Principal, Cybersecurity Risk

Fidelity Investments

Durham (NC)

On-site

USD 120,000 - 180,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Fidelity Investments seeks a Principal-level cyber risk professional to lead the creation of cyber risk analyses for the ECS program. You will participate in risk modeling, advise on exceptions and audit findings, and quantify risk to present to senior leadership.

You will gather data from multiple sources, integrate it into risk tools, and communicate insights across business lines in a fast-paced environment. Onsite with Fidelity’s phased regional rollout.

Qualifications

  • Minimum 3-5 years of risk experience quantifying cyber risk and presenting data to senior leaders.
  • Experience in cybersecurity risk management, assessment frameworks, and metrics reporting.
  • Experience managing end-to-end projects, from data collection to tracking, maintenance, and closure, with data integrated into risk analysis tools.
  • Use and understanding of governance, risk, and compliance tools.
  • Advanced understanding of NIST 800-53, CRI, and FAIR.
  • CRISC, CISSP, or CISM certifications are preferred.
  • Strong communication and presentation skills to senior leaders.
  • Ability to quantify work and risk position improvements through metrics.
  • Critical thinking to vet answers and identify gaps.
  • Ability to influence across business lines to mitigate cyber risk.
  • Understanding risks in cloud security, access controls, encryption, vendor security, data exfiltration, app security, perimeter security, customer protection, privileged access, DoS, unpatched vulnerabilities, and end-of-life software.
  • Operate in a fast-paced environment and integrate new cybersecurity data into risk models.
  • Investigator mindset to communicate actionable risk to business and technology groups.
  • Determining appropriate controls for cybersecurity risks.
  • Working with asset inventory and asset management.
  • Evaluate sources and trends to compare findings with ECS policies and identify gaps.
  • Draft policy enhancements to close gaps and sustain progress.

Responsibilities

  • Lead the creation of cyber risk analyses for ECS product areas.
  • Participate in risk/threat modeling sessions to prioritize top risks.
  • Advise on exceptions and audit finding risk levels to drive down exceptions and rate audit findings.
  • Quantify cyber risk and present analyses to technical and executive audiences for informed decision-making.
  • Integrate data from multiple sources and SMEs into risk analysis tools and communicate progress across teams.
  • Work across business lines to influence change and mitigate cyber risk.

Skills

Cyber risk management
Executive-level reporting
Cross-functional collaboration
Risk data analysis
Project management
GRC tools

Education

CRISC/CISSP/CISM certifications preferred

Tools

GRC tools

Job description

Job Description

Note: Fidelity will not provide immigration sponsorship for this position

The Role

The Enterprise Cybersecurity Risk (ECS Cyber Risk) team is seeking an experienced Principal-level risk professional to lead in the creation of cyber risk analysis pertaining to ECS. The candidate will understand current and emerging cybersecurity risks and determine key risk scenarios for the ECS Product Areas. The candidate will participate in risk / threat modeling sessions to prioritize top risks. The candidate will advise on both exceptions and audit finding risk levels to drive down the number of exceptions and accurately risk rate audit findings. The candidate will quantify cyber risk and present analyses at the technical and executive level that will allow senior management to make informed decisions based on resulting risk data.

