- Posting Location: Cary, North Carolina
Description and Requirements
Role Value Proposition:
The Cyber Regulatory Team is part of the Global Security Organization and reports to the CISO. This position is responsible for monitoring, documenting, and aligning cybersecurity regulations and guidelines with the control framework. It also collaborates with Legal, Privacy, Compliance, Risk, Internal Audit, and other business stakeholders to assess the implications of cybersecurity regulations. The role assists in responses to compliance and regulatory exams, inquiries, and cybersecurity incident reporting
The Global Security GRC Specialist is responsible for identifying and ensuring compliance with cybersecurity regulatory mandates, including documenting compliance, tracking regulatory changes, reporting incidents, and governing the program globally.
This is an exciting opportunity to collaborate with Legal, Privacy, Compliance, Risk, Internal Audit, and other business stakeholders to assess the implications of cybersecurity regulations. The role coordinates responses to compliance and regulatory exams, inquiries, and cybersecurity incident reporting, ensuring MetLife maintains compliance.
Key Responsibilities:
- Monitor and document the cybersecurity regulatory landscape using enterprise repositories such as OpenPages, Power BI, and metrics tools
- Coordinate compliance with reporting requirements, including assessment of internal controls, quarterly and annual compliance attestations, and cybersecurity incidents
- Manage and maintain the Cybersecurity Regulatory Change Management (RCM) process
- Assist with the facilitation of cybersecurity regulatory compliance, as well as external and internal audit activities
- Coordinate regulatory requirements to align with the Process, Risk, and Control (PRC) Framework
- Create and maintain metrics for cybersecurity regulations and guidelines
- Conduct research on emerging topics and concerns to formulate responses to proposed regulations
- Representing Global Security in regulatory and compliance discussions
Essential Business Experience and Technical Skills:
Required:
- 5+ years of experience in Information Security, IT Audit, Compliance, or IT Risk
- Preferably 2+ years of experience conducting SOX, SSAE-18, or SOC2 audits, or implementing compliance programs such as the NYDFS Cybersecurity regulation
- Experience in creating or updating a Process, Risk, and Control Framework within a global IT organization
- Familiarity with industry risk and control standards, including ISO, NIST, and COBIT
- Strong verbal and written communication and presentation skills
- Ability to challenge and provide constructive feedback as needed
- Effective project management skills to manage multiple work streams simultaneously
Preferred:
- Proficiency in utilizing Artificial Intelligence (AI) tools
- CISA and/or CRISC certification preferred
- Suggested 10 years of experience in IT audit, IT security, or similar roles
- Familiarity with GRC platforms and security control frameworks.
- Strong communication, collaboration, and writing skills
At MetLife, we’re leading the global transformation of an industry we’ve long defined. United in purpose, diverse in perspective, we’re dedicated to making a difference in the lives of our customers.
Our U.S. benefits address holistic well-being with programs for physical and mental health, financial wellness, and support for families. We offer a comprehensive health plan that includes medical/prescription drug and vision, dental insurance, and no-cost short- and long-term disability. We also provide company-paid life insurance and legal services, a retirement pension funded entirely by MetLife and 401(k) with employer matching, group discounts on voluntary insurance products including auto and home, pet, critical illness, hospital indemnity, and accident insurance, as well as Employee Assistance Program (EAP) and digital mental health programs, parental leave, volunteer time off, tuition assistance and much more!
Recognized on Fortune magazine's list of the "World's Most Admired Companies", Fortune World’s 25 Best Workplaces™, as well as the Fortune 100 Best Companies to Work For®, MetLife, through its subsidiaries and affiliates, is one of the world’s leading financial services companies; providing insurance, annuities, employee benefits and asset management to individual and institutional customers. With operations in more than 40 markets, we hold leading positions in the United States, Latin America, Asia, Europe, and the Middle East.
Our purpose is simple - to help our colleagues, customers, communities, and the world at large create a more confident future. United by purpose and guided by our core values - Win Together, Do the Right Thing, Deliver Impact Over Activity, and Think Ahead - we’re inspired to transform the next century in financial services. At MetLife, it’s #AllTogetherPossible. Join us!
MetLife maintains a drug-free workplace.