Senior Cybersecurity Governance Specialist
Western & Southern Financial Group
Overview Leads the team in providing strategic security leadership and assurance to business and IT teams for major corporate initiatives and information security projects. Develops the strategy in how Western & Southern Financial Group (W&SFG) performs risk assessments, security assessments and policy reviews of WSFG systems and third-party vendors to identify areas of noncompliance with established information security standards and regulations. Manages the recommendations and coaches the team on mitigation strategies and countermeasures. Provides guidance to IT stakeholders in the evaluation, design or implementation of secure computing environments including vulnerability management. Works with Cybersecurity Risk Management team in driving improvements in the information security policy framework. Manages the development, review and monitoring of information security policies and procedures, and develops and communicates improvements. Identifies and defines overall security requirements for the proper operation and design of business and IT applications to ensure the protection of W&SFG systems and data. Leads the development of the organization's information security awareness program. Escalates when needed and updates Director on a regular basis. Responsibilities What you will do; Consults and/or executes third-party vendor due diligence security reviews to ensure compliance with information security policy, security procedures and regulatory requirements. Identifies and reports deficiencies or risks to the appropriate stakeholders. Follows up with business teams and third parties to escalatie issues when necessary. Plans and executes security assessments and penetration testing. Leads effort to address identified IT audit findings and cybersecurity risks with corrective action plans. Develops the strategy and drives process/program improvements with IT leadership and compliance teams. Conducts ongoing monitoring of the first-party security posture and performance. Acts as a liaison with Internal Audit on IT audits. Works with stakeholders to plan, develop and deploy a comprehensive vulnerability management program to govern cybersecurity risk to the enterprise. Builds effective relationships with stakeholders who own and support applications, IT infrastructure and operations to review exposure to threats and drive risk reduction measures. Establishes and tracks performance metrics and provides regular updates to IT leadership on the status of the vulnerability management program. Leads efforts with project teams to ensure PMLC/SDLC tollgates are being met for security and that the appropriate security artifacts are being maintained. Plans and develops strategy to ensure security is incorporated into the PMLC/SDLC. Makes certain it assesses the protection of information and information systems from unauthorized access, use, disclosure, disruption, modification or destruction in order to provide confidentiality, integrity and availability. Develops key performance indicators to measure overall effectiveness and reduction of risk. Conducts in-depth research to understand industry best practices, emerging trends and the latest open source methods. Leads in developing practices and standards that inform design and deliver high-quality solutions that will help address current security challenges and enable new ways of delivering value to the Enterprise. Provides leadership to IT and the business with minimal supervision serving as a technical security consultant. Acts as a key contributor to solve complex business problems and deliver solutions that help avoid risks to corporate network and information assets. Ensures the appropriate level of controls are applied based on industry standards, best practices and cybersecurity regulations by developing repeatable processes to identify, evaluate, and measure IT security risk. Plans and delivers training and/or mentoring advice to team members and other IT groups on security topics, risk avoidance, and security best practices. Plans and manages the information security policy lifecycle, including policy creation, policy maintenance, policy exception, and policy change requests. Drives improvement in the overall security policy framework. Leads the effort in working with the business and IT management to ensure that the security policy framework and internal controls are being appropriate followed. Conducts risk assessments based on policy and control evaluations. Is responsible for the development, review, implementation and maintenance of the organization's information security awareness program. Leads efforts and collaborates with HR and Corporate Communication teams to deliver security training and security awareness to associates and consultants. Develops and executes security training and awareness strategy. Helps manage the remediation of audit and security review findings and recommendations. Performs other duties as assigned. Complies with all policies and standards. Qualifications Bachelor's Degree In computer science, computer engineering, IT or a related technical field, or commensurate selection criteria experience. Demonstrated extensive experience in the areas of information security governance and third-party risk management. Proven ability to influence and drive risk reduction measures within IT and across reporting structures. Demonstrated understanding of the current security threats, techniques, vulnerabilities, response and mitigation strategies used in cybersecurity. Proven extensive experience working with IT risk and compliance frameworks such as NIST (preferred), ISO, COBIT, COSO, COBIT, etc. Demonstrated extensive experience working with best practices and industry cybersecurity regulations including NY DFS, HIPAA, and PCI. Demonstrated experience with information security, security awareness, and risk assessment and mitigation concepts, methodologies, and processes. Demonstrated experience in completing assigned tasks accurately and on a timely basis. Proven ability to identify and assess the severity and potential