6 дней назад
TFSB Information Security Risk Manager (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
TFSB Information Security Risk Manager (Cybersecurity): Building and managing an enterprise-wide cyber risk management framework for a financial services bank with an accent on NIST RMF implementation, security controls, governance, and regulatory compliance. Focus on administering GRC processes, assessing system risk, preparing authorization packages, and reporting enterprise risk indicators to senior leadership.
Location: Plano, Texas, United States. The role requires existing authorization to work in the United States and does not offer employment-based visa or work authorization sponsorship.
Company
Toyota Financial Services supports Toyota and Lexus customers through financial and insurance products within .
What you will do
- Build, document, and maintain cyber risk policies, standards, procedures, and methodologies based on the NIST Risk Management Framework.
- Lead the cyber risk management lifecycle, including system categorization, security control selection, implementation guidance, and effectiveness assessments.
- Manage system authorization processes and prepare risk-based authorization recommendations and packages for senior leadership.
- Maintain the master security control catalog and establish continuous monitoring for acceptable security posture.
- Administer and configure the GRC platform supporting the risk management framework.
- Develop KPIs and KRIs, present the enterprise risk landscape, and coordinate remediation with system owners, IT, and security teams.
Requirements
- At least 7 years of experience in information security, IT audit, or technology risk management, including 3 years in program management or leadership.
- Expertise developing and implementing the NIST Risk Management Framework, including NIST 800-37 and NIST 800-53.
- Strong understanding of banking information security regulations, FDIC and FFIEC Examination Handbooks, FFIEC, GLBA, and SOX.
- Ability to explain complex security risk concepts to executive leadership and support prioritization and decision-making.
- Bachelor’s degree from an accredited institution or equivalent professional experience.
- Must be authorized to work in the United States without current or future Toyota immigration sponsorship.
Nice to have
- CGRC, CRISC, CISSP, or CISM certification.
- Experience building a risk management program from the ground up.
- Experience administering a GRC platform such as ServiceNow GRC or Archer.
- Advanced degree in IT or cybersecurity.
Culture & Benefits
- Team-oriented, flexible, and respectful work environment.
- Professional development programs and tuition reimbursement.
- Comprehensive health care and wellness plans.
- 401(k) plan with company match and annual retirement contribution where applicable.
- Paid holidays, paid time off, tax-advantaged accounts, and family support services.
- Vehicle purchase and lease programs, with relocation assistance where applicable.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
12 дней назад
Senior Manager, GRC Strategy & AI
142 500 - 237 500$
7 дней назад
Senior Cybersecurity & IT Controls Engineer (Cybersecurity)
10 дней назад
Senior Manager, Technology & Cyber Risk Management (Cybersecurity)
122 000 - 209 000$
CrowdStrike
8 дней назад
TPRM Technical Lead (Cybersecurity)
125 000 - 180 000$
13 дней назад
Director, IT Governance, Risk & Compliance (SOX)
6 дней назад
IT Security Manager (Cyber Risk & Audit)
145 600 - 187 200$