The Security Engineer – Governance, Risk, and Compliance, is a creative, well-rounded communicator who excels at the strategy and the tactics necessary to ensure that the Information Security Governance team is effectively changing organizational behavior, fostering a secure culture, and reducing security risk through well documented and communicated policies, standards, and information security metrics.
This is a people-focused position with an opportunity to assist in creating new processes and solutions and drive results within a team responsible for transforming the way Information Security supports our business and helps protect the information our customers, employees and business partners entrust to our care.
We believe that Delta’s people play a critical role in our cyber threat defense and maintaining a vigilant and security-aware workforce is the best strategy for detecting and thwarting cyber-attacks, running a successful operation, serving our customers, and maintaining a world class workforce. In this role, you’ll partner closely with others in the Information Security Division to drive aligned results and solve the big problems.
Your responsibilities in the role:
- Provide Policy and Standards subject matter leadership through the development and maintenance of Delta’s Information Security policies, standards, and procedures. Updating them annually, ensuring alignment with applicable frameworks and regulations and ensuring that they are clear and able to be understood at all levels of the organization – from technical teams to our frontline personnel.
- Improve Delta’s security positioning through process improvement, policy, automation, and the continuous evolution of capabilities.
- Manage human risk and develop a strong security-driven culture where security is part of every employee’s day-to-day operation and attitudes.
- Analyze and identify the top human risks to the organization and the behaviors that must change to mitigate those risks. Develop, review, implement, and maintain a security awareness training programs to mitigate human risks. Ensure security awareness programs meet all industry regulations, standards, and compliance requirements and that all Delta people understand, acknowledge, and fulfill all applicable enterprise information security policies.
- Develop Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs) for a metrics dashboard to track and report operational capabilities, success factors, risks, threats, and compliance metrics to measure the effectiveness of Delta’s Information Security program.
- Ensure up to date process and procedure documentation for the team.
- Identify process improvement/automation opportunities and innovate new ways of doing things.
- Communicate, and deliver, the value of Information Security throughout all of Delta.
- Work as a member of the broader GRC, IT and Delta teams.