Director, Cyber Risk

Jobtailor

Sterling (VA)

On-site

USD 180,000 - 280,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking a seasoned Chief Cyber Risk Officer to lead and mature the enterprise cyber risk program across technology, regulatory and business domains. You will establish risk measurement, governance and reporting aligned with NIST CSF 2.0 and ISO standards while partnering with Legal, Privacy and Procurement to embed risk-informed decisions.

The role requires executive communication, cross-functional influence, and hands-on GRC platform experience to scale risk management across the

Qualifications

  • Bachelor’s degree in a related field or equivalent professional experience.
  • 10+ years in cybersecurity, IT/technology risk, or GRC, including 5+ years leading managers or multiple teams/domains.
  • Proven experience designing, leading, or maturing an end‑to‑end enterprise cyber/IT risk management program.
  • Deep knowledge of NIST CSF 2.0, ISO 27001/27005, regulatory regimes, and the three-lines‑of‑defense model.
  • Experience operating a risk register, risk appetite/tolerance framework, and risk acceptance/exception governance.
  • Hands‑on experience with GRC/IRM platforms (e.g., ServiceNow IRM, Archer, OneTrust, or comparable).
  • Excellent executive communication skills with a track record of briefing senior leadership and boards.
  • Strong cross‑functional influence partnering across security, technology, legal, privacy, and business teams.

Responsibilities

  • Own and improve the cyber and tech risk management framework aligned to standards.
  • Define standards for risk identification, assessment, and reporting.
  • Lead enterprise cyber risk assessments across domains.
  • Establish a cyber risk quantification capability to express risk in business terms.
  • Maintain the enterprise cyber risk register and KRIs/KCIs.
  • Operationalize risk appetite with leadership; manage governance.
  • Govern cyber risk policy structure and governance with escalation.
  • Lead second-line assurance over design and effectiveness of key cyber controls.
  • Own issues management from intake to closure.
  • Define and report metrics for residual risk and incidents.
  • Serve as primary contact for cyber risk in exams, audits.
  • Integrate cyber risk into Enterprise Risk Management with stakeholders.
  • Oversee vendor/third-party risk within cyber risk portfolio.
  • Build and develop a team of managers and analysts.

Skills

Executive communication
Cross-functional leadership
GRC collaboration

Education

Bachelor's degree or equivalent

Tools

ServiceNow IRM
Archer
OneTrust

Job description

Responsibilities
  • Own and continuously improve the cyber and technology risk management framework, methodology, taxonomy, and lifecycle aligned to NIST CSF 2.0, ISO 27001/27005, and applicable regulatory obligations.
  • Define standards, procedures, and rating scales for consistent enterprise-wide risk identification, assessment, and reporting; partner with the PISO model to ensure common language and practices across portfolios.
  • Lead enterprise cyber risk assessments across technology, business, regulatory, and emerging-risk domains to produce consistent, defensible determinations.
  • Establish and operate a cyber risk quantification capability (e.g., FAIR-based) to express risk in business and financial terms and inform prioritization and investment decisions.
  • Maintain the enterprise cyber risk register; ensure risks are well‑described, owned, rated, and tracked to acceptable residual levels; develop and manage KRI/KCI programs for forward‑looking posture.
  • Operationalize the risk appetite and tolerance framework with the CISO and senior leadership; own risk acceptance and exception governance with clear, auditable documentation and time‑bound approvals.
  • Govern cyber risk policy structure, ownership, review cadence, and exception handling; chair or support cyber risk forums and escape decisions to appropriate authority levels.
  • Lead second‑line, risk‑based assurance over design and operating effectiveness of key cyber controls in coordination with first‑line and Internal Audit; identify thematic weaknesses and drive structural remediation.
  • Own issues and remediation management—intake, prioritization, owner assignment, tracking to closure, and escalation of aging items.
  • Define and report outcome‑focused metrics (e.g., residual risk trends, out‑of‑appetite reduction, early‑versus‑late finding ratios, incidents tied to accepted risk) in executive‑ and board‑ready formats.
  • Serve as primary point of contact for cyber risk in regulatory exams, audits, and carrier‑partner due diligence.
  • Integrate cyber risk into Enterprise Risk Management to ensure consistency in enterprise risk reporting and governance; partner with Legal, Privacy, Procurement, and technology leaders to embed risk‑informed decisions.
  • Oversee vendor/third‑party risk within the cyber risk portfolio to ensure supply‑chain risk is governed in line with enterprise practices.
  • Build, lead, and develop a team of senior managers and analysts; set objectives, manage performance, and scale capacity through process improvement, tooling, and appropriate AI‑assisted workflows.
Requirements
  • Bachelor’s degree in a related field or equivalent professional experience.
  • 10+ years in cybersecurity, IT/technology risk, or GRC, including 5+ years leading managers or multiple teams/domains.
  • Proven experience designing, leading, or substantially maturing an end‑to‑end enterprise cyber/IT risk management program.
  • Deep knowledge of NIST CSF 2.0, ISO 27001/27005, relevant regulatory regimes, and the three‑lines‑of‑defense model.
  • Experience operating a risk register, risk appetite/tolerance framework, and risk acceptance/exception governance.
  • Hands‑on experience with GRC/IRM platforms (e.g., ServiceNow IRM, Archer, OneTrust, or comparable).
  • Excellent executive communication skills with a track record of briefing senior leadership and boards.
  • Strong cross‑functional influence partnering across security, technology, legal, privacy, and business teams.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director, Cyber Risk
Director, Cyber Risk

Asurion • Nashville (TN)

Hybrid
USD 150,000 - 200,000
Senior Director, GRC, IT Controls, Cyber Culture
Senior Director, GRC, IT Controls, Cyber Culture

Jobtailor • Town of Florida (NY)

On-site
USD 180,000 - 240,000
Group Director, Cyber Risk & Security Engineering
Group Director, Cyber Risk & Security Engineering

Brobston Group LLC • New York (NY)

On-site
USD 180,000 - 240,000
Director, Risk Management – Information Security
Director, Risk Management – Information Security

Jobtailor • Arizona

On-site
USD 120,000 - 180,000
Chief Information Security Officer
Chief Information Security Officer

Glocomms • Charlotte (NC)

On-site
USD 150,000 - 200,000
Senior Analyst, Cyber Risk Governance & Reporting
Senior Analyst, Cyber Risk Governance & Reporting

Jobtailor • South Carolina

On-site
USD 70,000 - 110,000
Senior Director, Information Security (Relocation eligible)
Senior Director, Information Security (Relocation eligible)

Solving IT • Nashville (TN)

On-site
USD 180,000 - 260,000
Cybersecurity Manager
Cybersecurity Manager

BMA Group Global • Guaynabo (PR)

On-site
USD 120,000 - 190,000
CRO - Information Security & Risk Oversight Lead
CRO - Information Security & Risk Oversight Lead

Bloomberg • New York (NY)

On-site
USD 140,000 - 180,000
Manager, Cybersecurity
Manager, Cybersecurity

Carey International Group, LLC • Orlando (FL)

On-site
USD 130,000 - 190,000