Назад
Company hidden
7 часов назад

Principal Engineer I, Cyber - IT Security Governance (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Principal Engineer I, Cyber - IT Security Governance (Cybersecurity): Leading cybersecurity governance, risk management, control design, policy management, and maturity initiatives across technology, data, and AI solutions with an accent on CRI Profile assessments, RCSAs, regulatory alignment, and automated control monitoring. Focus on designing defensible governance frameworks, integrating AI and automation into risk reporting, and building executive-ready dashboards, evidence packages, and remediation roadmaps.

Location: CityScape, Phoenix, AZ, United States

Company

hirify.global is a nationwide financial services organization and a wholly owned subsidiary of Western Alliance Bancorporation, operating through multiple banking brands.

What you will do

  • Lead cybersecurity governance initiatives covering risk identification, control design, policy management, and maturity improvement.
  • Own cyber risk management activities, including control effectiveness guidance, risk treatment, residual risk decisions, and RCSAs.
  • Manage CRI Profile assessments, maturity scoring, evidence standards, remediation tracking, and traceability across risks, controls, and issues.
  • Develop and maintain cybersecurity policies, standards, procedures, risk statements, control descriptions, and audit-ready narratives aligned with GLBA, FFIEC, and NIST.
  • Support internal audits, regulatory examinations, credible challenge, control performance reporting, and executive risk briefings.
  • Develop engineering-enabled automation, dashboards, metrics, and AI-assisted workflows for risk assessments, control testing, evidence collection, and reporting.

Requirements

  • 8+ years of experience in cybersecurity, information security governance, IT risk, or enterprise risk management.
  • Bachelor’s degree in information systems, computer science, cybersecurity, risk management, or a related field.
  • Advanced to expert experience with NIST CSF, CRI Profile, FFIEC, ISO 27001 principles, RCSAs, control design, residual risk assessment, and policy lifecycle management.
  • Experience supporting regulatory and audit engagements in a financial services environment.
  • Ability to translate complex technical and regulatory concepts into clear, defensible documentation and manage cross-functional initiatives.
  • Expert verbal and written communication skills.

Nice to have

  • Master’s degree or MBA in a related field.
  • Experience governing or applying AI/ML, automation, or advanced analytics in cybersecurity, risk, or compliance.
  • Understanding of data architectures, data flows, system integrations, AI regulation, model risk, and data usage in financial services.
  • Working knowledge of Python, PowerShell, or automation workflows.
  • Certifications such as CISA, CRISC, CISSP, CISM, CGEIT, or ITIL.

Culture & Benefits

  • Medical and dental insurance.
  • Paid time off and a 401(k) matching program.
  • Ownership stake in the company.
  • Tuition assistance, wellness support, and an employee volunteer program.
  • Opportunities to develop business and financial services knowledge.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →