls aligned to NIST CSF 2.0 and applicable GLBA requirements
Compile a comprehensive, prioritized risk register
Recommend actionable measures to address control gaps and reduce risk exposure.
Deliverables:
Risk assessment report and risk register
Recommendations for risk mitigation
Control gap assessment report
Executive presentation
Primary Objective:
The primary objective of this Risk assessment is to deliver the following:
Conduct an independent assessment of Bank's cybersecurity program against the NIST Cybersecurity Framework (CSF) 2.0 and applicable GLBA security requirements.
Evaluate the effectiveness and maturity of the Bank's people, process, and technology controls across the NIST CSF 2.0 functions.
Perform a risk assessment of the identified gaps using NIST Risk Management Framework (RMF) principles and NIST SP 800-30 methodology to determine risk exposure and prioritization.
Provide assessment results, identified gaps, and a risk register detailing the associated risk ratings and observations.