Job Description
- Lead independent review, oversight, and credible challenge of enterprise-wide information security risk assessments, control testing results, and key risk metrics.
- Serve as the primary Second Line risk advisor for cybersecurity and technology-related risks.
- Partner closely with Information Security and Engineering teams to enhance risk awareness, accountability, and control ownership.
- Evaluate the design and operating effectiveness of security controls, particularly across complex, high-risk, or enterprise-scale technology initiatives.
- Review and challenge security-driven programs and initiatives to ensure alignment with enterprise risk appetite and regulatory expectations.
- Monitor information security findings, remediation plans, and validation activities to ensure timely and sustainable risk reduction.
- Identify root causes of control failures, security incidents, or systemic weaknesses and support the development of actionable, preventative recommendations.
- Prepare and present risk oversight materials to senior leadership committees, internal audit, and regulatory bodies as required.
- Contribute to the integration and maturation of information security within the firm’s enterprise risk management framework.
- Maintain governance documentation, including policies, standards, and procedures related to information security oversight.
- Act as a strategic thought partner to senior leaders by advising on emerging threats, evolving regulatory requirements, and industry best practices.
- Bachelor’s Degree required.
- 10+ years of experience in Information Security.
- 10+ years of experience in IT Risk Management.
- Demonstrated experience operating within a Second Line of Defense or independent risk oversight function.
- Strong understanding of cybersecurity control frameworks (e.g., NIST CSF, ISO 27001, COBIT, CIS).
- Experience interacting with regulators, internal audit, and executive governance forums.
- Authorized to work in the United States.
- Relevant professional certifications (e.g., CISSP, CISM, CRISC, CISA).
- Experience in regulated industries (e.g., financial services).
- Strong understanding of cloud security, application security, identity and access management, and cyber resilience.
- Familiarity with enterprise risk management methodologies and risk appetite frameworks.
- Strong analytical and critical thinking skills with the ability to provide constructive challenge.
- Executive-level communication and presentation skills.
- Ability to influence without direct authority.
- Strategic mindset with strong attention to detail.
- High integrity and independent judgment.
We offer one of the most comprehensive and generous benefits plans available and offer a range of total rewards that may include merit increases, incentive compensation (exempt roles only), paid holidays, paid time off, medical, dental, vision, short and long term disability benefits, 401(k) +match, life insurance, and various wellness programs, among others. The Company does not provide benefits directly to contingent workers/contractors and interns.