Job Description: Information Risk Manager
Position: Information Risk Manager
Department: Library and Information Science > Information Management
Reporting to: Director of Library and Information Science
Job Summary:
The Information Risk Manager is responsible for developing and implementing effective information risk management strategies within the Library and Information Science department. This role involves identifying, assessing, and mitigating potential risks that may impact the security, confidentiality, integrity, and availability of information assets. The Information Risk Manager will collaborate with cross-functional teams to ensure compliance with industry standards and best practices, while maintaining a proactive approach towards risk identification and mitigation.
Key Responsibilities:
1. Develop and implement information risk management strategies, policies, procedures, and controls to safeguard the confidentiality, integrity, and availability of information assets.
2. Conduct thorough risk assessments to identify potential vulnerabilities and threats to information systems and assets.
3. Collaborate with stakeholders to establish risk appetite and tolerance levels, and develop risk mitigation plans accordingly.
4. Monitor and evaluate existing risk mitigation measures and propose enhancements as necessary.
5. Stay up-to-date with emerging information security trends and technologies, ensuring the implementation of relevant best practices.
6. Lead incident response and manage the resolution of information security breaches or incidents.
7. Conduct regular audits and assessments to ensure compliance with applicable laws, regulations, and industry standards.
8. Provide guidance and support to staff on matters related to information risk management and security awareness.
9. Develop and deliver training programs to enhance information security awareness and knowledge among library staff.
10. Collaborate with cross-functional teams to integrate information risk management practices into various library projects and initiatives.
Required Skills and Qualifications:
1. Bachelor's degree in Library and Information Science, Information Management, or a related field.
2. Proven experience in information risk management, preferably within a library or academic setting.
3. In-depth knowledge of information security frameworks, standards, and best practices such as ISO 27001, NIST, and COBIT.
4. Strong understanding of information security principles and concepts, including risk assessment, threat modeling, and vulnerability management.
5. Familiarity with information governance and data protection regulations (e.g., GDPR, HIPAA).
6. Experience in conducting risk assessments, developing risk mitigation strategies, and implementing controls to address identified risks.
7. Excellent analytical and problem-solving skills, with the ability to think strategically and assess risks from a holistic perspective.
8. Strong communication and interpersonal skills, with the ability to effectively collaborate with stakeholders at all levels.
9. Proven ability to lead incident response activities and manage information security incidents effectively.
10. Relevant certifications such as Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM) are highly desirable.
Note: This job description outlines the general nature and key responsibilities of the role but is not exhaustive. The Information Risk Manager may be required to perform additional duties as assigned by the Director of Library and Information Science.