Information Security Risk Oversight Professional
$111.61k - $131.3kU.S. Bank
At U.S. Bank, we're on a journey to do our best. Helping the customers and businesses we serve to make better and smarter financial decisions and enabling the communities we support to grow and succeed. We believe it takes all of us to bring our shared ambition to life, and each person is unique in their potential. A career with U.S. Bank gives you a wide, ever-growing range of opportunities to discover what makes you thrive at every stage of your career. Try new things, learn new skills and discover what you excel at-all from Day One.
Job Description
The Information Security Risk Oversight Professional serves as a key member of the Cybersecurity Risk Oversight team within the Second Line of Defense (2LoD). This role is accountable for providing independent oversight and credible challenge of the First Line Information Security program to ensure risks are appropriately identified, assessed, managed, monitored, and reported in alignment with regulatory requirements, industry standards, and internal risk appetite.
This position is intentionally designed for a senior, autonomous professional who can manage their own oversight portfolio, prioritize work based on material risk, and engage effectively with Information Security Services, Technology teams, and senior leadership.
Key Responsibilities
Provide independent oversight and credible challenge of the Information Security program across multiple security pillars, including governance, risk assessments, controls, metrics, and issue management.
Perform risk-based assessments of first line security practices, identifying gaps, weaknesses, thematic concerns, emerging risks, and control deficiencies.
Develop and articulate independent risk opinions supported by sound analysis, evidence, and professional judgment.
Evaluate alignment of first line activities with applicable laws, regulations, regulatory guidance, industry standards (e.g., NIST 800-53, FFIEC, PCI, NIST CSF 2.0, etc), and internal policies.
Monitor key risk indicators, security metrics, assessment results, and issue trends to identify systemic risks or areas requiring escalation.
Escalate material risks, control weaknesses, or ineffective risk management practices through appropriate governance and reporting channels.
Act as a subject matter expert on information security risk, providing insights and guidance to stakeholders while maintaining 2LoD independence.
Build and maintain strong, professional relationships with first line stakeholders while confidently challenging assumptions, conclusions, and risk positions when necessary.
Contribute to executive-level risk reporting by clearly summarizing risk posture, trends, and areas of concern in a concise and defensible manner.
Stay current on evolving cybersecurity threats, regulatory expectations, and industry best practices to continuously strengthen oversight effectiveness.
Basic Qualifications
Bachelor's degree, or equivalent work experience
Typically more than eight years of applicable experience
Preferred Skills/Experience
Strong foundational understanding of information security domains (e.g., vulnerability management, identity and access management, application security, cloud security, security governance, incident management).
Demonstrated ability to perform risk assessments and oversight activities with depth, critical thinking, and professional skepticism.
Experience operating in or with a Second Line of Defense, audit, or regulatory environment is strongly preferred.
Proven ability to work independently and autonomously, managing priorities and delivering high-quality work with limited direction.
Strong written and verbal communication skills, including the ability to translate technical risk into clear, executive-ready insights.
Ability to engage confidently with senior stakeholders while maintaining independence, objectivity, and professionalism.
Relevant certifications (e.g., CISSP, CISA, CRISC, CISM) are preferred but not required.
This role requires working from a U.S. Bank location three (3) or more days per week.
If there's anything we can do to accommodate a disability during any portion of the application or hiring process, please refer to our disability accommodations for applicants ( .
Benefits:
Our approach to benefits and total rewards considers our team members' whole selves and what may be needed to thrive in and outside work. That's why our benefits are designed to help you and your family boost your health, protect your financial security and give you peace of mind. Our benefits include the following:
Healthcare (medical, dental, vision)
Basic term and optional term life insurance
Short-term and long-term disability
Pregnancy disability and parental leave
401(k) and employer-funded retirement plan
Paid vacation (from two to five weeks depending on salary grade and tenure)
Up to 11 paid holiday opportunities
Adoption assistance
Sick and Safe Leave accruals of one hour for every 30 worked, up to 80 hours per calendar year unless otherwise provided by law
Review our full benefits available by employment status here ( .
U.S. Bank is an equal opportunity employer. We consider all qualified applicants without regard to race, religion, color, sex, national origin, age, sexual orientation, gender identity, disability or veteran status, and other factors protected under applicable law.
E-Verify
U.S. Bank participates in the U.S. Department of Homeland Security E-Verify program in all facilities located in the United States and certain U.S. territories. The E-Verify program is an Internet-based employment eligibility verification system operated by the U.S. Citizenship and Immigration Services. Learn more about the E-Verify program ( .
