Senior Engineer, Regulatory GRC

Overview

On Site
Full Time

Skills

ICE
Physical Security
Vulnerability Management
Policies and Procedures
Auditing
Documentation
Organized
Security Awareness
Risk Assessment
Reporting
Information Security
Management Information Systems
System Administration
Computer Networking
Regulatory Compliance
Trading
Financial Services
Evaluation
Management
CISSP
Technical Writing
Communication
Microsoft Excel
Workflow
Data Collection
Normalization
Visualization
Scripting
Regular Expression
Software Development Methodology
Project Management
Cyber Security
SAP GRC
Microsoft Exchange
Augmented Reality

Job Details

Overview

Job Purpose

The Senior Engineer - Regulatory, GRC is part of a team responsible for the global Information Security program. The role would gain exposure to the full suite of businesses and products which underpin the Parent ICE company.

Information Security ("IS") is charged with:
  • Preventing impactful cybersecurity and physical security incidents,
  • maintaining a reputation with customers, regulators, and key stakeholders as running a best-in-class cybersecurity and physical security program, and
  • avoiding negative impact to business agility and growth from cybersecurity and physical security policies and controls.

Governance, Risk, and Compliance maintain said policies, ensure controls are operating effectively via assessment and attestation, and own the vulnerability management program to identify and correct any problems within.

Responsibilities
  • Security Metrics - Uses automated and manual processes to produce regular reports communicating the status of the Information Security program
  • Policies and Procedures - Maintains corporate Information Security policies and departmental procedures and maps them to relevant control standards
  • Regulator, Audit, and Customer Inquiries - Organizes and updates departmental documentation and responds to inquiries in an organized and repeatable fashion
  • Recertification - Operates periodic processes to ensure hire, transfer, and termination protocols are complied with and regular access reviews are conducted
  • Security Awareness - Builds and maintains company awareness and education programs
  • Risk Assessment - Builds and operates the company platform to document, measure, and report assessments, risks, controls, findings, and remediation activity

Knowledge and Experience
  • University degree in Information Security, Engineering, MIS, CIS, or related discipline
  • 5 or more years of relevant work experience
  • Experience with Systems Administration and/or IP Networking is a plus
  • 5 or more years of experience with Regulatory and/or Framework Compliance
  • Experience in an exchange, trading facility, or financial services a plus
  • Experience in Customer communication and Vendor evaluation
  • Experience with senior management and board metrics generation and communication
  • Advanced certifications (for example, the CISSP)
  • Advanced technical writing and/or communication education and experience

Specific Technologies:

Excel, Workflow automation tools, Data collection, normalization, indexing, correlation, and visualization. Scripting, regular expressions, string-parsing, light SDLC, and project management. NIST Cyber Security Framework, CIS, and GRC Platforms.

Intercontinental Exchange, Inc. is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to legally protected characteristics.

#LI-AR1

#LI-Hybrid
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.