Specialist, Cybersecurity - Risk Management

Location:

USA-Houston 

 

Chemistry that Matters™ 

A career at SABIC provides you with an opportunity to leave a lasting positive impact to the world and yourself. From excellent health and well-being benefits to our comprehensive learning programs. We offer a wide range of benefits and offerings that recognize that our people have unique motivations and ambitions. It’s all about matching what matters to you with what matters to us. Let’s explore what matters!

As one of the world’s largest diversified chemical companies, we activate the power of human capital to address society’s future challenges. Through partnerships, we enable life-saving medical innovations and help fight world hunger. We are driving the circular economy for the benefit of communities and our planet through sustainability initiatives, such as our TRUCIRCLE™ portfolio.  Today, the company serves customers in more than 140 countries with a global workforce of close to 29,000 talented individuals.  Our values – Inspire, Engage, Create, and Deliver – are the foundation of our success. To learn more about these and how we strive to Be the Impact, click  here: www.sabic.com/en/careers/benefits-that-matter/career-matters/SABIC-Leadership-Way


Our purpose is "Chemistry that Matters". This is what drives us to do what we do. "Chemistry" goes beyond applying science and technology to enhance the supply of essential materials to the world. It is how we work, to build long-lasting relationships of trust. “What Matters” is making a meaningful impact for the world – through the customers and communities we collaborate with, so that we succeed and grow together.


It is all about matching what matters to you with what matters to us. We are mindful about the importance of the team we are building and how our team members impact to our culture.   We believe that good ideas come from anywhere, being inclusive to diverse perspectives is stimulating, encourages innovation and is critical to our mission. Let us explore this together!

For an overview of our benefits here at SABIC, please visit: www.yoursabicbenefits.com

 

Job Summary

The Cybersecurity Risk Management Specialist is responsible for governing changes that could introduce cybersecurity risk into the environment, via IT and OT changes.  They operationally govern the environment, following the enterprise's cybersecurity policies and standards, via defining and enforcing operational processes for cybersecurity risk assessment and remediation covering the organization's IT and OT environment.   They establish operational risk management processes and operational playbooks, aligned to corporate cybersecurity policy and agreed upon risk management frameworks and enterprise risk management guidelines, to ensure secure IT and OT changes, while providing enterprise-wide cybersecurity risk visibility.

 

They serve as the focal point and technical consultant to the business units and IT and OT project team and management to assess and identify cybersecurity risks related to environment changes.  They establish risk remediation approaches based upon corporate policies and standards, steering and facilitating implementation of any needed cybersecurity controls with the appropriate control owners. 

 

They are responsible for planning, managing, and coordinating various cybersecurity risk management activities, focused on identifying, assessing, and mitigating unacceptable risks while enabling the underlying business goals and objectives.  They also oversee and manage all 3rd-party risk management and act as a gatekeeper for enabling integrations with 3rd-party partners, suppliers, and vendors, overseeing TPRM assessments and specifying controls needed to protect the organization's data and connectivity with 3rd-parties.

 

Job Responsibilities

  • Maintain enterprise risk management operational frameworks and risk scoring criteria in accordance with company cybersecurity policies, standards, and frameworks and enterprise risk management guidelines.
  • Perform cybersecurity risk assessments for all qualifying IT and OT environment changes.
  • Coordinate with the cybersecurity architecture senior specialist to validate risk assessment findings, and to request guidance when pre-approved risk mitigation strategies are not available for identified risks.
  • Establish and track risk remediation plans for all identified risks.
  • Coordinate with the cybersecurity assurance specialist to ensure ongoing verification of mitigated risks are effective over time.
  • Implement, manage, and maintain risk-related workflows, including coordination with the appropriate risk owners and authority functions to obtain approval for risk exceptions and policy deviations.
  • Act as a gatekeeper between Implementation Phase and production go-live (Manage & Measure phase) to ensure all identified risks have been addressed via closure of risk remediation plans.
  • Ensure all 3rd-party / external partner, vendor, and supplier interactions have undergone an appropriate risk assessment to verify the safety, security, and risk mitigation of all 3rd-party integrations and interactions.
  • Maintain a register of approved 3rd-parties, including the controls required to ensure safe and secure interactions, and the approved use case(s) of each 3rd-party
  • Establish and maintain a 3rd-party re-verification program to verify that usage, risks, and risk mitigations are updated as needed, if any 3rd-party relationships change over time
  • Coordinate with the cybersecurity Assurance team to ensure on-going operational validation of 3rd-party integrations and interactions
  • Review all third-party contracts for IT / OT services and solutions to ensure all required risk-mitigating controls and clauses are included and enforced contractually.
  • Oversight and management of the enterprise cybersecurity risk register to facilitate the monitoring and reporting of risks.
  • - Management of the operational risk assessment methodology covering the organization's IT , OT, and 3rd-party integration components related to secure, compliant and resilient operations.
  • Oversight of the managed services providers performing risk assessments to ensure they are following the methodology in compliance with company policies, standards, processes, and expectations.
  • Provide evidence to Assurance function, Legal, approved stakeholders, and contribute to internal and external audits and assessments as needed in regard to cybersecurity risks.
  • - Ensure feedback from cybersecurity Assurance role and similar stakeholders are used to improve risk assessment methodologies and processes
  • Identifies gaps and needs in regard to risk assessment, working with the cybersecurity architect role to ensure needs are incorporated into the cybersecurity strategy and roadmap.
  • Manages control implementations and improvement projects in the area of risk management, following the organization's project management and project execution processes.
  • Drives operational risk assessment maturity and process improvements and automation for processes and controls in-scope of role.

Job Requirements

  • BS or MA in computer science, information security, cybersecurity or a related field
  • Cybersecurity certification in risk assessment (or appropriate on-the job experience)
  • 5+ years of experience in a cybersecurity, enterprise (ERM), or IT risk management role
  • 5+ years of experience with regulatory compliance, risk management frameworks and information security management frameworks (e.g. ISO, NIST, etc)
  • Strong understanding of Zero Trust principals
  • Cybersecurity principles and practices, including IT and OT cybersecurity risk assessment, cybersecurity risk mitigation, and third-party risk assessment.
  • Cybersecurity frameworks and standards, such as the NIST CSF, Secure Controls Framework, ISO/IEC 27001, and OT cybersecurity standards (62443, ...).
  • Strong background in conducting Business Impact Analysis (BIA) to evaluate the potential impact of cybersecurity risk on critical business processes and functions.
  • Third Party and Vendor Risk
  • Regulatory and Compliance alignment
  • Strong communication skills
  • Planning and organizing
  • Personal Leadership
  • Analytical and Risk Based decision making.

Eligibility Requirements (Regional Specific)

  • You must submit your application for employment online to be considered. Please submit your resume using the “Apply Now/Apply” option on this page.
  • You must be 18 years or older
  • Applicants must be currently authorized to work for SABIC in the United States on a full-time basis.

 

Work Availability

Regular, predictable attendance is an essential function of this position. Applicants must be regularly available and willing to work (e.g. Monday – Friday)] during assigned hours of operation and such other hours as the company determines are necessary or desirable to meet business needs

 

We are proud to be a diverse and an equal opportunity employer .We are fully committed to a culture of respect and inclusion.


Nearest Major Market: Houston