Reporting to the Director of Cybersecurity Risk Oversight, the Sr. Cybersecurity Risk Oversight Professional is a 2nd Line of Defense risk management position that provides independent oversight and Risk Management subject matter expertise to 1st Line of Defense Business Units and their corresponding Business Risk Teams.
This position is responsible for Cybersecurity and Information Security Risk Oversight of our client’s technology services line of business, as well as technology and information security risk oversight for areas of the enterprise that manage technology, data and AI/ML systems. As part of this oversight role, experience with cybersecurity domains – including security operations, network and cloud security architecture, identity and access management, and cyber defenses – along with emerging AI security risk and AI governance frameworks. Candidates should have a background and proven, ability to identify material risks, provide credible challenge and assist in developing effective mitigation strategies.
Essential Functions
· Evaluate risk and control identification within key processes and perform gap assessments on control coverage as well as first line of defense identification processes
· Collaborate and independently foster relationships with leaders to gain insights on cybersecurity posture, emerging cyber and AI-related risks and strategic technology initiatives, identifying opportunities to mitigate risk.
· Evaluate and monitor security portfolio, strategic initiatives, including AI adoption and deployments, and new and emerging technologies to ensure alignment with cyber risk appetite and business goals.
· Review cybersecurity processes, risks and controls, and conduct targeted assessments to support effective oversight and compliance with enterprise risk management requirements.
· Provide expert advice on cybersecurity and AI risk management practices, offering practical solutions to mitigate identified risks.
· Analyze and assess cybersecurity and AI-related risks associated with new products or services including third parties.
· Assist with cybersecurity and technology audits and regulatory examinations, ensuring thorough and timely responses to inquiries and findings.
· Escalate and report any significant risk issues and facilitate appropriate corrective actions.
· Perform ongoing monitoring of emerging cyber and AI-related risks and industry and regulatory trends.
Required Qualifications
· Bachelor’s degree in cybersecurity, information systems, computer science, business or related field, or commensurate/relevant degree is required.
· 5+ years industry experience in Cybersecurity Risk, Information Security Risk, Technology Risk or External/Internal Security Audit.
· Practical knowledge of cybersecurity domains such as security operations, cyber defenses, identity and access management, network/cloud security architecture.
· Functional knowledge with AI/ML security risk concepts (e.g., AI governance, data security, adversarial threats).
· Outstanding active listening skills with the ability to synthesize complex information or processes.
· Demonstrated ability to work with internal and external auditors and regulators.
· Ability to think strategically coupled with the ability to independently drive execution to closure.
· Ability to view risk holistically within a dynamic, fast-paced team environment
· In-depth practical knowledge of cybersecurity and technology controls, risk assessments and applicable techniques for implementation of compliance and regulatory requirements.
· Manage workflows and task assignments simultaneously to ensure timely completion of work
· Have an execution-oriented, process efficiency and continuous improvement mindset
· Possessing intellectual curiosity and a passion for seeking to understand
· Proven ability to have, maintain, and establish strong contacts within the industry so as to be aware of current industry issues and practices
Licenses and Certifications such as:
o ISACA: CISA, CRISC, CET, CGEIT, CISM
o ISC2: CISSP, CCSP, SSCP
o Cloud Security Alliance Certs: CCAK
o Cloud Provider-Specific Certifications
Preferred Qualifications
· BS or Masters in Technology or Security related field
· Current and practical knowledge of Technology and/or Information Security activities, challenges, and workflows
· Additional industry certifications such as those listed above
· MBA, Law Degree or other relevant advanced education
· Foundational knowledge of Archer GRC preferred
· Project management, Agile experience preferred
Job Type: Full Time
Job Location: Albany NY Atlanta Georgia Buffalo NY Chicago Illinois Cincinatti Ohio Cleveland Ohio Columbus Ohio Denver Colorado
