Назад
Company hidden
6 дней назад

TFSB Information Security Risk Manager (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
TFSB Information Security Risk Manager (Cybersecurity): Building and managing an enterprise-wide cyber risk management framework for a financial services bank with an accent on NIST RMF implementation, security controls, governance, and regulatory compliance. Focus on administering GRC processes, assessing system risk, preparing authorization packages, and reporting enterprise risk indicators to senior leadership.

Location: Plano, Texas, United States. The role requires existing authorization to work in the United States and does not offer employment-based visa or work authorization sponsorship.

Company

Toyota Financial Services supports Toyota and Lexus customers through financial and insurance products within hirify.global.

What you will do

  • Build, document, and maintain cyber risk policies, standards, procedures, and methodologies based on the NIST Risk Management Framework.
  • Lead the cyber risk management lifecycle, including system categorization, security control selection, implementation guidance, and effectiveness assessments.
  • Manage system authorization processes and prepare risk-based authorization recommendations and packages for senior leadership.
  • Maintain the master security control catalog and establish continuous monitoring for acceptable security posture.
  • Administer and configure the GRC platform supporting the risk management framework.
  • Develop KPIs and KRIs, present the enterprise risk landscape, and coordinate remediation with system owners, IT, and security teams.

Requirements

  • At least 7 years of experience in information security, IT audit, or technology risk management, including 3 years in program management or leadership.
  • Expertise developing and implementing the NIST Risk Management Framework, including NIST 800-37 and NIST 800-53.
  • Strong understanding of banking information security regulations, FDIC and FFIEC Examination Handbooks, FFIEC, GLBA, and SOX.
  • Ability to explain complex security risk concepts to executive leadership and support prioritization and decision-making.
  • Bachelor’s degree from an accredited institution or equivalent professional experience.
  • Must be authorized to work in the United States without current or future Toyota immigration sponsorship.

Nice to have

  • CGRC, CRISC, CISSP, or CISM certification.
  • Experience building a risk management program from the ground up.
  • Experience administering a GRC platform such as ServiceNow GRC or Archer.
  • Advanced degree in IT or cybersecurity.

Culture & Benefits

  • Team-oriented, flexible, and respectful work environment.
  • Professional development programs and tuition reimbursement.
  • Comprehensive health care and wellness plans.
  • 401(k) plan with company match and annual retirement contribution where applicable.
  • Paid holidays, paid time off, tax-advantaged accounts, and family support services.
  • Vehicle purchase and lease programs, with relocation assistance where applicable.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →