Cybersecurity Governance Manager

OneMain Financial

Maryland

On-site

USD 150,000 - 185,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

OneMain Financial is seeking a Manager of Cybersecurity Governance to lead a comprehensive governance framework for on‑premise and cloud environments, ensuring regulatory compliance and risk visibility across the technology stack.

You will partner with risk, internal audit, and technology teams to drive policy, controls, and assurance activities, and establish a data‑driven GRC program delivering management insights to reduce risk.

Qualifications

  • Bachelor's degree in Cybersecurity, IT, or equivalent.
  • 5–7 years in governance and controls in finance or regulated industry.
  • 3–5 years in a leadership role.
  • Deep knowledge of NIST, SOC2, and CIS.
  • Familiarity with GLBA 501(b), NYDFS, PCI.
  • Strong communication and program management skills.

Responsibilities

  • Establish and maintain a security governance framework based on NIST CSF.
  • Oversee policy program, drafting policies, controls, and enforcement.
  • Maintain risk and controls matrix aligned with SOC2, CIS, PCI, NIST.
  • Lead annual enterprise technology and cybersecurity risk assessment.
  • Establish an automated GRC program to monitor risk and control effectiveness.
  • Lead annual NYDFS Part 500 Cybersecurity self-assessment.
  • Oversee SOC2 audits and regulatory exams.
  • Educate and direct projects to apply policies across tech, systems and services.
  • Coordinate with risk management, internal audit, and cyber risk teams.
  • Partner with architects, engineers, and operations to implement governance controls.
  • Lead metrics and reporting program for senior management.

Skills

Governance leadership
Regulatory compliance
Cybersecurity frameworks
Policy development
Communication & collaboration

Education

Bachelor's degree in Cybersecurity/IT

Tools

Archer
Power BI
Anecdotes

Job description

We are seeking a Manager of Cybersecurity Governance to join our dynamic team reporting to the Director of Cybersecurity Governance and Risk. This role will lead the development of a comprehensive technology and cybersecurity governance framework tailored to our on-premise and cloud environments. This role is critical in ensuring that our company's technology and cybersecurity practices are compliant with regulatory requirements and industry standards, while also effectively identifying risks.

Members of the Cybersecurity Governance team are motivated, detail-oriented, and thrive in a collaborative environment where they will add value to key business partners. This position will require you to be adaptive, willing to drive change and innovation, and work in a fast-paced environment requiring collaboration and the ability to organize and prioritize assignments.

Responsibilities
  • Establish and maintain a security governance framework based on the National Institute of Standards and Technology (NIST) Cybersecurity Framework to ensure effective oversight and accountability.
  • Oversee the technology and cybersecurity policy program, which includes policy and control drafting, facilitating cross-functional input, and enforcement of policies, procedures, and controls.
  • Maintain the company's technology and cybersecurity risk and controls matrix in alignment with multiple frameworks, including SOC2, CIS, PCI, NIST CSF, NIST 800-53, and NYDFS Part 500.
  • Lead the annual enterprise technology and cybersecurity risk assessment.
  • Establish an automated technology and cyber governance risk and compliance (GRC) program to continuously monitor and report on technology and cyber risk and control effectiveness.
  • Lead the company's annual NYDFS Part 500 Cybersecurity self-assessment.
  • Oversee and facilitate the annual SOC2 audit and any exams and assessments focused on technology and cybersecurity controls from state examiners, regulators, and OneMain partners.
  • Educate, influence and provide clear directives for technology projects, either directly or through committees, to ensure the consistent application of policies, standards and controls across all technology projects, systems and services.
  • Partner and coordinate with the enterprise risk management team, internal audit, and other functions within the cyber risk team to ensure appropriate oversight and management of cyber risks and controls in-line with OneMain’s enterprise risk management framework.
  • Partner with cybersecurity architects, engineers, and technology operations teams to ensure governance programs for access privileges, applications, cloud environments, asset management, artificial intelligence, and other technology functions are implemented and maintained according to cybersecurity standards and guidelines.
  • Lead a metrics and reporting program to measure the efficiency and effectiveness of the cybersecurity program for senior management providing insights, trends and recommendations.
Qualifications
  • Bachelor's Degree with a focus in Cybersecurity, Information Technology disciplines or equivalent experience.
  • Minimum of 5 - 7 years of experience in planning, designing, implementing and managing technology and cybersecurity governance and controls framework in the financial industry or other regulated industry.
  • Minimum 3 - 5 years in a leadership role with a strong ability to influence peers, leaders and team members at all levels and across functional lines.
  • In-depth knowledge of cybersecurity frameworks, such as NIST, SOC2, and CIS.
  • In-depth knowledge of cybersecurity laws and regulations, industry standards and best practices including GLBA 501(b), NYDFS and PCI.
  • Excellent verbal and written communication and presentation skills with the ability to prepare and deliver complex data in a way that is concise/understandable.
  • Strong organizational and program management skills. Ability to effectively respond to shifting priorities and assignments.
  • Sound analytical, problem solving and research skills.
  • Proficient in computer skills in Microsoft Office suite - Word, Excel, and PowerPoint.
  • Familiarity with GRC, metrics, and reporting tools like Archer, Anecdotes, Power BI, or equivalent software a plus.
  • Self-motivation with proven ability to be adaptable to a dynamic, fast-paced work environment with multiple priorities and strict timelines.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Governance Manager
Cybersecurity Governance Manager

OneMain Financial • Baltimore (MD)

On-site
USD 140,000 - 180,000
Senior Cybersecurity Governance & Risk Lead
Senior Cybersecurity Governance & Risk Lead

OneMain Financial • Maryland

On-site
USD 150,000 - 185,000
Strategic Cybersecurity Governance Lead
Strategic Cybersecurity Governance Lead

OneMain Financial • Baltimore (MD)

On-site
USD 140,000 - 180,000
Cybersecurity Manager
Cybersecurity Manager

BMA Group Global • Guaynabo (PR)

On-site
USD 120,000 - 190,000
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

mTrade • Oxford (MS)

On-site
USD 110,000 - 160,000
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

mTrade, LLC. • Oxford (MS)

On-site
USD 110,000 - 160,000
Chief Information Security Officer
Chief Information Security Officer

Glocomms • Charlotte (NC)

On-site
USD 150,000 - 200,000
Senior Analyst, Cyber Risk Governance & Reporting
Senior Analyst, Cyber Risk Governance & Reporting

Jobtailor • South Carolina

On-site
USD 70,000 - 110,000
Senior Manager, Cyber Governance, Risk, and Compliance
Senior Manager, Cyber Governance, Risk, and Compliance

Fayette Chamber of Commerce • Atlanta (GA)

On-site
USD 150,000 - 190,000
SVP & Director of IT Governance - Cyber Security
SVP & Director of IT Governance - Cyber Security

WesBanco Bank Inc. • Huntington (WV)

On-site
USD 150,000 - 230,000