The Expertise And Skills You Bring
  • Minimum 3-5 years of risk experience quantifying cyber risk scenarios and presenting data in a meaningful and insightful way to senior leaders.
  • Demonstrated experience in cybersecurity risk management, assessment frameworks, and metrics reporting.
  • Experience managing projects end-to-end, from initial stages of acquiring data from multiple sources and subject matter experts to the tracking, maintenance, and closure of a project, with proven ability to integrate data into risk analysis tools and communicate progress effectively across multiple lines and levels.
  • Use and understanding of governance, risk, and compliance tools.
  • Advanced understanding of NIST 800-53 Cybersecurity Framework, Cybersecurity Risk Institute (CRI), and FAIR
  • CRISC, CISSP, or CISM certifications are preferred.
  • You have effective communication and excellent presentation skills to senior leaders.
  • You can deep dive into metrics that will both (1) quantify the work being done and (2) quantify how cyber risk position has improved.
  • Critical thinking skills to ask detailed questions and fully vet answers to uncover discrepancies and gaps others may not have found is a must.
  • You can work across business lines to influence change and help mitigate cyber risk.
  • You have an intermediate understanding of risks pertaining to the following: cloud security, access controls, encryption, vendor security, data exfiltration, application security, perimeter security, customer protection, privileged access, denial of service, unpatched vulnerabilities, and end of life software.
  • You operate in a fast-paced environment and can complete analyses quickly and accurately integrating new cybersecurity data into risk models as it emerges.
  • You bring an investigator mindset to deep dive into metrics to understand and communicate actionable risk to business and technology groups.
  • Determining the appropriate controls for cybersecurity risks
  • Working with asset inventory and asset management
  • Evaluating multiple sources, reports, industry trends to compare risk related findings to existing ECS policies and uncover gaps and opportunities for process improvement.
  • Determining what, who, and where changes are warranted to close gaps, working with appropriate contacts to draft policy enhancement ensuring continued progress.
The Team

ECS Cyber Risk provides cybersecurity risk analyses pertaining to existing and emerging risk scenarios and communicates these risks to appropriate ECS technical teams and senior leadership. This team focuses on identifying, measuring, prioritizing, and reporting on cyber risk scenarios and will work both independently and across business units and technology teams to assist senior management with informed decisions and directions in strategy to either maintain the course or if needed, change direction.
Fidelity’s Onsite Working Model
Fidelity is transitioning to a full-time onsite working model through a phased rollout across regions and roles. Currently, some roles and locations require 100% onsite presence, while others require less. Onsite expectations are likely to evolve as the rollout continues. This transition does not apply to fully remote roles.

Certifications

Category:
Information Technology

Please be advised that Fidelity’s business is governed by the provisions of the Securities Exchange Act of 1934, the Investment Advisers Act of 1940, the Investment Company Act of 1940, ERISA, numerous state laws governing securities, investment and retirement-related financial activities and the rules and regulations of numerous self-regulatory organizations, including FINRA, among others. Those laws and regulations may restrict Fidelity from hiring and/or associating with individuals with certain Criminal Histories.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Cyber Risk Analyst & Quantification Leader
Principal Cyber Risk Analyst & Quantification Leader

Fidelity Investments • Durham (NC)

On-site
USD 120,000 - 180,000
Principal Cybersecurity Analyst
Principal Cybersecurity Analyst

Soteria Reinsurance Ltd. • Durham (NC)

On-site
USD 120,000 - 180,000
Onsite Working Model
Principal Technology Risk Analyst
Principal Technology Risk Analyst

Fidelity • Westlake (TX)

On-site
USD 140,000 - 190,000
Director, Enterprise Technology Standards & Controls
Director, Enterprise Technology Standards & Controls

Fidelity Investments Inc. • Westlake (TX)

On-site
USD 180,000 - 240,000
Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

Soteria Reinsurance Ltd. • Town of Texas (WI)

On-site
USD 95,000 - 135,000
Principal Technology Risk Analyst - Program & Regulatory Assurance
Principal Technology Risk Analyst - Program & Regulatory Assurance

Fidelity • Town of Texas (WI)

On-site
USD 110,000 - 160,000
Senior Digital Assets Systems Engineer
Senior Digital Assets Systems Engineer

Fidelity Investments • Roanoke (TX)

On-site
USD 140,000 - 230,000
Principal Technology Risk Analyst - Program & Regulatory Assurance
Principal Technology Risk Analyst - Program & Regulatory Assurance

Fidelity Investments • Merrimack (NH)

On-site
USD 110,000 - 170,000
Principal Full Stack Engineer
Principal Full Stack Engineer

Worky • Durham (NC)

On-site
USD 120,000 - 180,000
Principal Systems Engineer
Principal Systems Engineer

Soteria Reinsurance Ltd. • Durham (NC)

On-site
USD 140,000 - 200,000