Serving as the Information Security Trusted Advisor and Business liaison, with direct responsibility supporting Consumer Digital Transformation, Consumer Business Banking, Santander Bank North America Operations, and Santander Securities Investment Banking. Providing First Line of Defense and Second Line of Defense business-stakeholder consulting services.
- Serving as an advisor, liaising between the business and technology to ensure collaboration, prioritization, and oversight.
- Leading cross-functional teams to create, implement, and evolve risk-based security strategies, while adhering to policies, procedures, and compliance requirements.
- Identifying and communicating risk concerns to business, audit and technology audiences, to ensure minimal exposure to regulatory and operational risks.
- Working closely with security leadership to instill cybersecurity policies and practices throughout business units to address security operations, and incident response.
- Actively informed and engaged in security projects across the business.
- Enforcing the strong security culture set forth by the CISO (Chief Information Security Officer), ensuring uniformity across security leadership, business units and employees.
- Foster strong relationships with internal Business units and excel in cybersecurity communication.
- Producing materials and leading a Business Information Security Forum on a monthly basis to communicate key initiatives, highlights and emerging risks.
- Advising business units on enterprise-wide people, process and technology security recommendations.
- Maintaining up-to-date knowledge related to security threats, vulnerabilities and mitigations.
- Ensuring business projects are focused on cybersecurity from the beginning. Review all new NPBA (New Product Business Activities) and provide advice and guidance from an Information Security perspective.
- Identifying and documenting threats and vulnerabilities that may impact the business and address them regularly with business units.
- Motivating business units to adopt cybersecurity controls.
- Staying abreast of new laws, regulations and standards, and assess their impact to the business.
- Verifying security content training initiatives and internal/external communication are conducted regularly.
- Support the CISO, management team and executive leadership.
- Promoting awareness, training, and education on information security.
- Responding to daily business area requests related to information security and consultation.
- Supporting Incident Response in regards to security breaches and resulting investigations. Participating in events as a representative of Information Security to provide domain expertise.
- Track and report on business owned information security Action Drivers.