Business Information Security Officer-AVP
Core
Provides cyber risk advisory services to strengthen defensive cybersecurity posture through proactive risk management, control oversight, and security-by-design practices.
Role type
Senior IC cyber risk advisor
Builds
Risk-informed decisions and measurable reductions in cyber exposure for technology, infrastructure, application, and business teams
Domain
Financial services cybersecurity
Required skills
enterprise networking concepts, network security technologies, secure cloud, Secure SDLC, SaaS security (Identity, Data Protection, Monitoring, Governance), architecture diagram review, cyber risk assessment, control evaluation, remediation tracking, regulatory framework knowledge (FFIEC, NIST, ISO, SOC)
Preferred skills
experience in regulated financial services, ability to influence without direct authority, audit and regulator support experience
Technologies
cloud platforms, SaaS platforms, network security tools, threat intelligence models
Responsibilities
Assess cyber risks for infrastructure, applications, cloud services, and third-party supply chains; review network designs and architecture artifacts for security risk; provide guidance on risk acceptance and exception handling; partner with engineering teams to embed security-by-design principles; prioritize vulnerability remediation based on risk; lead network security risk assessments and control gap analysis; support internal audits and regulatory reviews; provide advisory support during cyber incidents.
Seniority
AVP, Senior, hands-on IC