The salary range reflects figures based on the primary location, which is listed first. The actual range for the role may differ based on the location of the role. In addition to salary, U.S. Bank offers a comprehensive benefits package, including incentive and recognition programs, equity stock purchase 401(k) contribution and pension (all benefits are subject to eligibility requirements). Pay Range: $111,605.00 - $131,300.00
U.S. Bank will consider qualified applicants with arrest or conviction records for employment. U.S. Bank conducts background checks consistent with applicable local laws, including the Los Angeles County Fair Chance Ordinance and the California Fair Chance Act as well as the San Francisco Fair Chance Ordinance. U.S. Bank is subject to, and conducts background checks consistent with the requirements of Section 19 of the Federal Deposit Insurance Act (FDIA). In addition, certain positions may also be subject to the requirements of FINRA, NMLS registration, Reg Z, Reg G, OFAC, the NFA, the FCPA, the Bank Secrecy Act, the SAFE Act, and/or federal guidelines applicable to an agreement, such as those related to ethics, safety, or operational procedures.
Applicants must be able to comply with U.S. Bank policies and procedures including the Code of Ethics and Business Conduct and related workplace conduct and safety policies.
Posting may be closed earlier due to high volume of applicants.
- .... GENERAL FUNCTION: Provide independent oversight and effective challenge of Technology and Information Security risk activities to support safe and sound operations... ...Data Science, or related area. ~ Relevant professional certifications (e.g., CISA, CISM, CRISC,...Risk
- ...Information Security Consultant Provides support to business and IT teams... ...projects. Performs risk assessments, security assessments... ...Required Demonstrated calm and professional demeanor when handling... ...to provide direction and oversight. - Required Demonstrated...RiskWork experience placementWork at office
- ...include first line of defense risk limits, with policies... ...to management.* Provides oversight to the LOB supplier and... ...Computer Science, Cyber Security, Software Engineering, management... ...- Specialty + Certified Information Systems Security Professional (CISSP) + Certified...Risk
- ...Description As an AI Technology Risk Manager, the role... .../Audit (RCA) professionals, and RCA Managers to create... ...identifying gaps and informing solutions to minimize... ...awareness and manage the oversight of the AI risk... ...protect your financial security and give you peace of...RiskTemporary workWork experience placementWork at officeLocal area3 days per week
$110.5k - $202.7k
...reliable overview of their risk landscape. Our... ...cloud risk framework and oversight capability to ensure consistency... ...evaluate, and enhance information systems facilitating... ...other Risk Assurance professionals in performing... ...technology control and security engagements. Skills...RiskContract workSummer holidayWork at officeImmediate startFlexible hours- Back Security Engineer 2 - Cyber Security #51-8943 Multiple Locations... ...Bachelor's degree in Information Security or other computer-related... ...and/or experience. Professional level knowledge of common network... ...assessment outcomes, risk findings, security posture,...RiskFull timePart timeRemote work
$110.5k - $202.7k
...reliable overview of their risk landscape. Our... ...cloud risk framework and oversight capability to ensure consistency... ...evaluate, and enhance information systems facilitating... ...other Risk Assurance professionals in performing... ...technology control and security engagements. Skills and...RiskContract workSummer holidayWork at officeImmediate startFlexible hours$152.7k - $294k
Opportunity As part of EY Information Security, this role focuses on ensuring... ...the Technology Assurance, Risk & Policy (TARP) function’s... ...ISO 31000 in an execution‑oversight context. Experience with enterprise... .... What We Look For Professionals who think critically,...RiskWork at officeRemote workFlexible hours- Western & Southern Financial Group in Cincinnati is seeking a professional in information security to provide support for corporate initiatives and projects. The role encompasses risk assessments, security guidance, and policy development to ensure compliance with industry...Risk
$60 - $65 per hour
...Solutions is immediately hiring for an Information Systems Security Manager. Position Type: Full Time... ...in accordance with the NISPOM, NIST Risk Management Framework, NIST 800-53 requirements... ...employs approximately 50,000 professionals worldwide and reports an annual revenue...RiskHourly payFull timeContract workTemporary workWork experience placementWork at officeLocal areaImmediate startWorldwideFlexible hours$110k - $165k
...OFFICES Job Description Information Technology at Procter &... ...we serve worldwide. Our IT professionals are diverse business leaders... ...world’s most advanced cyber security adversaries? The Information... ...Produce executive-ready risk narratives and technical reporting...RiskFull timeWork at officeRemote workWorldwide$100.38k - $149.16k
...automation, ensuring secure, scalable, and efficient... ...-team resolution and risk reduction. Drive platform... .... Promote Information Security policies and... ...Associate Cloud Engineer or Professional Cloud Architect... ...results with minimal oversight. Mentor engineers of...RiskFull timeTemporary workLocal area$31.44 - $43.26 per hour
...greatest assets and biggest risks: vulnerabilities in people.... ...candidate passionate about Information Protection and Compliance and... ...meet Information Protection security and compliance requirements.... ...years industry experience in a Professional Services Consulting or...RiskFlexible hours- ...environments. We specialize in safety training, risk management, compliance consulting,... ...and results-driven Business Development Professional to join our national sales team. This... ...the broader sales strategy for safety, security, emergency response, safety rentals, and...RiskFull time
