Назад
Company hidden
1 день назад

Cybersecurity Governance Manager (Fintech)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Cybersecurity Governance Manager (NIST/GRC): Building and managing a technology and cybersecurity governance framework for on-premise and cloud environments with an accent on regulatory compliance, risk assessment, and control effectiveness. Focus on automating GRC monitoring, leading NYDFS and SOC 2 assessments, and reporting cybersecurity risk metrics to senior management.

Location: Baltimore, MD, United States

Company

hirify.global is a financial services company operating in a regulated industry.

What you will do

  • Establish and maintain a cybersecurity governance framework based on the NIST Cybersecurity Framework.
  • Manage the technology and cybersecurity policy and control program, including drafting, cross-functional review, enforcement, and oversight.
  • Maintain the technology and cybersecurity risk and controls matrix across SOC 2, CIS, PCI, NIST CSF, NIST 800-53, and NYDFS Part 500.
  • Lead annual enterprise technology and cybersecurity risk assessments, NYDFS Part 500 self-assessments, SOC 2 audits, and regulatory examinations.
  • Establish automated GRC monitoring and reporting for technology and cyber risk and control effectiveness.
  • Coordinate with enterprise risk management, internal audit, architects, engineers, and technology operations teams while reporting cybersecurity metrics and recommendations to senior management.

Requirements

  • Bachelor’s degree focused on Cybersecurity, Information Technology, or equivalent experience.
  • 5–7 years of experience managing technology and cybersecurity governance and controls frameworks in financial or other regulated industries.
  • 3–5 years of leadership experience with the ability to influence stakeholders across functions and organizational levels.
  • In-depth knowledge of NIST, SOC 2, CIS, GLBA 501(b), NYDFS, PCI, cybersecurity regulations, and industry standards.
  • Strong communication, presentation, organization, program management, analytical, problem-solving, and research skills.
  • Proficiency with Microsoft Office, including Word, Excel, and PowerPoint.

Nice to have

  • Familiarity with GRC, metrics, and reporting tools such as Archer, Anecdotes, or Power BI.

Culture & Benefits

  • Collaborative environment focused on adding value to business partners.
  • Fast-paced work involving change, innovation, multiple priorities, and strict timelines.
  • Opportunity to influence technology projects and promote consistent cybersecurity standards and controls.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →