Responsibilities: • Conducting thorough reviews of legal contracts and agreements relevant to cloud services, including service level agreements (SLAs), data processing agreements (DPAs), and vendor contracts. This involves interpreting complex legal language and terms to ensure compliance with information security and privacy requirements, identifying potential risks or areas of non-compliance, and articulating these findings in a clear, comprehensible manner to business units and legal counsel. • Liaise closely with County attorneys and business stakeholders to provide actionable insights, ensuring that contractual obligations align with the County’s governance, risk, and compliance frameworks and standards. • Designing, implementing, and continuously improving the County’s cloud information security/privacy compliance program based on applicable policies, local/state/federal laws/regulations and adopted risk management frameworks. • Designing, implementing, leading cloud-based risk assessments and control gap analysis procedures, activities, documents, and communication plans • Leveraging NIST 800-53/FedRAMP assessment experience, technical, and program management skills to lead, plan, track, collaborate and report on the cloud governance, risk compliance program deliverables, including scheduling/leading meetings, assigning/tracking action items, and developing status reports. • Performing cross functional interviews with business, technical and information security partners to determine if information security/privacy controls are implemented correctly, operating as intended, and producing the desired results. • Communicating program controls, measurements, metrics, and assessment results confidentially, professionally, and effectively, in both written and verbal formats, with business, technical, and third-party stakeholders.
ANY GRADUATE