BASF Veterans Jobs

Job Information

Meta Cloud Security GRC Specialist in London, United Kingdom

Summary:

Meta's Security Governance, Risk and Compliance function (Security GRC) serves as the primary hub for Security risk management and compliance across the company, providing support to Meta and its family of apps. Within Security GRC, the Cloud Security GRC function is a horizontal capability providing guidance and direction to first line teams in making Meta’s Cloud platforms secure, available and compliant.At Meta, we understand the significance of security, data protection, and privacy for the billions of people who use our services. We are committed to ensuring compliance with applicable laws and regulations such as the General Data Protection Regulation (GDPR), the European Electronic Communications Code (EECC), the Network and Information Security Directive (NIS2), and others, while enabling the business to rapidly and securely use appropriate Cloud solutions.We are currently seeking highly experienced information security professionals to join our Cloud Security Function to continue to develop our Cloud Security GRC capabilities. This role is critical in driving change and ensuring compliance with these and other obligations. As part of this role, you will collaborate closely with engineers, analysts, technical program managers, business stakeholders, legal teams, and risk & compliance teams across the Meta organization.This role requires a comprehensive understanding of various aspects of information security and the capability to apply this knowledge to solve problems at scale. This role demands a blend of business and technical acumen, demonstrated capability to communicate clearly with a broad range of stakeholders, and a demonstrated desire to learn.Our goal is to make Meta the premier place to work for governance, risk, compliance, security, and integrity professionals.

Required Skills:

Cloud Security GRC Specialist Responsibilities:

  1. Lead significant programs of work across various levels of cross-functional teams in Cloud Security and Cloud Governance, Risk and Compliance areas

  2. Collaborate with team members and stakeholders to understand or identify defined work problems and program goals, obtain prioritized deliverables, and discuss program impact.

  3. Designing, implementing, and/or assessing security controls and frameworks

  4. Implement maturity frameworks across multiple programs factoring in emerging regulations and proactive detection of risks.

  5. Assess and document emerging regulatory impact on established policy and control frameworks

  6. Identify, communicate, and collaborate with relevant stakeholders within one or more teams to drive impact and work toward mutual goals.

  7. Establish learnings, best practices, standardized frameworks and tools across GRC and related teams.

  8. Develop detailed program/project plans in partnership with cross-functional teams

  9. Identify opportunities for information sharing, process improvement and automation.

  10. Support business travel on an as needed basis (up to 10%).

Minimum Qualifications:

Minimum Qualifications:

  1. 17+ years of relevant experience, including:

  2. At least 8+ years experience in information security and/or technology risk including one or more domains (e.g., access management, vulnerability management, change management, business continuity, application security, asset management).

  3. Experience of and demonstrable familiarity with key Cloud Security, Risk Management and Compliance concepts

  4. Several years (5+) of hands on security experience with at least one of the major Cloud Service Providers (AWS, GCP, Azure)

  5. Experience in a Governance, Risk and Compliance function overseeing Cloud implementations at scale

  6. Experience in designing and implementing control frameworks

  7. Experience in assessing security deficiencies in information systems and recommending mitigating controls in a corporate environment

  8. Familiarity with compliance frameworks and regulatory requirements such as NIST, ISO-27001, ISO27018, SOC2, GDPR, EECC, eDP, NIS2, and other relevant structures.

Preferred Qualifications:

Preferred Qualifications:

  1. Security industry qualification (CISSP, CISM, CISA or similar)

  2. Cloud-specific Cloud Certifications (CCSP, AWS Certified Security Specialist, CCSK, etc.)

  3. BSc/MSc or equivalent in Computer Science, Information Systems, Engineering, Cybersecurity or related field

Industry: Internet

DirectEmployers