Senior Manager, Information Security Risk
Core
Senior risk advisor providing independent oversight and effective challenge of cybersecurity and related technology risks for a bank's second line of defense.
Role type
Senior Manager, Information Security Risk (Second Line of Defense)
Builds
Independent risk oversight frameworks, strategic risk input, and governance recommendations for senior leadership.
Domain
Banking / Financial Services / Cybersecurity Risk Management
Deliverable
dashboards & analysis
Required skills
Cybersecurity risk management, Governance frameworks, Regulatory compliance, Risk assessment, Strategic advisory, Independent challenge, Cross-functional collaboration, Data-informed analysis
Preferred skills
Technical expertise in security operations, vulnerability management, cloud security, or identity and access management, Experience with regulatory examinations, Knowledge of NIST/ISO/FFIEC frameworks
Technologies
NIST, ISO, FFIEC, Cloud platforms, Security operations tools
Responsibilities
Provide independent oversight and credible challenge on cybersecurity risks and controls; Develop and communicate the cybersecurity risk profile; Evaluate governance frameworks and recommend enhancements; Lead risk-based oversight activities including thematic reviews; Translate complex technical matters into decision-useful reporting for senior management and regulators; Represent the second line during regulatory examinations and audits.
Seniority
Senior Manager, hands-on IC with strategic advisory scope