The Information Security Risk Oversight Professional is a senior individual contributor within the Second Line of Defense (2LoD), reporting to the Director of Cybersecurity Risk Oversight. The role provides independent risk oversight and credible challenge across the enterprise Information Security program, including governance, risk assessments, controls, security architecture and practices, metrics, and issue management. The ideal candidate combines strong technical knowledge with critical thinking, professional skepticism, and sound judgment. This person must be able to assess information independently, distinguish fact from opinion, identify weaknesses in existing approaches, and develop a clear point of view supported by evidence. Success requires more than restating first line conclusions. The role is expected to test assumptions, evaluate whether practices are effective and efficient, and recommend stronger approaches when current methods do not reflect sound risk management or industry best practice. The successful candidate will have more than eight years of relevant experience in information security, technology risk, audit, engineering, architecture, or risk management. They must be comfortable moving across security domains, learning unfamiliar topics quickly, and translating technical concerns into clear, defensible risk insights for senior leaders.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior