Logo
The Pasha Group

Cybersecurity Compliance Manager

The Pasha Group, San Rafael, California, United States, 94911


Position at The Pasha Group

Job Summary The Cybersecurity Compliance Manager develops, implements, and monitors enterprise cybersecurity compliance programs, policies, reporting, and practices to support operational resiliency and compliance with various cybersecurity standards such as ISO, NIST, CMMC, and DFARS as well as industry regulations such as USCG and IMO.

Primary Objectives Identify, evaluate, and define technical and physical security requirements of applicable regulations and contracts. Ensure compliance for ISO 27001, NIST 800-171, 800-53, CMMC, DFARS 7012, 7019, 7020, 7021, and other relevant frameworks. Partner with Information Technology and business unit teams to implement program and process changes to meet compliance requirements. Perform risk-based compliance testing of existing procedures and controls to identify, detect, and correct noncompliance. Develop and deliver presentations, training, and communications related to compliance requirements. Duties and Responsibilities Develop, implement, manage, and monitor cybersecurity compliance programs in line with industry standards including International Organization for Standardization (ISO), National Institute of Standards and Technology (NIST), Cybersecurity Maturity Model Certification (CMMC), and Defense Federal Acquisition Regulation (DFARS) as well as industry regulations such as United States Coast Guard (USCG) and International Maritime Organization (IMO). Continuously monitor the organization's cybersecurity practices to ensure compliance with relevant frameworks and regulations. Facilitate the implementation of corrective actions and improvements across the organization. Conduct regular cybersecurity risk assessments on vessels, shore-based systems, and supply chain operations. Collaborate with business unit leadership teams, Facility Security Officers, Terminal Operations teams, and Fleet Management to identify vulnerabilities, assess risk levels, analyze mitigation costs and recommend action plans. Create and maintain cybersecurity policies, incident response plans, and disaster recovery procedures. Align cybersecurity initiatives with broader organizational goals and operational needs. Work closely with IT, Legal, HR, ESG, and other departments to address compliance issues. Monitor implementation and adherence of best practices onboard vessels and in operational facilities. Evaluate and monitor third-party vendors and contractors for cybersecurity compliance. Collaborate with port authorities and industry partners to address shared cybersecurity concerns. Respond to cybersecurity assessments and questionnaires as required by government agencies, business partners, and auditors. Ensure timely and accurate communication and reporting to regulatory authorities. Develop processes and procedures relating to controlled and classified governmental documents and information. Perform 3rd party SaaS risk assessments. Prepare and deliver risk assessment and gap analysis reporting and presentations for leadership teams. Compile detailed reports on the status of cybersecurity compliance efforts. Receive, review, and recommend responses to cyber threat intelligence from law enforcement and industry sources. Other duties as assigned. QUALIFICATIONS To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

Education Bachelor's degree in Cybersecurity, Information Technology, or related field or equivalent combination of coursework and experience in a directly related field required. Master's degree in a related field preferred. Licenses and Certifications Certified Information Systems Security Professional or similar certification required. Transportation Worker Identification Credential (TWIC) required. Ability to obtain and maintain U.S. Government Department of Defense security clearance required. Work Experience 5+ years of related Cybersecurity compliance experience required. 5+ years experience with IT control frameworks, such as NIST-CSF, NIST 800-171, ISO27001, and PCI preferred. Experience in the transportation/shipping industry strongly preferred. Experience with US Coast Guard cybersecurity requirements for vessels and facilities preferred. Required Knowledge, Skills and Abilities Demonstrated knowledge of cybersecurity, compliance, and IT audit requirements. Knowledge of maritime industry security regulations and frameworks. Ability to read, interpret, and apply technical manuals, materials, and knowledge bases. Ability to identify problems, evaluate alternatives and recommend effective solutions. Demonstrated ability to drive projects, programs, and initiatives through all stages including research, analysis, planning, costing, development, proposal, implementation, and administration. Ability to multi-task, manage priorities, and meet critical deadlines. Excellent written, verbal, and interpersonal communication skills. Demonstrated ability to maintain confidentiality with tact and discretion. Demonstrated proficiency with Microsoft Office products at the following levels: * Word, Excel, PowerPoint: Intermediate level of skill; * Outlook: Advanced level of skill. Competencies Builds High-Performing Teams

- Selects, organizes, and motivates colleagues to work together in a committed way to achieve a common mission and ensures a pipeline of talent for the future. Delivers Results

- Rigorously drives self and others to achieve high levels of individual and organization performance. Engages & Inspires Others

- Leads with energy, self-confidence and understanding in ways that motivate colleagues to achieve more than they thought possible. Focuses on the Customer & Market

- Continuously evaluates what is important to the customer/client and develops products or solutions that exceed expectations. Makes Sound Business Decisions

- Makes timely and well-informed decisions that advance critical priorities, capitalize on new opportunities, and resolve problems. Partners Across Boundaries

- Works collaboratively and effectively with colleagues throughout the company toward the common good of The Pasha Group. Practices our Values

- Supports and models The Pasha Way; conduct reflects Excellence, Honesty, Integrity, Innovation and Teamwork. PHYSICAL DEMANDS, WORK ENVIRONMENT, AND TRAVEL Physical Demands The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. Hear and speak with sufficient clarity to understand and engage in telephonic information exchange; hear and understand verbal instructions; give and receive information verbally in person or via communication device - Often. Walk/travel within office environment, crouch/bend to access floor-level storage - Often. Use hands/fingers to operate office equipment, type/complete data input, write - Often. Reach with hands, arms; lift, move and manipulate objects weighing up to 20 pounds - Regularly. Sight sufficient to read instructions, documents, and screen-based information - Often. Use hands/fingers to manipulate and file documents, folders, small objects - Regularly. Working Environment This role requires work that may involve the following environmental conditions: Corporate office environment. Travel Occasional. Must be able to travel independently to U.S. locations including Hawaii.

Screening Requirements Background Checks.

Must be fully vaccinated against COVID-19, except as prohibited by law. The information included in this description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive or exhaustive inventory of all duties, responsibilities, and qualifications required of employees assigned to this job.

#J-18808-Ljbffr