- This role is responsible for building and strengthening relationships across the Bank with technical leads and business partners, to understand technology stacks, designs, and review processes in support of the Bank’s cyber risk management practices.
- The role will assist management in the development, implementation, and execution of a measurements-based cyber risk management program.
- The primary responsibility will be to review and assess new and existing vendor engagements and collaborate with technical leads and business partners to ensure comprehensive vendor portfolio management.
Requirements
- Bachelor’s degree in computer science, management information systems (MIS), engineering, statistics or related field, or equivalent work experience required.
- Two (2) or more years of experience in information security required.
- Certified Information Systems Security Professional (CISSP), ISACA Certified in Risk and Information Systems Control (CRISC), or comparable security certification desired.
- Working knowledge of requirements for Federal Financial Institutions Examination Council (FFIEC) IT examination, Gramm-Leach-Bliley Act (GLBA) Information Security Standards and Sarbanes-Oxley Section 404 (“Management Assessment of Internal Controls”).
- Performs cybersecurity risk assessments and ongoing monitoring.
- Coordinates with managers and staff of IT, business units, and executive management.
- Interacts with consultants and vendors as required.
- Experience designing, implementing, and managing risk management processes and workflows.
- Cyber risk management experience.
- Develop and implement security plans and projects.
- Knowledgeable in risk quantification modeling and platforms (e.g., strong understanding of basic probability, calibrated estimations, monte carlo simulations, etc.).
- Able to plan, organize and budget.
- Excellent written and verbal communication with demonstrable experience collaborating with technically oriented as well as business audiences.
- Strong critical thinking and analytical skills.
- Able to handle confidential matters judiciously.
- Possesses attention to detail with excellent follow-through.
- Able to work under pressure with multiple deadlines.
- Excellent time management skills.
- Demonstrated ability to work under pressure and manage multiple deadlines to completion in a timely manner with quality results.
- Proficiency in Microsoft 365 suite of applications.
Core Competencies
Demonstrates expertise in Cyber Risk Management, including the development and execution of risk management programs, vendor portfolio management, and cybersecurity risk assessments. Proficient in collaborating with technical and business partners to ensure compliance with relevant regulations and standards.
Highest-signal resume keywords
- Cyber Risk Management
- Information Security Experience
- Certified Information Systems Security Professional (CISSP)
- Risk Quantification Modeling
- Federal Financial Institutions Examination Council (FFIEC) Compliance
ATS Optimization Keywords
Hard Skills
- Cybersecurity Risk Assessments
- Risk Management Processes
- Vendor Portfolio Management
- Security Plans Development
- Risk Quantification Modeling
Soft Skills
- Excellent Communication
- Critical Thinking
- Analytical Skills
- Attention to Detail
- Time Management
Certifications & Qualifications
- Certified Information Systems Security Professional (CISSP)
- ISACA Certified in Risk and Information Systems Control (CRISC)
Industry Keywords
- Gramm-Leach-Bliley Act (GLBA)
- Sarbanes-Oxley Section 404
- Federal Financial Institutions Examination Council (FFIEC)
Tools & Technologies