Principal, GRC Cyber Risk Management
Core
Lead the identification, assessment, prioritization, and reporting of cyber risks across the enterprise, driving modernization of risk methodologies and executive reporting.
Role type
Principal, GRC Cyber Risk Management
Builds
Enterprise cyber risk reporting, risk metrics, KRIs, KCIs, and predictive analytics for executive leadership and regulators.
Domain
Financial Services / Cybersecurity Governance, Risk, and Compliance
Deliverable
dashboards & analysis
Required skills
Cyber risk management frameworks (NIST CSF, FAIR, MITRE ATT&CK, ISO 27001), cyber threat intelligence, data analytics, AI-enabled risk processes, executive communication, regulatory compliance
Preferred skills
Master's degree in Information Security or Computer Science, CISSP/CISM/CRISC certifications
Technologies
NIST CSF, FAIR, MITRE ATT&CK, ISO 27001
Responsibilities
Lead identification and assessment of enterprise cyber risks; Drive evolution of data-driven risk decision-making; Conduct cyber risk assessments and maturity reviews aligned to frameworks; Develop forward-looking risk reporting for executives and regulators; Partner with security experts to improve risk reduction outcomes; Enhance risk intelligence via analytics and automation; Translate technical risks into business impact narratives; Evaluate emerging threats including AI capabilities; Contribute to development of risk metrics and predictive analytics.
Seniority
Principal, strategy & mentorship
