Cyber Security & Technology Risk Manager

Early Warning ServicesNew York City, NY
$104,000 - $156,000Hybrid

About The Position

At Early Warning, we’ve powered and protected the U.S. financial system for over thirty years with cutting-edge solutions like Zelle®, Paze℠, and so much more. As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses. Positions located in Scottsdale, San Francisco, Chicago, or New York follow a hybrid work model to allow for a more collaborative working environment. Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment Visa sponsorship. Overall Purpose The Manager, Cyber & Technology Exam Management, will support the Cybersecurity and Technology Risk Oversight Center of Excellence (CTRO-COE) Program within the Second Line of Defense (2LOD). This role is responsible for facilitating regulatory exams, audits, and other assessments, including independent review and challenge of the first line, as well as leading targeted assessments across technical domains.

Requirements

  • Education and/or experience typically obtained through completion of a Bachelor’s degree or equivalent.
  • Minimum of 7+ years of risk management experience, preferably in financial services or other highly regulated industries.
  • Familiarity with frameworks, regulations, and standards, including but not limited to: Cyber Risk Institute Profile, ISO Standards, PCI DSS, NIST 800-53a, SIG, Federal Financial Examination Council (FFIEC) handbooks, Service Organization Controls in accordance with SSAE No.18, GLBA, NYDFS, and FCRA.
  • Required certification in one of CISA, CISSP, CISM, CCSP, CRISC, CGEIT, GSNA, GCIH, or equivalent or ability to sit for one of the certifications within the first 12 months of hire.
  • Strong understanding of operational risk programs (e.g. RCSA, Risk Events, Issue Management, KRIs, etc.).
  • Exceptional communication skills with ability to synthesize and present complex risk issues clearly and persuasively.
  • Creative problem solver who also demonstrates strong attention to detail and efficiency.
  • Ability to drive change in a dynamic business environment.
  • Strong relationship building skills.
  • Excellent organizational, analytical and project management skills.
  • Background and drug screen.

Nice To Haves

  • Multiple certifications in any of the following: CISA, CISSP, CISM, CCSP, CRISC, CGEIT, GSNA, GCIH, or equivalent.
  • Experience with security-related technologies including Identity and Access Management tools, single-sign-on technologies, and technology systems.
  • Cybersecurity and technology consulting or advisory background at a top firm (Deloitte, PwC, Accenture, or equivalent).
  • Additional related education and/or experience preferred.

Responsibilities

  • Center of Excellence Operations
  • Unify second-line oversight across cybersecurity and technology risk by executing a center-of-excellence operating model in the context of exam, audit, and assessment management.
  • Work with other risk domain owners to support first-line’s understanding of risk/control requirements and to provide integrated risk management oversight on cross-risk assessments.
  • Develop and drive periodic management reporting regarding cybersecurity and technology risk management exams, audits, and assessments.
  • Regulatory Exam Facilitation & Oversight
  • Drive consistency and defensibility in regulatory exam readiness and response through centralized oversight and quality assurance.
  • Lead the distribution, collection, and review of cybersecurity and technology-related examination, audit, and assessment requests.
  • Execute quality control review during cybersecurity and technology-related examinations, including developing management responses and remediation plans for regulatory findings.
  • Second Line Targeted Assessments
  • Conduct targeted assessments across technical domains including but not limited to identity and access management, cryptography, data security, DevSecOps, and IT asset management.
  • Advisory & Partnership
  • Serve as a trusted advisor to first-line business and functional leaders, balancing strong risk oversight with enabling business objectives.
  • Collaborate with Enterprise Risk, Operational Risk, Enterprise Compliance, Technology & Security Risk, and Legal to ensure coordinated risk management practices.
  • Provide timely and actionable feedback to strengthen first-line risk ownership and accountability.

Benefits

  • Healthcare Coverage – Competitive medical (PPO/HDHP), dental, and vision plans as well as company contributions to your Health Savings Account (HSA) or pre-tax savings through flexible spending accounts (FSA) for commuting, health & dependent care expenses.
  • 401(k) Retirement Plan – Featuring a 100% Company Safe Harbor Match on your first 6% deferral immediately upon eligibility.
  • Paid Time Off – Flexible Time Off for Exempt (salaried) employees, as well as generous PTO for Non-Exempt (hourly) employees, plus 11 paid company holidays and a paid volunteer day.
  • 12 weeks of Paid Parental Leave
  • Maven Family Planning – provides support through your Parenting journey including egg freezing, fertility, adoption, surrogacy, pregnancy, postpartum, early pediatrics, and returning to work.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service