Information Security Risk Manager

Bloomberg

New York (NY)

On-site

USD 160,000 - 215,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Medical, dental, vision
401(k) match
Life insurance
Paid time off

Job summary

Bloomberg is seeking an Information Security Risk Manager to unite cybersecurity expertise with risk oversight. You will report to the Head of Information Security Risk in the Chief Risk Office and support independent oversight, credible challenge, and clear risk communications across the firm’s security program.

You will collaborate with Information Security, CISO, Engineering, Technology Risk, and Enterprise Risk Management to identify, assess, and resolve cybersecurity risks, translating

Qualifications

  • Bachelor’s degree or equivalent professional experience.
  • 5+ years of relevant security risk experience.
  • Ability to translate risks into actionable insights.
  • Familiarity with NIST CSF, NIST 800-53, MITRE ATT&CK, ISO 27001, COBIT, or CIS.
  • Strong written and verbal communication.
  • Authorized to work in the United States.

Responsibilities

  • Support Second Line oversight and credible challenge of cybersecurity risks across the organization.
  • Assess security risks and advise on the design and effectiveness of security controls across technology initiatives and security programs.
  • Review security programs and initiatives to assess alignment with enterprise risk standards, established security frameworks, and regulatory expectations.
  • Partner with Information Security, CISO, Engineering, Technology Risk, and Enterprise Risk Management teams to strengthen risk awareness and control ownership.
  • Analyze security findings, incidents, control weaknesses, and risk scenarios to identify themes, root causes, and opportunities for improvement.
  • Develop practical recommendations to address identified security and control risks.
  • Assist in developing cybersecurity risk assessments, reporting, metrics, and materials for management and governance forums.
  • Monitor emerging cybersecurity threats, regulatory developments, and industry practices and assess their potential relevance to the organization.
  • Participate in risk assessments of areas including cloud security, application security, identity and access management, cyber defense, vulnerability management, and cyber resilience.
  • Build strong relationships across technical and risk teams and provide thoughtful, constructive challenge when appropriate.

Skills

Security risk management
Cybersecurity knowledge
Communication skills
Stakeholder management
Cross-functional collaboration
Regulatory awareness
Independent risk oversight

Education

Bachelor’s degree or equivalent professional experience

Tools

NIST CSF
NIST 800-53
MITRE ATT&CK
ISO 27001
COBIT
CIS

Job description

We're looking for an Information Security Risk Manager who can bring together cybersecurity knowledge, risk management, and strong analytical skills. Reporting to the Head of Information Security Risk within the Chief Risk Office, you will support independent oversight and credible challenge across the firm’s information security program. You will work closely with colleagues across Information Security, CISO, Engineering, Technology Risk, and Enterprise Risk Management to identify, assess, communicate, and resolve cybersecurity risks. This role is well suited to someone with a strong foundation in cybersecurity who is looking to broaden their experience within an independent risk oversight function. You will have exposure to a range of security topics, from technical security findings and control effectiveness to cyber resilience, emerging threats, and regulatory requirements. You will help translate technical security risks into clear, actionable insights and support the organization in understanding where controls can be strengthened and risks appropriately managed.

