CRO - Information Security & Risk Oversight Lead

Bloomberg

New York (NY)

On-site

USD 140,000 - 180,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Bloomberg is seeking an experienced Information Security Risk Oversight Lead to join their team in New York City. This role involves translating cybersecurity risks into executive insights while providing independent oversight across the firm’s information security program.

The ideal candidate will have over 10 years of experience in Information Security and IT or Cyber Risk Management, alongside a strong grasp of cybersecurity control frameworks. Responsibilities include evaluating security controls and preparing risk oversight materials for senior leadership.

Qualifications

  • 10+ years of experience in Information Security.
  • 10+ years of experience in IT or Cyber Risk Management.
  • Experience operating within a Second Line of Defense.

Responsibilities

  • Serve as the primary Second Line risk advisor for cybersecurity related risks.
  • Identify and measure threat-actor initiated risks.
  • Evaluate effectiveness of security controls.
  • Quantify risk to support executive decision-making.

Skills

Information Security
IT or Cyber Risk Management
Cybersecurity Control Frameworks
Analytical and Critical Thinking
Executive Communication

Education

Bachelor’s Degree

Tools

NIST CSF
ISO 27001
CISSP

Job description

The energy of a newsroom, the pace of a trading floor, the buzz of a recent tech breakthrough; we work hard, and we work fast - while keeping up the quality and accuracy we’re known for. It's what keeps us inventing and reinventing, all the time. Our culture is wide open, just like our spaces. We bring out the best in each other through collaboration. Through our countless volunteer projects, we also help network with the communities around us, too. You can do amazing work here. Work you couldn’t do anywhere else. It's up to you to make it happen.

About the Role

We’re looking for an Information Security Risk Oversight Lead who can translate cybersecurity risk into executive insight and action. Sitting in the Company’s Second Line of Defense, the Chief Risk Office and reporting directly to our Head of Technology Risk, you will provide independent oversight and credible challenge across the firm’s enterprise-wide information security program. Operating at the intersection of technology, risk management, cybersecurity, governance and strategy, you will partner with the Chief Information Security Office, Engineering, and CTO teams to ensure cyber risks are appropriately identified, measured, monitored, and aligned with the firm’s risk appetite. The “so what” is critical: your oversight will enable leadership to understand not only what the risks are, but whether they are being managed effectively—and where decisive action is required to strengthen the firm’s overall security posture.

Key Responsibilities
  • Serve as the primary Second Line risk advisor for cybersecurity related risks and lead independent oversight and credible challenge of First Line of Defense activities.
  • Identify and measure threat-actor initiated risks and risk scenarios that may impact the confidentiality, integrity, and availability of information systems.
  • Evaluate the design and operating effectiveness of security controls, particularly across complex, high-risk, or enterprise-scale technology initiatives.
  • Quantify risk and control posture to support executive decision-making through scenario analysis and metrics (e.g., KRIs, KPIs, SLA/SLOs, ALE).
  • Review and challenge security-driven programs and initiatives to ensure alignment with enterprise risk appetite, industry control frameworks, and regulatory expectations.
  • Partner closely with Information Security and Engineering teams to enhance risk awareness, accountability, and control ownership.
  • Identify root causes of control failures, security incidents, or systemic weaknesses and support the development of actionable, preventative recommendations.
  • Prepare and present risk oversight materials to senior leadership committees, internal audit, Board of Directors, and regulatory bodies as required.
  • Act as a strategic thought partner to senior leaders by advising on emerging threats, evolving regulatory requirements, and industry best practices.
Required Qualifications
  • Bachelor’s Degree required.
  • 10+ years of experience in Information Security.
  • 10+ years of experience in IT or Cyber Risk Management.
  • Demonstrated experience operating within a Second Line of Defense or independent risk oversight function.
  • Strong understanding of cybersecurity control frameworks (e.g., NIST CSF, NIST 800-53, MITRE ATT&CK, ISO 27001, COBIT, CIS).
  • Experience interacting with Boards, regulators, internal audit, and/or executive governance forums.
  • Authorized to work in the United States.
Preferred Qualifications
  • Relevant professional certifications (e.g., FAIR, CISSP, CISM, CRISC, CISA).
  • Experience in regulated industries (e.g., financial services).
  • Strong understanding of cloud security, application security, identity and access management, and cyber resilience.
  • Familiarity with enterprise risk management methodologies and risk appetite frameworks.
Core Competencies
  • Strong analytical and critical thinking skills with the ability to provide constructive challenge.
  • Executive-level communication and presentation skills.
  • Ability to influence without direct authority.
  • Strategic mindset with strong attention to detail.
  • High integrity and independent judgment.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Consultant, Financial Services
Senior Cybersecurity Consultant, Financial Services

Jobtailor • California (MO)

On-site
USD 120,000 - 180,000
Tech Risk, Risk Practices and Controls Management - Vice President, Dallas
Tech Risk, Risk Practices and Controls Management - Vice President, Dallas

Goldman Sachs • Dallas (TX)

On-site
USD 180,000 - 320,000
Tech Risk & Controls - Executive Director
Tech Risk & Controls - Executive Director

JPMorgan Chase & Co. • Plano (TX)

On-site
USD 180,000 - 250,000
Chief Information Security Officer
Chief Information Security Officer

Glocomms • Charlotte (NC)

On-site
USD 150,000 - 200,000
Cyber Risk Sr. Group Manager, Director
Cyber Risk Sr. Group Manager, Director

Citi • New York (NY)

On-site
USD 170,000 - 300,000
Medical, dental and vision coverage
401(k)
Life, accident and disability insurance
+2
Information Security Operations Lead
Information Security Operations Lead

Top Prospect Group • Connecticut

On-site
USD 130,000 - 155,000
Technology and Information Security Risk Specialist
Technology and Information Security Risk Specialist

IDBNY • New York

Hybrid
USD 160,000 - 180,000
Annual bonus
Medical coverage
Dental & vision
Vice President – Information Technology & Cyber Risk Mgmt
Vice President – Information Technology & Cyber Risk Mgmt

Crédit Agricole CIB • New York (NY)

Hybrid
USD 170,000 - 210,000
IP Tech Risk and Controls Director
IP Tech Risk and Controls Director

JPMorgan Chase & Co. • Columbus (OH)

On-site
USD 140,000 - 210,000
IP Tech Risk and Controls Director
IP Tech Risk and Controls Director

JPMorgan Chase & Co. • Kentucky

On-site
USD 180,000 - 280,000