
GS Reg Compliance Consultant
- Columbus, GA Columbia, SC
- $139,000-159,000 per year
- Permanent
- Full-time
- If you live within 50 miles of the Aflac offices located in Columbus, GA or Columbia, SC, this role will be hybrid. This means you will be expected to work in the office for at least 60% of the work week. You will work from your home (within the continental US) for the remaining portion of the work week. Details of this schedule will be discussed with your leadership.
- If you live more than 50 miles from the Aflac offices located in Columbus, GA or Columbia, SC, this role will be remote. This means you will be expected to work from your home, within the continental US. If the role is remote, there may be occasions that you are requested to come to the office based on business need. Any requests to come to the office would be communicated with you in advance.
- Acting with Integrity
- Communicating Effectively
- Pursuing Self-Development
- Serving Customers
- Supporting Change
- Supporting Organizational Goals
- Working with Diverse Populations
- Excellent verbal and written communication skills with the ability to understand and communicate complex information security, risk management, and legal/regulatory compliance concepts.
- Experience applying and assessing industry-recognized security standards and regulatory frameworks for areas such as Information Security, Physical Security, Business Continuity, Disaster Recovery, Crisis Management, and IT (e.g., Asset Management, Configuration Management, Vulnerability Patching).
- Technology Risk Management concepts and control
- Managing to legal/regulatory requirements for protecting information assets
- Global technology organizational concepts
- Principles and methods of all information security disciplines
- Knowledge of and in-depth experience in the ability to apply state, federal, and international information security and information protection laws and regulations such as, but not limited to: NYDFS, GLBA, HIPAA, SEC, GDPR, CCPA, FSA, and financial integrity under Sarbanes-Oxley, etc.
- Knowledge of and in-depth experience in the ability to apply industry-recognized security standards such as NIST, PCI, etc.
- Knowledge of cloud computing technologies and security best practices.
- Encompasses professional maturity to work independently and work collaboratively in teams.
- Strong multi-tasking and time management capability.
- Detail oriented, structured and organized.
- Bachelor’s Degree in Computer Science, Information Security, Cybersecurity, business administration or a related field
- Six or more years of information security compliance, risk management or equivalent experience
- Certification in CISSP, CISA, CISM, CIPP
- May be required for a final interview
- Evaluate the impact of security and information protection legal and regulatory requirements affecting Aflac and maintain documented assessments/remediation tracking
- Assist with operationalizing security and information protection legal and regulatory requirements affecting Aflac by providing guidance on the creation and revision of security practices that include cybersecurity best practices and compliance with all applicable regulations and other frameworks, such as: NYDFS, GLBA, HIPAA, PCI, SEC, CCPA, GDPR, FSA, SOX, NIST, etc.
- Remain current with security and information protection legislation, standards, best practices, and industry trends affecting Aflac business practices and customer expectations
- Proactively collaborate with the business, technology, and functional teams to communicate new or changing regulations that affect cybersecurity requirements
- Support Global Security leadership with changes to security and information protection legal and regulatory requirements by documenting feedback during comment periods
- Assist with the maintenance of processes, KRIs and metric reporting, tools, and systems leveraged to identify, assess, measure, and monitor technology regulatory compliance and cybersecurity risk across Aflac
- Maintain control requirements and associated meta data for cybersecurity controls as well as the control mapping to laws, regulations, risks, and industry standards
- Provide guidance to key stakeholders as needed regarding documentation, evidence, and other supporting material that should be maintained to demonstrate that processes are designed and operating effectively
- Produce presentations, reporting, and other content that will be used to communicate with leadership and other key stakeholders (e.g., employees, producers) about legal/regulatory updates, annual attestation results, and other changes affecting the organization's Information Security posture
- Performs other duties as required