Key Responsibilities
  • Support Second Line oversight and credible challenge of cybersecurity and information security risks across the organization.
  • Assess security risks and consult on the design and effectiveness of security controls across technology initiatives and security programs.
  • Review security programs and initiatives to assess alignment with enterprise risk standards, established security frameworks, and regulatory expectations.
  • Partner with Information Security, CISO, Engineering, Technology Risk, and Enterprise Risk Management teams to strengthen risk awareness, accountability, and control ownership.
  • Analyze security findings, incidents, control weaknesses, and risk scenarios to identify themes, root causes, and opportunities for improvement.
  • Develop practical recommendations to address identified security and control risks.
  • Assist in developing cybersecurity risk assessments, reporting, metrics, and materials for management and governance forums.
  • Monitor emerging cybersecurity threats, regulatory developments, and industry practices and assess their potential relevance to the organization.
  • Participate in risk assessments of areas including cloud security, application security, identity and access management, cyber defense, vulnerability management, and cyber resilience.
  • Build strong relationships across technical and risk teams and provide thoughtful, constructive challenge when appropriate.
Required Qualifications
  • Bachelor’s degree or equivalent professional experience.
  • 5+ years of relevant experience across Security Engineering, Security Architecture, Application Security, Cyber Defense, or a related technical discipline.
  • Working knowledge of cybersecurity risks, controls, and security principles.
  • Experience assessing technology or security risks and communicating findings and recommendations to stakeholders.
  • Familiarity with one or more cybersecurity or technology control frameworks, such as NIST CSF, NIST 800-53, MITRE ATT&CK, ISO 27001, COBIT, or CIS.
  • Strong written and verbal communication skills, including the ability to explain technical risks to both technical and non-technical audiences.
  • Ability to work collaboratively across technology, security, and risk teams.
  • Authorized to work in the United States.
Preferred Qualifications
  • Experience conducting assessments as part of Information Security, Technology Risk, Risk Management, Internal Audit, Security Architecture, or another technology control function.
  • Relevant technical or professional certification such as CISSP, CISM, CRISC, CISA, GIAC, or FAIR.
  • Familiarity with enterprise risk management concepts and risk assessment methodologies.
  • Experience within a regulated industry, including financial services, is helpful but not required.
Core Competencies
  • Strong analytical and problem-solving skills.
  • Technical depth in one or more security domains.
  • Ability to assess information objectively and provide constructive challenge.
  • Clear and concise written and verbal communication.
  • Strong collaboration and stakeholder-management skills.
  • Ability to manage multiple priorities in a fast-moving environment.
  • Attention to detail while maintaining an understanding of broader risk implications.
  • High integrity, sound judgment, and a commitment to independent risk management.

Salary Range = 160,000-215,000 USD Annual+ Benefits + Bonus

The referenced salary range is based on the Company's good faith belief at the time of posting. Actual compensation may vary based on factors such as geographic location, work experience, market conditions, education/training and skill level.

We offer one of the most comprehensive and generous benefits plans available and offer a range of total rewards that may include merit increases, incentive compensation (exempt roles only), paid holidays, paid time off, medical, dental, vision, short and long term disability benefits, 401(k) +match, life insurance, and various wellness programs, among others. The Company does not provide benefits directly to contingent workers/contractors and interns.

Discover what makes Bloomberg unique - watch our podcast series for an inside look at our culture, values, and the people behind our success.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Risk Manager New York, NY Posted today
Information Security Risk Manager New York, NY Posted today

Bloomberg L.P. • New York (NY), Northern (KY)

Hybrid
USD 160,000 - 215,000
Medical, dental, vision coverage
Short & long-term disability benefits
401(k) + match
+3
Head of Information Security Risk - Chief Risk Office
Head of Information Security Risk - Chief Risk Office

Bloomberg • New York (NY)

On-site
USD 180,000 - 260,000
CRO - Information Security & Risk Oversight Lead
CRO - Information Security & Risk Oversight Lead

Bloomberg • New York (NY)

On-site
USD 140,000 - 180,000
Risk Manager - Engineering - CRO New York, NY Posted yesterday
Risk Manager - Engineering - CRO New York, NY Posted yesterday

Bloomberg L.P. • Northern (KY), New York (NY)

Hybrid
USD 130,000 - 180,000
Benefits package
Information Security Risk Manager: Elevate Controls & Insight
Information Security Risk Manager: Elevate Controls & Insight

Bloomberg • New York (NY)

On-site
USD 160,000 - 215,000
Medical, dental, vision
401(k) match
Life insurance
+1
Head of Cybersecurity & Information Security Oversight (SVP)
Head of Cybersecurity & Information Security Oversight (SVP)

The Security Executive Council • Boston (MA)

On-site
USD 225,000 - 338,000
401K with company match
Comprehensive insurance coverage
Paid time off including vacation and sick leave
Technical Product Manager - Security Data - CTO Office
Technical Product Manager - Security Data - CTO Office

Bloomberg • New York (NY)

On-site
USD 240,000 - 330,000
Chief Information Security Risk Officer
Chief Information Security Risk Officer

Bloomberg • New York (NY)

On-site
USD 180,000 - 260,000
Tech Risk, Risk Practices and Controls Management - Vice President, Dallas
Tech Risk, Risk Practices and Controls Management - Vice President, Dallas

Goldman Sachs Group, Inc. • Dallas (TX), Northern (KY)

Hybrid
USD 180,000 - 250,000
Technology Risk - Control Enablement and Transformation-Dallas-Vice President
Technology Risk - Control Enablement and Transformation-Dallas-Vice President

Goldman Sachs • Dallas (TX)

On-site
USD 150,000 - 190,000