impact of risks. Proven inherent passion for information security and service excellence. Demonstrated ability to identify project risks and gaps, developing creative and workable solutions to complex problems and policy issues. Proven strong team player - collaborates well with others to solve problems and actively incorporate input from various sources. Demonstrated strong analytical and problem-solving skills with the ability to grasp new concepts and apply them; effectively evaluates information/data to make decisions; anticipates obstacles and develops plans to resolve. Proven excellent verbal and written communication skills with ability to convey information to internal and external customers in a clear, focused and concise manner. Demonstrated calm and professional demeanor when handling demanding situations. Proven ability to work with a team and multiple stakeholders to provide direction and oversight. Demonstrated self-starter with strong internal motivation. Proven ability to work under multiple deadlines and with minimal supervision. Basic computer, network, and system knowledge and skills with a thorough understanding of security controls. Strong proficiency in the use of Microsoft Office, particularly Word, Excel and PowerPoint. Certified Information Systems Security Professional (CISSP), any GIAC certification or ISACA certifications-preferred Work Setting/Position Demands: Works in an office setting and remains in a stationary position for long periods of time while working at a desk, on a computer or with other standard office equipment, or while in meetings. Requires the ability to verbally communicate and exchange accurate information to customers and associates on a regular basis. Requires visual acuity to read and interpret a variety of correspondence, procedures, reports and forms via paper and electronic documents, visual inspection involving small defects; small parts, and/or operation of machinery (including inspection); using measurement devices continuously. Visual acuity is required to determine accuracy, neatness, and thoroughness of work assigned. Requires the ability to prepare written correspondence, reports and forms using prescribed formats and conforming to rules of punctuation, grammar, diction, and style on a regular basis. Requires the ability to apply principles of logical thinking to define problems, collect data, establish facts, and draw valid conclusions Performs substantial movement of wrists, hands, and fingers for continuous computer work. Extended hours required during peak workloads or special projects/events. Travel Requirements: Occasional travel may be required. #J-18808-Ljbffr Western & Southern Financial Group
$101.4k - $152.2k
...Northrop Grumman in Melbourne, FL seeks a Senior Principal Subcontract Specialist to manage procurement and supplier contracts. This role requires expertise in subcontracts and purchasing with a clear path for career growth. Candidates must possess a Bachelor’s degree...Senior- Job Title: Senior Specialist, Contracts Job Code: 36463 Job Location: Cincinnati, OH Job Schedule: 4/10 - Employees work 10 hour days, 4 days... ...FAR and DFARS regularly to ensure contract compliance with government regulations. Evaluates contract performance to determine...SeniorFull timeContract workWork at office
- ...Anywhere Real Estate is seeking a senior Advisory Title Officer in Cincinnati, Ohio, responsible for examining and resolving complex title issues in residential and commercial transactions. This role provides authoritative guidance to internal teams, escrow officers,...Senior
- ...R&K Enterprise Solutions is hiring a TSA Senior Certified OSH Specialist for telework in the Northeast Region, requiring travel to major airports. The role focuses on compliance and safety inspections, with at least two years of Occupational Health and Safety experience...SeniorPermanent employmentFull timeRemote work
- ...A leading insurance provider is seeking a Senior Production Underwriting Specialist to manage risk selection and pricing within the Excess Liability Division. The ideal candidate will have over 10 years of casualty underwriting experience, with at least 3 years specifically...Senior
- ...A prominent technology firm in Cincinnati seeks a Senior Specialist in Configuration Management with extensive experience in managing technical data packages for Electro-Mechanical products. Candidates should hold a Bachelor's degree and have at least 4 years of experience...Senior
- ...wide variety of more difficult to place manufacturers and processors.Our Excess Liability Division is looking for a Senior Production Underwriting Specialist to join their team. This individual will work out of the office in Marietta, GA or Cincinnati, OH depending on the...SeniorFull timePart timeWork at officeNight shift
$79k - $127.65k
...Johnson & Johnson is currently recruiting for a Senior Health Authority Reporting Specialist! This position can be located at any US J&A location. This job description covers the purpose, responsibilities, skill sets, and associated training & education required for the...SeniorApprenticeshipLocal areaImmediate start- ...Syneos Health/ inVentiv Health Commercial LLC is seeking a Senior Project Specialist dedicated to Real World Evidence. This role involves overseeing operational support within RWE and Late Phase research settings to ensure accurate project coordination. Ideal candidates...SeniorRemote workFlexible hours
$81.4k - $122k
...an opening for a Principal Subcontract Specialist to join our team of qualified, diverse individuals... ...Supply Chain, Project Management, Government Acquisitions or similar Working level... ...conducting written and oral presentations to senior leadership Working knowledge of Earned...SeniorContract workFor subcontractorRelocation packageShift work- ...cyber domains in the interest of national security. Job Title Senior Specialist, Contracts Job Code: 32598 Job Location: Cincinnati, OH Job... ...FAR and DFARS regularly to ensure contract compliance with government regulations. Evaluates contract performance to determine necessity...SeniorContract workWork at officeLocal area
