Expert - Cyber Risk and Control Frameworks
Hewlett Packard EnterpriseAbout the role
This role has been designed as ‘Hybrid’ with an expectation that you will work on average 2 days per week from an HPE office.
Who We Are:
Hewlett Packard Enterprise is the global edge-to-cloud company advancing the way people live and work. We help companies connect, protect, analyze, and act on their data and applications wherever they live, from edge to cloud, so they can turn insights into outcomes at the speed required to thrive in today’s complex world. Our culture thrives on finding new and better ways to accelerate what’s next. We know varied backgrounds are valued and succeed here. We have the flexibility to manage our work and personal needs. We make bold moves, together, and are a force for good. If you are looking to stretch and grow your career our culture will embrace you. Open up opportunities with HPE.
Job Description:
We are seeking a Cybersecurity Risk and Controls Framework Expert to analyse the regulatory compliance, business and operational risk requirements related to cybersecurity and develop a framework against which control requirements can be defined and applied. This will include analyzing the inventory of cyber policies and standards and validating them against the risk and controls framework as well as against the threat landscape. This role will also be responsible for driving enterprise risk reporting and creating the right awareness and visibility for executive decision making.
What You’ll Do
- Support Governance, Risk and Compliance (GRC) leadership in delivering various risk overview summaries, including monitoring regulatory changes that impact cybersecurity
- Contribute to the development of the Cyber risk governance framework by leveraging existing frameworks and approaches
- Facilitating a gap analysis of the current processes against the Risk management framework
- Provide subject matter expertise on the control framework, policies, standards and guidelines to ensure their effective development.
- Analyse the current suite of controls against the control framework to ensure our policies and standards delivers a balanced risk / reward profile in alignment with business strategies and priorities
- Ensure that changes to risk governance frameworks and control guidance are effectively communicated to allow for adequate implementation and compliance.
- Work with regional representatives to coordinate the scanning for regulatory changes related to cybersecurity.
- Provide expert opinion on HPE’s risk and effectiveness of our policies and standards using analytics, review of cyber issues, control effectiveness reviews, Key Risk Indicators and assessments as required.
- Support the handling of questions pertaining to cyber policies and standards from regulators, partners and customers.
- Deliver presentations and updates to key business and technology stakeholders.
- Provide timely insight to business and technology partners on risk and controls, to ensure effective response and no surprises.
Key Competencies
- Expert in a broad range of Information Security domains (e.g., Application Security, Cloud Security, Network Security, Data Security, Infrastructure Security).
- Strong understanding of cybersecurity control frameworks (e.g., NIST CSF, ISO 27001).
- Proven experience in risk assessments and analysis.
- Proven experience in defining and implementing cybersecurity policies, standards and guidelines across multiple platforms.
- Strong organizational skills and attention to detail.
- Ability to work effectively with technical and non-technical stakeholders.
- Excellent documentation, communication, and problem-solving skills.
Qualifications and Education
- Bachelor’s degree in Information Security, Information Technology, Risk Management or a related field, or equivalent experience.
- CISSP, CRISC, or similar
Desired experience
- 5-7 years of experience in Information Security, IT Governance, and / or Risk Management
- 5+ years of experience working with various industry standards and frameworks on risks and controls (e.g. ISO 27001, NIST CSF, COBIT).
Additional Skills:
Accountability, Accountability, Action Planning, Active Learning, Active Listening, Agile Methodology, Bias, Business, Coaching, Creativity, Critical Thinking, Cybersecurity, Data Analysis Management, Data Collection Management (Inactive), Data Controls, Design Thinking, Development Methodologies, Empathy, Follow-Through, Growth Mindset, Implementation Methodologies, Infrastructure Design, Intellectual Curiosity (Inactive), Long Term Planning, Managing AApply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s