Lead Cyber Risk Security Assurance Engineer
*We are unable to sponsor for this permanent Full time role*
*Position is bonus eligible*
Prestigious Financial Institution is currently seeking a Lead Cyber Risk Security Assurance Engineer. Candidate will be responsible for leading the scoping, planning, conducting, and reporting of various Security assessments, including collaboration with other Security teams to assess risk and requirements for new technology onboarding and PoCs, Third Party Security Assessments to support Third Party Risk Management team, assisting with oversight of the Security Observation Risk Tracking process, and special risk assessments as requested by the CSO or DCSO. This position includes supporting Security Assurance team members in the development of these various risk assessments listed above.
Responsibilities:
Developing and enhancing Security Assurance processes. This includes automation enhancements, the advancement of Cyber Risk practices, and updating relevant policies and procedures to reflect these changes.
Scoping, planning, conducting, and reporting Security assessments for internal departments and of third parties and technologies
Collaborate with the Security Engineering & Technology Integration and Threat Intelligence teams to assess risk and set security requirements for new technology onboarding and PoCs
Assist with oversight of the Security Observation Risk Tracking process which includes processing security observations nominated from various sources, assessing risk ratings for observations, communicating observations to risk owners, and managing the observation life cycle
Collaborate with Threat Intelligence to determine MITRE ATT&CK tagging for observations within the Security Observation Risk Tracking process
Participate in Security review and approval of Linux server privilege elevation, Proxy exception, and Firewall exception requests
Participate in Security review and approval of Risk Intake, Risk Action Plan, and Risk Acceptance records managed by the Operational Risk Management & Controls team
Research and recommend new or updated risk assessment methodologies, frameworks, and standards
Assist with other Security Assurance Program efforts including but not limited to tracking of remediation and validation of audit, compliance, and regulatory findings as needed.
Collaborate with automation and AI teams to assess opportunities for incorporating AI into team processes
Documenting process flow enhancements and working with Security Business Operations to develop and enhance Security Assurance processes.
Assist Security Analysts, transferring technical and risk management knowledge
Partnering with IT department to disseminate, train, and provide guidance against the Security requirements
Qualifications:
Analytical skills to successfully analyze, model, and present complex risk assessments
Ability to work independently and effectively with local and remote staff, management, vendors, and consultants while exercising sound judgment
Strong understanding of information technology, risk management concepts, and analytics
Advanced understanding of information related frameworks and standards such as COBIT, NIST 800-53, NIST CSF, ISO etc.
Experience in security risk management principles and practices.
Experience in working with regulatory frameworks and requirements such as, Reg SCI, CFTC 99.18, etc.
Experience working in ServiceNow, Tableau, Archer GRC, Jira, and Confluence
Education and/or Experience:
5 years hands-on Information Security experience, preferably within previous work in Compliance, Audit, Risk Management, or Security.
Bachelor's degree in Computer Science, Management Information Systems, Statistics & Quantitative Modeling, Mathematics a plus or the equivalent combination of education and/or relevant experience.
Certificates or Licenses:
Professional network and/or security certifications are a plus, but not required (ie, GIAC, CISSP, CISA, CISM, CRISC, AWS cloud computing)
Recommended Jobs
IT Technician
Job Type Full-time Description Purpose: To support the IT Manager by providing assistance in maintenance of IT equipment and software. Job Responsib…
Mid-Level Golang AWS Developer
Goland Developers Plano or Dallas TX 6-12 Months+ Looking for Golang Developers with experience in deploying robust and cloud-native solutions on AWS. Should have over 7 vears' o…
Sr Product Manager - Endpoint
The Basics: Our Product Management team is actively seeking a Sr Product Manager for Endpoint Technology and Client Tools to join our passionate, driven and fast-paced team. In this role you …
State and Local Indirect Tax - Property Tax Manager Save for Later Remove job
At PwC, our people in tax services focus on providing advice and guidance to clients on tax planning, compliance, and strategy. These individuals help businesses navigate complex tax regulations an…
Senior AI/ML Engineer (Remote - US-Based)
Join us to Improve Health Equity for 5 Million People! CareMessage is the technology non-profit building the largest patient engagement platform for low-income populations in the United States. Pow…
Executive Recruiter (AFG)
Job ID#: 31186 Executive Recruiter Accounting & Finance Group Direct-Hire/Full-time | Houston, TX Professional Alternatives is growing and looking to add an Executive Recruiter to our …
Construction Estimator
Job Description: Experience: 7 Yrs Interview Type: Phone Interview Employment Type: FULLTIME Experience Level: Experienced (Non-Manager) This candidate will be someone who thrives in precision, …
Data Management Coordinator
Position Summary The Data Quality Analyst plays a crucial role in ensuring the integrity, accuracy, and reliability of data across our OEM organization. Initially, the focus is on validating and c…
Web Developer
Figma is growing our team of passionate people on a mission to make design accessible to all. Born on the Web , Figma helps entire product teams brainstorm , design and build better products — fr…
Accountant
Company Description RRD is a leading global provider of marketing, packaging, print, and supply chain solutions that elevate engagement across the complete customer journey. The company offers t…