Amanda Bolton
IT Security Governance Partner @Weir
Signup · Get unlimited contacts
WORK HISTORY
IT Security Governance Partner @Weir
Glasgow, GB
Working with the Chief Information Security Officer (CISO) to drive an improved maturity in the Weir Groups Information Security governance; Key responsibilities include:* Development and implementation of Information Security Controls Framework based on NIST CSF.* Develop, implement, lead and manage the group third-party security assurance process including the development of new tooling to support the business in managing third-party security risk in our supply chain.* Lead and manage the six monthly security attestation process with each of the Weir operating companies.* Lead internal and supplier assurance exercises against NIST CSF/ISO27001 Information Security Controls, to ensure that our teams and suppliers are fully aligned with our controls.* The development the implementation of a remediations process, to include the creation of a findings register, to ensure that all findings are logged, tracked, managed and reported on.* Develop and maintain the Information Security Policies for the group, including ISP (AUP), Third Party Assurance, BYOD, UAM, Cloud, Data Classification etc.* Manage the communication of our policies to ensure that the business understands their responsibilities in terms of Information Security.* Development of scalable information security contract schedules to reduce supply chain risk.* Management of Information Security Risk for the Weir Group, ensuring that risks are understood and remain up-to-date/managed.* Lead activities for the development a Crisis Management Framework, working with leaders from across the globe to ensure that the framework is repeatable regardless of the type of Crisis.* Deputise/cover for the CISO as required.
SKILLS
ABOUT AMANDA BOLTON
I am a highly skilled Information Security professional with specific interest in Internal & Supplier Assurance, Information Security Certifications, Remediations Management, IT Quality, Compliance, Governance and Risk Management. I am a proficient auditor with strong experience in internal and supplier auditing against ISO27001, and firm wide policies and controls. I have developed control and audit frameworks to standardise audit processes and ensure that audits are conducted consistently by all team members, regardless of individual experience or knowledge. I am an excellent leader and people manager with superb organisation and leadership skills; a high performing employee who always delivers to a high standard and on target. Service, Audit & Project Management Skills: ISO27001 Lead Auditor, Implementer, Audit Management, Security Management Fundamentals, Advanced ESARIS (Enterprise Security Architecture for Reliable ICT Service), Risk Management, Information Protection, ITIL Expert V3 (Lilac Badge), ITIL Managers Certificate in ITSM V2 (Red Badge), 6 Sigma Black Belt (DMAIC), IT Service Management Foundation (Green Badge), COBIT Foundation, Prince 2 Overview, Project Management, Process specific training includes: Incident (incl. Zero Outage), Problem, Change, SACM, Request Fulfilment and Event Management.Personal & Management Skills: Leadership, Influencing & Persuading, Negotiation Skills, Meeting Facilitation & Presentation Skills, Effective Communication, Time Management & Customer Service.Technical Skills: Telecoms & GSM Fundamentals, TCP/IP Protocol Suite, Netcool OMNIbus User & Admin, Business Objects Web Intelligence, Microsoft NT Admin.(MCSE), Building Effective PC System Support Skills (A+ Certified Hardware Engineer), UNIX Basics, ARIS (Process Modelling). Service Management Tools: Service Now, Remedy E-Service Desk, Axios Assyst, HP Service Center, Service Manager & Asset Manager.
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.