Information Technology Cybersecurity

Hybrid in New York, NY, US • Posted 8 hours ago • Updated 8 hours ago
Full Time
No Travel Required
Hybrid
$140,000 - $180,000/yr
Company Branding Image
Fitment

Dice Job Match Score™

🫥 Flibbertigibetting...

Job Details

Skills

  • Amazon Web Services
  • CISM
  • Data Analysis
  • Data Security
  • Cyber Security
  • Cloud Security
  • Artificial Intelligence
  • IT Risk Management
  • IT Risk
  • Machine Learning (ML)
  • Regulatory Compliance
  • Security Awareness
  • Vulnerability Management
  • Security+
  • Investment Management
  • 4 year degree
  • NO THIRD PARTY PLEASE

Summary

 

Professional Experience: 6-10 years related experience

Job Description

Seeking a Vice President of Cybersecurity to join its Information Technology team. This is a broad, hands-on role at the intersection of cybersecurity, infrastructure operations, and business resilience in a fast-moving investment environment. The successful candidate will own the firm''''''''s security program protecting sensitive investment data, proprietary analytics, and confidential investor and counterparty information while contributing meaningfully to day-to-day security operations in close collaboration with the larger team.

Specific job responsibilities include: Cybersecurity Program Ownership

  • Own and mature the firm''''''''s cybersecurity program, conducting continuous gap analysis and driving improvements to the overall security posture across a multi-jurisdictional investment management environment
  • Assess and harden the firm''''''''s infrastructure stack spanning cloud platforms, connectivity with external vendors, and investor portals from a security perspective
  • Coordinate with the firm''''''''s Managed Security Service Provider (MSSP) to ensure comprehensive monitoring across endpoint, cloud, and identity surfaces, including coverage for remote and international office users
  • Serve as first responder for threat detection alerts and security escalations, conducting log analysis and triage across SIEM, EDR, and other security tooling with sensitivity to events involving investment data, trade information, or investor communications
  • Oversee vulnerability management lifecycle: scanning cadence, prioritization, patching coordination, and exception tracking across devices, servers, and third-party connected systems
  • Manage the phishing simulation program, security awareness training, and onboarding training for new hires tailoring content to reflect threats relevant to the financial services sector
  • Evaluate and recommend new security tooling, building a business case for investment, and communicating risk trade-offs to senior leadership

AI Security & Emerging Threats

  • Partner with investment, technology, and operations teams to assess AI and machine learning initiatives including use of large language models, co-pilot tools, and data analytics platforms ensuring appropriate data security, access controls, and governance frameworks are in place
  • Evaluate risks associated with AI tools accessing or processing sensitive investment data, credit models, LP information, or proprietary research, and establish guardrails and usage policies
  • Monitor the evolving threat landscape including financially motivated cybercrime, nation-state activity targeting financial institutions, and supply chain risks and proactively recommend enhancements to the firm''''''''s defenses
  • Contribute to SecDevOps practices in collaboration with the application development and portfolio analytics teams, embedding security into the development of tools and pipelines

Governance, Risk & Compliance

  • Maintain and update the firm''''''''s cybersecurity policy framework in collaboration with Legal & Compliance, ensuring alignment with regulatory cybersecurity rules
  • Coordinate BCP/DR tabletop exercises and failover testing with stakeholders across investment, operations, finance, and legal teams
  • Conduct quarterly internal cybersecurity audits, including access control reviews, privileged access assessments, and third-party connectivity reviews and serve as the primary point of contact for external audits, regulatory examinations, and investor due diligence questionnaires (DDQs) relating to technology and security
  • Support R&D efforts related to security frameworks and contribute to the firm''''''''s ongoing assessment against these benchmarks
  • Maintain accurate, up-to-date documentation of systems, configurations, procedures, and incident response playbooks, ensuring readiness for regulatory review at short notice

Qualifications and Education Requirements

  • Bachelor s degree in information technology, computer science, cybersecurity, or related field
  • 7 10 years of progressive experience in information technology with a meaningful focus on cybersecurity, infrastructure security, or a combined security and operations role
  • Demonstrated experience owning or materially contributing to a security program in a financial services, asset management, or similarly regulated environment
  • Hands-on experience with EDR, SIEM, DLP, vulnerability management tools, and IAM platforms
  • Working knowledge of cybersecurity regulations and a solid grasp of GRC frameworks
  • Understanding of data classification and information barriers relevant to an investment management context, including handling of MNPI and investor confidential information
  • Strong interpersonal and communication skills able to engage credibly with senior investment and business professionals, and to translate technical risk clearly for non-technical audiences
  • Self-directed and highly organized, with the ability to manage competing priorities and operate effectively with minimal oversight in a demanding environment
  • Experience with cloud security (AWS, Azure, or Google Cloud Platform), including securing cloud-hosted financial data and enforcing access governance in hybrid environments
  • Familiarity with investor DDQ processes and the ability to respond competently to LP and auditor questions on technology risk and security controls
  • Exposure to SecDevOps practices and collaboration with internal application development or data engineering teams
  • Relevant certifications such as CISSP, CISM, CISA, CompTIA Security+, or equivalent
  • Ability to step in and support the general help desk when needed
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10112409
  • Position Id: 8915623
  • Posted 8 hours ago

Company Info

About The Astor Group

Established in 1989, The Astor Group is a search firm based in Midtown, New York City. We specialize in placing professionals in Financial Services, Banks, Hedge Funds, and Fortune 500 Companies. We offer search practices for technology professionals at all levels across various industries.

With a rich history of over 20 years, The Astor Group has honed its expertise in the art of recruitment. We understand that finding the right person for the position is more than just finding a qualified professional. We match sharp, skilled, experienced IT experts, representing diverse skills and specialized training, with our client's corporate culture and specific technical needs, creating a perfect fit for our clients and candidates.

About_Company_OneAbout_Company_Two
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

It looks like there aren't any Similar Jobs for this job yet.

Search all similar jobs