Join Delta IT on our journey to becoming the best IT organization in the airline industry.
Delta IT is on a journey of transformation. We are changing the way we do business from top to bottom. As thought leaders within Delta, we strive to create meaningful and innovative solutions and are looking for team members to help us realize our vision.
Delta IT employees are thinkers, doers, innovators.
We are proactive.
We are collaborative.
We deliver impact to our customers.
Join us on our transformation journey in becoming a world-class IT organization at the worlds best airline!
YOUR RESPONSIBILITIES IN THIS ROLE:
As a manager, Second Line GRC, you will be responsible for overseeing the Second Line GRC team within the Information Technology area that is focused on monitoring, tracking and reporting risk within the Delta organization. This role will partner with other teams throughout the Delta organization to identify, assess, track, report and validate risks and the implementation of controls throughout the organization. The Manager will balance their time between technical thought-leadership, hands-on solution collaboration, and talent development. This role provides technical guidance and mentoring to the team to achieve high-quality results. The ideal candidate will have excellent organizational, communication, and management skills, along with an ability to lead training sessions and workshops for staff members.
- Develop, maintain, and support an IT Risk management program to include risk identification, measurement/prioritization, mitigation, and reporting (in partnership with the Governance Manager).
- Oversee development and implementation of high-level control architectures, including preventive, detective, and corrective controls.
- Apply assessment data of identified threats in risk decision making.
- Knowledge of industry indicators useful for identifying technology trends. Assess and communicate the potential risk of these trends to Delta. Recommend controls to mitigate the risk.
- Through a close partnership with the Threat Intelligence team, maintain knowledge of current and emerging threats, translate threats to potential risk, and identify possible risk mitigation strategies.
- Acquire and maintain a working knowledge of relevant laws, regulations, policies, standards, and compliance obligations.
- Advise senior leadership of changes affecting Delta’s risk posture.
- Assure successful implementation of Information Security requirements and controls.
- Lead Information Security assessment process, blending industry best practices with Delta’s culture and risk posture.
- Collaborate and partner with other risk organizations at Delta. Align IT Risk’s approach with Delta’s risk tolerance/risk management approach where possible.
- Leverage industry best practices for evaluating, implementing, and disseminating Information Security internal assessments, monitoring, detecting, and remediation.
- Represent the GRC team on internal committees related to key risk areas (like vulnerability management).
- Create auditable evidence of security measures.
- Develop risk mitigation strategies to resolve vulnerabilities and recommend security changes as needed.
- Develop specific countermeasures and risk mitigation strategies.
- Provide guidelines for performance of, and conduct, a risk analysis whenever an application undergoes a major change.
- Tackle “big” problems, provide options, and drive resolution.
- Provide consulting/thought leadership for Information Security, IT, and the business.
- Work as a member of the broader GRC, IT and Delta teams. Do what’s right for Delta.
- Ensure up to date process and procedure documentation for the team.
- Identify process improvement/automation opportunities and innovate new ways of doing things.
- Communicate, and deliver, the value of Information Security throughout all of Delta.
- Lead with integrity and a positive attitude.
- Provide leadership and oversight to a high performing team of Delta Information Security professionals to ensure the confidentiality, integrity, and availability of information.
- Meet with staff on a timely basis to conduct performance evaluations and provide feedback. Provide ongoing coaching, mentoring, and training to develop and encourage employee performance and development.
- Develop strategic and operational plans for the work group, manage execution, drive improvements, and measure results.
- Define metrics to accurately convey risk, team performance and measure against goals.
- Drive awareness and knowledge of security.
- Perform special projects as assigned, while effectively manage time with competing priorities.
- Build highly motivated and result-oriented team.