- ## Senior Specialist, Logistics AdministrationApplylocations: Midwest City, Oklahomatime type: Full timeposted on: Posted Yesterdayjob requisition... ..., operations, science, program management, mission IT and cybersecurity solutions.* Collaborative Environment: Be part of a dynamic...Senior
- ...Job Title: Senior Specialist, Configuration Management Job Code: 35617 Job Location: Cincinnati, OH Job Schedule: 4/10: Employees work 10... ...accept a conditional offer of employment may be subject to government security investigation(s) and must meet eligibility requirements...SeniorContract workLocal area
$61.4k - $78.29k
...As a Senior Project Management Specialist at Cincinnati Children’s Hospital Medical Center, you will play a critical role in leading complex, data-driven initiatives that advance clinical, operational, and research outcomes. In this role, you will determine resource and...SeniorFull timeRemote workShift work- ...Role description Job Description Developer Senior Developer Data Engineer Databricks on GCP Service Type Development Services... ...control and promote code across environments DevUATProd Security Governance Implement data governance using Databricks access...Senior
$161k
...OPEN JOB: Senior Specialist, FPGA Engineer LOCATION: Cincinnati, Ohio ***Relocation Assistance Available BASE SALARY: $142,000 to $161,000 JOB SCHEDULE: 4/10 - Employees work 10 hour days, 4 days per week. INDUSTRY: Aerospace / Aviation...SeniorRelocation package10 hours per week- ...A leading insurance company is seeking a Senior Azure Cyber Security Engineer to enhance their security posture. The role involves... ...documentation. Candidates should have over 5 years of experience in cybersecurity engineering and expertise in Microsoft Azure. This position...Senior
- ...A leading insurance company is looking for a Senior Azure Cyber Security Engineer who will act as a technical leader within the Cyber... ...security measures and requires 5+ years of experience in cybersecurity engineering. Applicants will work in a hybrid environment, contributing...Senior
- ...A leading cybersecurity firm is seeking a Senior Sales Engineer to join their Sales Engineering team in Cincinnati, Ohio. In this role, you will serve... ...and customers, focusing primarily on state and local government as well as education sectors. Candidates should have at...SeniorLocal areaRemote workFlexible hours
- ...Ernst & Young Oman seeks an AI Finance Senior to support finance applications in data management strategy. This role demands expertise in finance applications, data governance, and Machine Learning technologies. Key responsibilities include analyzing business requirements...SeniorFlexible hours
- ...FEG in Cincinnati, OH is hiring a Senior Security Engineer who will own cybersecurity operations from design to implementation. The role requires a technical expert who will partner with IT teams to mitigate security risks through a proactive, hands-on approach. You will...Senior
- A top cybersecurity firm is seeking a Senior Sales Engineer to support State and Local Government and Education accounts, mainly in the Eastern U.S. This role involves pre-sales technical leadership, building trusted relationships with clients, and delivering product demonstrations...SeniorLocal area
- ...Inc. is seeking an experienced Business Systems Analyst to support Identity and Access Management (IAM) initiatives within their Cybersecurity organization. The role involves collaborating with stakeholders and technology teams to enhance IAM platforms, strengthen access...Senior
$80k
...United Way Worldwide in Cincinnati is seeking a Sr. Manager of Information Technology & Security to lead IT operations and cybersecurity. This hands-on leadership role ensures reliable technology services while managing help desk and endpoint administration teams. The...SeniorWorldwide- ...FEG Investment Advisors in Cincinnati, OH is hiring a Senior Security Engineer responsible for cybersecurity operations, risk management, and securing systems and data. Ideal candidates have over 5 years of relevant experience in security engineering with a solid grasp...SeniorFlexible hours
- ...Core Specialty Insurance Holdings, Inc. is seeking a Deputy General Counsel focused on corporate governance in Cincinnati, OH. This role requires an experienced attorney with at least 10 years in legal practice, ideally within the financial services or insurance sector...Senior
- ...involves conducting comprehensive risk-based audit activities in a dynamic team environment, focusing on systems, databases, and cybersecurity controls. The ideal candidate will possess strong analytical and project management skills, as well as a Bachelor’s degree in a...Senior
- ...Summit Consulting is seeking a Senior Data Governance Analyst to lead Enterprise Data Management initiatives in Cincinnati, OH. This role will engage with business units to ensure trusted data for analytics and AI-driven use cases. The successful candidate will operationalize...Senior
- ...Engineer to implement and manage application development platforms. This role includes optimizing security tools while working with cybersecurity professionals. You will ensure secure development processes and enhance application security practices. Responsibilities include...SeniorFlexible hours
- ...Corporation in Deer Park, Ohio is seeking a Senior Security Engineer to enhance their... ...involves designing, implementing, and governing security measures while leading risk assessments... ..., and at least 5 years of cybersecurity experience. Benefits include competitive...SeniorFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Cybersecurity Governance Specialist. Be the first to apply!
- traffic specialist Cincinnati, OH
- wellness specialist Cincinnati, OH
- staffing specialist Cincinnati, OH
- family engagement specialist Cincinnati, OH
- google specialist Cincinnati, OH
- search engine optimization specialist Cincinnati, OH
- reading specialist Cincinnati, OH
- senior specialist Cincinnati, OH
- deployment specialist Cincinnati, OH
- member outreach specialist Cincinnati, OH


