Senior Associate, Cyber and Digital Risk Management
- Establish themselves as one of the second line of defense subject matter experts for key stakeholders in the management of cybersecurity and technology risks across all operating entities
- Identify and assess cybersecurity risks and participate in the independent and ongoing risk oversight of key technology components of the firm's digital transformation initiatives.
- Participate in evaluation of new products / Business changes / projects and assess related cybersecurity risks and impact to the technology risk profile
- Participate in the evaluation and management of cybersecurity risks related to third-party suppliers involved in technology and business projects
- Manage and execute targeted risk reviews designed to evaluate information security risks and their effective and sustainable mitigation
- Perform review and challenge of first line of defense information security risk management processes, data and outcomes (e.g. risk assessments, control evaluations, risk metrics, mitigation plans, risk acceptances etc.) and support the development of risk opinions for various levels of management
- Analyze information security / cyber risk data from various sources (e.g. external events, control deficiencies, risk register etc.) to identify and measure levels of risk, concentration, trends and patterns
- Contribute to the updating of existing information security policies and framework or develop new ones that steer the safe and sound adoption of technologies across the organization
- Monitor external trends and evaluate potential impacts to business strategy; provide documented analytical insights of the cyber risk horizon, while ensuring a sound operational and compliance control environment through establishment of a system of effective and sustainable internal controls
- Be able to analyze, assess and advise on remediation of regulatory findings, correction of any inconsistencies and monitors resolution
- Prepare information to enable governance committees / working groups in the management oversight of cybersecurity and technology risks
- Support process for constructive engagement across the Lines of Defense regarding differences or conflicts in risk appetite, risk metric determination or evaluation, issue severity or other areas of dispute
- Initiate timely escalations to the Sr. Director, Cyber & Digital Risk and to the leadership team
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. Education:
- Bachelor's Degree in a technical discipline or equivalent work experience: Computer Science, Information Technology, Information Systems, Information Security. Required
- Master's Degree in related technical disciplines. Pref
- Professional Certifications in Cybersecurity. Required
- Professional Certifications in Cloud Security (AWS, Azure). Pref
- Professional and practitioner experience of 9+ years in one or more areas of cybersecurity risk management roles in a matrix organization
- Experience in Cybersecurity risk consulting in the financial services sector, Cyber security audit, Chief Information Security Office or in a similar second line of defense role is highly preferred
- Experience within a highly regulated environment such as the financial services industry and knowledge of the current and evolving regulatory landscape is necessary
- Strong understanding of multiple information security and cyber risk domains, and knowledge of industry good practice standards
- Experience with execution of technology & cyber risk oversight programs, preferably in a 2nd or 3rd line of defense
- Demonstrated ability to coordinate oversight activities across different teams
- Knowledge of current and evolving regulatory requirements and industry best practices in technology and cybersecurity risk management
- Strong experience as a team player, adaptability and flexibility
- Resilient Security Architecture
- Identity and Access Management
- Network / Firewall Management
- Vulnerability and Patch Management
- Cloud Security Architecture
- Secure Application Development / Containerization
- Encryption / Tokenization
- Data Loss Prevention
- Security Logging and Monitoring
- Incident Detection and Response Management
- Offensive Security
- Demonstrated expertise and track record in information security and cyber risk management, and ability to perform at an advanced level of competence.
- Strong risk, process, and control validation and/or assessment skills.
- Advanced knowledge of technical risk management best practices and how to implement them.
- A keen sense of attention to details with a passion for impeccable documentation while having the ability to multi-task and adapt/adjust to multiple demands and competing priorities
- A high degree of intellectual curiosity to research, study and assess technical documentation to support oversight activities
- A team player who can coordinate and drive consensus among different teams and stakeholders having varying view points
- Ability to convey a sense of urgency and drive issues/projects to closure.
- Excellent written and oral communication skills.
- Excellent analytical, organizational and project management skills.
- Professional Certifications in Cybersecurity. Required
- Professional Certifications in Cloud Security (AWS, Azure). Pref
- Established work history or equivalent demonstrated through a combination of work experience, training, military service, or education.
- Experience in Microsoft Office products.
. click apply for full job details
Recommended Jobs
Pediatric Speech Pathologist - Sarasota, FL
Job Description – Pediatric Speech-Language Pathologist (Part-Time) Location: Lakewood Ranch, FL Company: Word Therapy About Us: With over 25 years of expertise in Speech Pathology…
Irrigation Technician- San Antonio, FL
We are in need of someone who wants to learn the Irrigation business. We are looking to find an Irrigation Technician Assistant. All duties will be trained. Summary of Duties include: 1. Ability …
Program Manager
King Technologies has a contingent Program Manager position available. Overall responsibility for managing scope, cost, schedule, internal staffing, outside vendors, and contractual deliverables for …
Security Professional - Armed Government Center - Full Time
Allied Universal®, North America's leading security and facility services company, offers rewarding careers that provide you a sense of purpose. While working in a dynamic, welcoming, and collaborativ…
Director of Operations
Location: On Site – Pompano, FL Department: Operations Reports to: Chief Administrative Officer Salary: Competitive, based on experience About Us Founded in 2016, Boca Re…
Care Management Assistant - GCMC
Location: Gulf Coast Medical Center -13681 Doctor's Way Fort Myers FL 33912 Department:Care Management Work Type:Full Time Shift:Shift 1/8:00:00 AM to 4:30:00 PM / 5 days per week, including …
REGISTERED NURSE MANAGER - SURGICAL SERVICES
JOB RESPONSIBILITIES- Registered Nurse Manager - Surgical Services RN MGR - OR Full-Time Registered Nurse Manager candidates for the Surgical Services Department will have the …
Registered Nurse RN Surgical PCU - AdventHealth - Daytona Beach, Florida, United States
All the benefits and perks you need for you and your family: Up to $3,000 Relocation Assistance available for eligible candidates (see terms below) Benefits and Paid Days Off from Day One Pai…
ER RN OOJ - 34761 OOJ - 34760 OOJ - 34749 OOJ - 34781
Job Description An ER RN, or Emergency Room Registered Nurse, assesses and treats patients with serious or life-threatening conditions, requiring quick thinking and decision-making skills in a fas…
Project Coordinator
Company Overview At Everon, we truly believe that our people are the difference – for our organization, the customers we serve and the communities we protect. When you’re a part of Everon, you’ll …