About the Role
Seeking a Manager, Expert Cyber Risk Management to lead a team of 5 professionals responsible for enterprise cyber risk, security assurance, governance, and control effectiveness.
This is a highly technical leadership role with a strong emphasis on security assurance, audit, GRC, risk assessments, security controls, and governance. The manager will partner with security, infrastructure, application, data, audit, legal, compliance, and executive leadership teams to identify and mitigate enterprise cybersecurity risks.
Key Responsibilities
- Manage and mentor a team of 5 cyber risk professionals while providing technical and strategic leadership.
- Lead enterprise security assurance, risk assessments, audit readiness, GRC, and control effectiveness initiatives.
- Develop and maintain internal cybersecurity frameworks, standards, policies, processes, and documentation.
- Assess security controls and identify gaps, risks, remediation requirements, and opportunities for improvement.
- Establish and track KPIs, metrics, remediation timelines, control effectiveness, and risk trends.
- Partner with technical and business leaders to ensure security controls are embedded throughout technology lifecycles.
- Advise senior leadership and governance bodies on cybersecurity risks, control maturity, and remediation strategies.
- Collaborate with audit, legal, compliance, and third-party risk teams to meet regulatory and contractual requirements.
- Leverage AI/ML and automation to improve third-party risk management, security event analytics, assurance processes, and risk reporting.
- Evaluate enterprise security capabilities including authentication/authorization, PKI, DLP, third-party risk, security analytics, and cloud security.
- Provide thought leadership on emerging threats, technologies, and cybersecurity risk management practices.
Frameworks & Regulatory Standards
Experience working with security and compliance frameworks such as:
NIST 800-53, NIST 800-series, CMMC, NERC CIP, CIS, HIPAA, SOC, FedRAMP, ISO, OCC, and related regulatory/industry standards.
Technical Qualifications
- Strong background in cyber risk management, security assurance, GRC, security architecture, or cybersecurity consulting.
- Deep understanding of security controls, risk assessments, audit, governance, and control effectiveness.
- Experience with Azure Cloud and preferably Oracle Cloud/OCI.
- Experience applying AI/ML or automation to cybersecurity, risk management, analytics, or third-party risk processes.
- Strong understanding of enterprise cybersecurity technologies such as IAM/authentication, PKI, DLP, SIEM/security event analytics, and third-party risk management.
- Experience developing security frameworks, policies, standards, metrics, and governance processes.
- Strong analytical, problem-solving, communication, and executive presentation skills.
- Ability to translate complex technical risks into clear business and strategic recommendations.