61 Provide consultation on information security objectives and compliance with relevant security standards, policies, and procedures. 61 Serve as trusted advisor to effectively communicate complex security risks in a manner that is easily understood and actionable. Enable the business to leverage enterprise-wide security solutions. 61 Advise on processes and methodologies required when evaluating purchased product, new internal solutions, or outsourcing IT systems by various of security tools and processes, such as Software Asset management (SAM) process, Secure configuration baseline (SCB) and Third-Party Risk Assessment (TPRA), etc. 61 Test and evaluate information security controls and techniques to ensure they are efficiently and effectively implemented. Conduct Information Security Compliance Assessments according to the process and issue quality reports on time. 61 Help with the risk owners through the remediation process by following the cybersecurity risk treatment plan (RTP) process. 61 Support Computer Security Incident Response Team (CSIRT) when necessary. 61 Communicate in a timely fashion to update the CSIRT team. Coordinate incident response needs within area of responsibility in the event of an enterprise CSIRT incident or investigation. 61 Support the Caterpillar’s Information Security Awareness program. Ensure Information Security Awareness material is included in orientation for new staff, or third-party professionals, where applicable by law. 61 Identify the need for customized awareness or phishing result messages specific to business areas. 61 Develop and present messages in alignment with Information Security directives. 61 Travel may be required based on business need.
Required Qualifications: 61 Bachelor or Master degree in Computer Science, Cybersecurity 61 Good understanding of the information security knowledge in at least 1-2 security domains, such as: 61 Law & Regulation 61 Information security management 61 Communication security 61 Cryptography and Encryption 61 Access Control management 61 Software Development Life Cycle Management 61 Business Continuity and Disaster Recovery 61 Obtain one of the following certifications within eighteen months and maintain in good standing: Certified Information Systems Security Professional (CISSP), Certified Information Security Auditor (CISA), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Controls (CRISC). CISSP preferred.