Enova
Hybrid

SR. IT Risk Management Advisor

Sorry, this job was removed at 2:01 a.m. (CST) on Sunday, May 8, 2016
Find out who's hiring in Chicago.
See all Developer + Engineer jobs in Chicago
Easy Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

SR. IT Risk Management Advisor

Tracking Code
1563-626
Job Description

Sr. IT Risk Management Advisor

Reports to Head of IT Risk

  

Our IT Risk Management team:

We work in conjunction with legal, compliance, back office operations, analytics, operations, technology and software development. We are expected to be the experts in security and risk management, while being able to articulate the risks to the business in order to make sound decisions for Enova. What makes us great is that we work as a team, are passionate about our jobs and provide immense value to the company.

 

This is where YOU come in:

As a Sr. IT Risk Management Advisor, your job will be to manage our PCI and BCP programs and to facilitate the risk management of internal projects, architectures, external partners and vendors. You will assist in managing our control framework and educating our associates on appropriate security measures. You’ll be collaborating with just about every organizational function and will utilize your incredible people skills to gain trust and respect by delivering straightforward results and solutions. Through your leadership ability you will improve controls, policies and processes. You will have strong decision-making capabilities with the ability to weigh relative costs and benefits of potential actions and identify the most appropriate one for Enova.

 

You’re right for this job if you:

  • Have 5-10+ years of experience in assessing enterprise risk and delivering security solutions
  • Have a technical expertise in networking and security knowledge (TCP/IP, Routers, VLANS, Firewalls, WAF, IDS, DLP, SDLC) – can understand and follow a packet
  • Strong technical understanding of threats, malware, vulnerabilities, exploit techniques, and log analysis
  • Strong technical understanding of application and cloud security controls (OWASP 10 and AWS)
  • Be hands on and have experience managing a PCI-DSS (as a Level 1) program and remediate any issues
  • Have experience supporting a vulnerability scanning tool (think Tenable & Qualys), interpret the results and remediate findings
  • Have a strong understanding of controls (NIST, ISO, PCI, SOX), how to apply them and how to assess them
  • Can identity and assess risks and gaps, create a mitigation plan to address them and ensure implementation to closure
  • Can lead security investigations; including evidence gathering, interpretation, forensics and report production (you will have to be active hands on keyboard for this)
  • Have Business Continuity Planning experience, can run testing exercises and update BIA’s
  • Experience in writing, assessing and modifying IT Security policies, procedures and processes
  • Identify and resolve any security or compliance problems related to our standard security framework
  • Researches and designs information security solutions for organization systems and products that comply with all applicable security policies and standards
  • Assists in responding to audits, penetration tests and vulnerability assessments
  • Analyzes and makes recommendations to improve network, system, and application architectures
  • Can stay abreast of the security landscape; threats; tools; controls; regulations;
  • Have a Bachelor’s degree in Information Security/Risk, Computer Science or equivalent experience
  • Are able to jump in and handle new tasks as assigned

**May be required to travel domestically or internationally

 

Kudos to you if you:

  • Have been exposed to Reciprocity Labs GRC Tools
  • Can understand and write SQL scripts, RegEx, and shell scripts
  • Have knowledge of Altassian’s Confluence and Jira
  • Have knowledge of Pivotal Tracker, SpringCM, AWS, Tenable, TripWire, McAfee, F5, Cisco, Palo Alto, Splunk and Metasploit
  • Have one or more relevant security certifications; CISSP, CISA, CISM, GIAC-GISP, GIAC-GCFA, CEH, PCI-ISA, etc.
  • Proficiency with at least one scripting language (e.g.: Perl, Python, PowerShell)

 

Job Location
Chicago, Illinois, United States
Position Type
Full-Time/Regular
See More
Easy Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

What are Enova Perks + Benefits

Culture
Volunteer in local community
Partners with nonprofits
Open door policy
Pair programming
Open office floor plan
Flexible work schedule
Enova employees are able to leave at 2pm on Fridays between Memorial Day and Labor Day!
Remote work program
Diversity
Dedicated diversity and inclusion staff
Mandated unconscious bias training
Diversity manifesto
Diversity employee resource groups
- B.L.A.C.K @ Enova - HOLA @ Enova - Pride @ Enova - South Asians @ Enova - Women @ Enova - Parents @ Enova
Hiring practices that promote diversity
Health Insurance + Wellness
Flexible Spending Account (FSA)
Disability insurance
Dental insurance
Vision insurance
Health insurance
Life insurance
Pet insurance
Wellness programs
Team workouts
Enova's team fitness initiatives include Sponsored race teams.
Mental health benefits
Financial & Retirement
401(K)
401(K) matching
Company equity
Performance bonus
Charitable contribution matching
Child Care & Parental Leave
Childcare benefits
Generous parental leave
Family medical leave
Return-to-work program post parental leave
Company sponsored family events
Vacation + Time Off
Generous PTO
Paid volunteer time
Sabbatical
Paid holidays
Office Perks
Commuter benefits
Company-sponsored outings
Free snacks and drinks
Some meals provided
We provide free breakfast on Monday.
Company-sponsored happy hours
Company-wide happy hours are hosted once per month and team's host happy hours at their discretion..
Onsite office parking
We offer employees discounted on-site garage parking.
Relocation assistance
Fitness stipend
Home-office stipend for remote employees
Onsite gym
Professional Development
Job training & conferences
Tuition reimbursement
Lunch and learns
Both company-wide and department-specific events.
Promote from within
Mentorship program
Continuing education stipend
Online course subscriptions available
Customized development tracks
Paid industry certifications

Additional Perks + Benefits

Sabbatical program • Recognition programs • Commuting reimbursement • Monthly social events • Discounted gym memberships • Pet insurance

More Jobs at Enova

Easy Apply
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about EnovaFind similar jobs like this