Verified today
Associate IS Security Engineer
About the role
Amgen seeks an Associate IS Security Engineer to identify, assess, and mitigate IT risks. The role involves conducting risk assessments, maintaining risk register, recommending controls, collaborating with IT and business teams, ensuring compliance with GDPR, SOX, PCI-DSS, NIST, supporting audits, and managing vendor risk. Requires Bachelor's in IT/Cybersecurity/Risk Management, 2-4 years experience, knowledge of ISO 27001, NIST, COBIT, GRC tools, and strong analytical, communication, and collaboration skills.
What you’ll do
- Conduct risk assessments to identify vulnerabilities in IT systems, processes, and policies.
- Evaluate risks from third-party vendors and partners.
- Maintain IT risk register documenting risks, issues, remediation actions.
- Recommend and implement risk mitigation strategies across IT infrastructure.
- Collaborate with IT, cybersecurity, and business teams to resolve risks and vulnerabilities.
- Monitor and report on effectiveness of existing IT risk controls and recommend enhancements.
- Ensure compliance with industry standards and regulatory requirements (GDPR, SOX, PCI-DSS, NIST).
- Assist in audit preparation, providing documentation and evidence of IT risk management practices.
- Support development and implementation of IT governance, risk, and compliance frameworks.
- Conduct vendor risk assessments and review vendor performance and risk exposure.
What you’ll bring
Bachelor's in IT, Cybersecurity, Risk Management, or related; CRISC, CISA, CISSP desirable
Nice to have
2-4 years IT risk management/auditing/infosec; ISO 27001, NIST, COBIT tools
Skills
Education
Bachelor's