1 день назад
Information Technology Enterprise Risk Manager (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Information Technology Enterprise Risk Manager (Cybersecurity): Supporting and overseeing Northwest's operational risk framework for information technology, information security, and data with an accent on RCSA, control testing, regulatory assessments, and remediation governance. Focus on independently challenging technology risk practices, validating control effectiveness, measuring residual risk, and analyzing IT-related losses and disruptions.
Location: Pittsburgh, Pennsylvania, United States; onsite role
Company
is a financial institution with an enterprise risk management organization supporting technology, information security, data, and regulatory risk oversight.
What you will do
- Oversee technology-related Risk and Control Self-Assessments and challenge RCSA conclusions and monitoring routines.
- Independently assess risks, identify root causes of residual operational risk, and drive corrective actions.
- Validate first-line control testing and independently test IT, information security, and data controls.
- Partner with IT, information security, and data teams to mature risk assessments, document controls, identify gaps, and develop action plans.
- Support GLBA, authentication and access, PCI DSS, and HIPAA assessments, including challenge of methodologies and results.
- Monitor issue remediation, technology exceptions, resilience testing, vulnerability management, technology failures, policies, standards, and risk metrics.
Requirements
- Bachelor's degree in Management Information Systems, Cybersecurity, or Business Administration.
- 8–12 years of cybersecurity or information technology experience.
- 6–8 years of prior financial institution experience.
- Deep knowledge of information technology, information security, data principles, risk management methodologies, frameworks, and RCSA execution.
- Knowledge of NIST CSF, GLBA, PCI DSS, and HIPAA compliance requirements.
- Experience with vulnerability scanning and penetration testing tools, plus strong analytical, problem-solving, communication, and reporting skills.
Nice to have
- ITIL certification.
- Certified Information Systems Auditor, CISM, CRISC, or CISSP certification.
Culture & Benefits
- Work within the Risk Management organization and collaborate with IT, information security, data, and first-line business teams.
- Support compliance with corporate policies and Federal and State regulations.
- Use Microsoft Office and department-specific applications to improve efficiency.
- Work as part of a team and with on-site equipment.
- Northwest is an equal opportunity employer committed to an inclusive work environment.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
2 часа назад
IT Security Manager - Third-Party IT Risk Manager
118 300 - 207 400$
12 часов назад
IT Audit, Cybersecurity & Risk Manager (HITRUST)
123 840 - 234 770$
1 день назад
Staff Engineer II - Cyber
5 дней назад
Sr. Staff Risk Management Analyst (Cybersecurity)
17 часов назад
Senior Associate, Technology Compliance and Emerging Risk Consulting (Cybersecurity)
77 700 - 146 900$
1 день назад
Senior Information Security Analyst (Cybersecurity)
94 400 - 129 800$