- U.S. Bank is seeking an Information Security Third‑Party Risk Analyst to support third‑party risk management and vendor security oversight. This role evaluates and manages information security risks across external vendors, ensuring appropriate controls are in place and...RiskContract workTemporary work
- ...sourcing strategies specifically for information technology categories,... ...services, SaaS, telecom, and IT professional services. This role partners closely with IT, Security, Finance, and Legal to... ...ownership (TCO), manage technology risk, ensure licensing and contractual...RiskContract workWork at office
- ...compliance with data governance, privacy, and information security standards. Stay current with... ...organizational impact, communicating risks and opportunities to stakeholders. Business... ...an active contributor to the company, professional development and career advancement...RiskTemporary workCurrently hiring
$100k - $110k
...citizen and must possess a Secret Security clearance or be capable of... ...layers of the OSI model. Information Security - Splunk, Trellix,... ...to excel in their role. Professional demeanor to work in an active... ...Collaboration, Decision Making, and Risk Management - experience in...RiskFull timeWork at officeLocal areaRemote work$172k - $250k
...Director Of Information Security Audit & Compliance Grant Thornton is seeking a Director of Information... ...remediation plans. Governance, Risk & Control Framework Align the... ...team of audit and compliance professionals. Define roles, responsibilities, career...RiskWork at office- ...: Supports LOB for Financial Crimes, Risks, Disputes, etc. Administration of applications... ...tools. ~ Familiarity with information security, user management, and network environment... ...with a small team of 5 support professionals, ensuring smooth application functionality...RiskLocal areaNight shift
$110k - $165.3k
...Senior Communications Manager, Information Security and Technology The Senior Communications... ...implications, external visibility, and risks associated with cybersecurity incidents... ...1336 Job Segmentation: Experienced Professionals Starting Pay / Salary Range: $110,0...RiskFull timeWork at office$20.34 per hour
...time, referral bonuses and professional development. IDEA may offer... ...Communication - effectively conveys information using a variety of channels... ...Escalate major and minor risks to relevant actors... ...Proficient rating on Information Security & Data Privacy Rubric by January...RiskHourly payWork at officeImmediate startRemote workRelocation package$22 - $26 per hour
...WhiteDog is seeking an Information Security Analyst to join our Security Operations Center team.... ...attacks and techniques, threat vectors, risk management, incident management etc.... ...Excellent interpersonal skills and professional demeanor. Excellent verbal and written...RiskHourly payFull timeWork at officeRemote workShift work- ...and support infrastructure security controls across the enterprise... ...of IT Infrastructure and Information Security, translating security... ...requirements, audit findings, and risk management objectives into... ...opportunities & professional development Volunteer opportunities...Risk
- ...Analysis (BIA), testing, and exercises under guidance of the Information Security Risk Officer. The program is managed in accordance with safe... ...and preparedness. Cultivates and maintain effective professional working relationships with management and staff to build...RiskBank staffWork at office
- Director - Cyber Security GE Renewable Energy Power and... ...aligned to enterprise risk, regulatory... ...managing performance oversight and accountability of... ...and cybersecurity. Stay informed with the latest trends... ...Qualification Minimum of 8 years professional experience with a...RiskPermanent employmentImmediate startVisa sponsorshipWork visaRelocation package
- ..., Ohio is seeking an experienced cybersecurity professional to manage client engagements and provide data security solutions. This role requires a minimum of 15 years... ...candidate will have a Bachelor’s Degree in Information Systems, various cybersecurity certifications,...RiskFlexible hours
$80k
...Cincinnati is seeking a Sr. Manager of Information Technology & Security to lead the day-to-day operations of... ...protection, access management, and risk mitigation Maintain system health,... ...programs Community volunteer opportunities Professional development and training...RiskTemporary workWork at office$87.8k - $160.9k
...better working world. Digital Risk - Senior Consultant - Power &... ...assist clients in employing proper information systems, resources, and... ...assist clients and other Risk professionals in performing information technology control and security engagements. Skills and attributes...RiskContract workSummer holidayFlexible hours$96k - $181k
...Reporting to the Director of Cybersecurity Risk Oversight, the Sr. Cybersecurity Risk Oversight Professional is a 2nd Line of Defense risk management position... ...line of business, as well as technology and information security risk oversight for areas of the enterprise...RiskWork at officeFlexible hoursNight shift
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security Risk Oversight Professional. Be the first to apply!
- security officer nights Cincinnati, OH
- part time overnight security officer Cincinnati, OH
- part-time security guard Cincinnati, OH
- overnight security guard Cincinnati, OH
- overnight hospital security officer Cincinnati, OH
- security officer retail store Cincinnati, OH
- security guard day shift Cincinnati, OH
- security officer hiring event Cincinnati, OH
- hiring security guard Cincinnati, OH
- armed security officer Cincinnati, OH


