Head of Information Security Risk - Chief Risk Office

Bloomberg

New York (NY)

On-site

USD 180,000 - 260,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Bloomberg is seeking a Head of Information Security Risk to translate cyber risk into executive insight and technical solutions. You will oversee enterprise-wide information security risk, report to the Chief Risk Office, and partner with CISOs, ERM, and Engineering to strengthen the security posture across the firm.

You will lead a team of risk professionals, advise leadership on emerging threats, and ensure regulatory expectations are met while aligning programs with the firm’s risk appetite.

Qualifications

  • Bachelor’s degree required.
  • 10+ years in one or more technical information security disciplines.
  • Experience in independent oversight within a Risk/Information Security/Architecture team.
  • Strong knowledge of cybersecurity frameworks (NIST CSF, NIST 800-53, MITRE ATT&CK, ISO 27001).
  • Experience interacting with boards, regulators, internal audit, or governance forums.

Responsibilities

  • Serve as the primary Second Line advisor for cybersecurity-related risks and lead independent oversight and credible challenge of First Line activities.
  • Evaluate and consult on design and operating effectiveness of security programs and controls across enterprise initiatives.
  • Review and challenge security programs to ensure alignment with risk appetite and regulatory expectations.
  • Partner with Information Security, CISO, ERM, and Engineering to enhance risk awareness and control ownership.
  • Identify root causes of control failures or incidents and support actionable recommendations.
  • Prepare and present risk oversight materials to senior leadership committees, internal audit, and the board as required.
  • Advise senior leaders on emerging threats and evolving regulatory requirements.
  • Attract, hire and manage a team of technical risk professionals.

Skills

InfoSec governance
Security architecture
Penetration testing
Application security
Cyber defense
Executive communication
Leadership

Education

Bachelor's degree

Job description

The energy of a newsroom, the pace of a trading floor, the buzz of a recent tech breakthrough; we work hard, and we work fast - while keeping up the quality and accuracy we're known for. It's what keeps us inventing and reinventing, all the time. Our culture is wide open, just like our spaces. We bring out the best in each other through collaboration. Through our countless volunteer projects, we also help network with the communities around us, too. You can do amazing work here. Work you couldn't do anywhere else. It's up to you to make it happen.

About the Role

We’re looking for a Head of Information Security Risk who can translate cybersecurity risk into both executive insight and technical solutions. Reporting directly to our Head of Technology Risk as part of the Chief Risk Office, you will provide independent oversight, technical consultation and credible challenge across the firm’s enterprise-wide information security program. Operating at the intersection of cybersecurity, risk management, governance, and strategy, you will be the senior cyber-risk partner to the Chief Information Security Office, Engineering, and Chief Technology Office. You will engage on topics ranging from technical security findings to programmatic decisions and regulatory strategy to ensure the company is operating within its target risk appetite and regulatory expectations. Your oversight will enable Bloomberg’s senior leadership to understand not only what the risks are, but where decisive action is required to strengthen the firm’s overall security posture.

Key Responsibilities
  • Serve as the primary Second Line advisor for cybersecurity-related risks and lead independent oversight and credible challenge of First Line of Defense activities.
  • Evaluate and consult on the design and operating effectiveness of security programs and controls, particularly across complex, high-risk, or enterprise-scale technology initiatives.
  • Review and challenge security-driven programs and initiatives to ensure alignment with enterprise risk appetite, industry control frameworks, and regulatory expectations.
  • Partner closely with Information Security, CISO, ERM, and Engineering teams to enhance risk awareness, accountability, and control ownership.
  • Identify root causes of control failures, security incidents, or systemic weaknesses and support the development of actionable, preventative recommendations.
  • Prepare and present risk oversight materials to senior leadership committees, internal audit, Board of Directors, and regulatory bodies as required.
  • Act as a strategic thought partner to senior leaders by advising on emerging threats, evolving regulatory requirements, and industry best practices.
  • Attract, hire and manage a team of technical risk professionals to identify and measure threat-actor initiated risks and risk scenarios that may impact the confidentiality, integrity, and availability of information systems.
Required Qualifications
  • Bachelor’s Degree required.
  • 10+ years of experience in one or more technical Information Security disciplines (security architecture, penetration testing, application security, cyber defense, etc.).
  • Demonstrated experience operating within an independent oversight function as part of a Risk, Information Security, or Architecture team.
  • Strong understanding of cybersecurity frameworks (e.g., NIST CSF, NIST 800-53, TLPT/TIBER-EU, MITRE ATT&CK, ISO 27001, COBIT, CIS).
  • Experience interacting with Boards, regulators, internal audit, and/or executive governance forums.
  • Authorized to work in the United States.
Preferred Qualifications
  • Relevant technical and/or professional certifications (e.g., GIAC GPEN/GDAT, CREST, FAIR, CISSP, CISM, CRISC, CISA).
  • Experience in regulated industries (e.g., financial services).
  • Strong understanding of cloud security, application security, identity and access management, and cyber resilience.
  • Familiarity with enterprise risk management methodologies and risk appetite frameworks.
Core Competencies
  • Strong analytical and critical thinking skills with the ability to provide constructive challenge.
  • Executive-level communication and presentation skills.
  • Ability to influence without direct authority.
  • Strategic mindset with strong attention to detail.
  • High integrity and independent judgment.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

CRO - Information Security & Risk Oversight Lead
CRO - Information Security & Risk Oversight Lead

Bloomberg • New York (NY)

On-site
USD 140,000 - 180,000
Information Security Risk Manager
Information Security Risk Manager

Bloomberg • New York (NY)

On-site
USD 160,000 - 215,000
Medical, dental, vision
401(k) match
Life insurance
+1
Information Security Risk Manager New York, NY Posted today
Information Security Risk Manager New York, NY Posted today

Bloomberg L.P. • New York (NY), Northern (KY)

Hybrid
USD 160,000 - 215,000
Medical, dental, vision coverage
Short & long-term disability benefits
401(k) + match
+3
Chief Information Security Risk Officer
Chief Information Security Risk Officer

Bloomberg • New York (NY)

On-site
USD 180,000 - 260,000
InfoSec Risk Oversight Lead — Executive Risk Partner
InfoSec Risk Oversight Lead — Executive Risk Partner

Bloomberg • New York (NY)

On-site
USD 140,000 - 180,000
Risk Manager - Engineering - CRO New York, NY Posted yesterday
Risk Manager - Engineering - CRO New York, NY Posted yesterday

Bloomberg L.P. • Northern (KY), New York (NY)

Hybrid
USD 130,000 - 180,000
Benefits package
Information Security Risk Manager: Elevate Controls & Insight
Information Security Risk Manager: Elevate Controls & Insight

Bloomberg • New York (NY)

On-site
USD 160,000 - 215,000
Medical, dental, vision
401(k) match
Life insurance
+1
Technology Risk - Control Enablement and Transformation-Dallas-Vice President
Technology Risk - Control Enablement and Transformation-Dallas-Vice President

Goldman Sachs • Dallas (TX)

On-site
USD 150,000 - 190,000
Technology Risk - Control Enablement and Transformation-Dallas-Vice President
Technology Risk - Control Enablement and Transformation-Dallas-Vice President

The Goldman Sachs Group • Dallas (TX)

On-site
USD 150,000 - 210,000
Employee Experience Control Manager
Employee Experience Control Manager

Bloomberg • New York (NY)

On-site
USD 140,000 - 200,000