Director, Cyber and Information Risk Lead
The Custom Group of Companies
Director, Cyber and Information Risk Lead 26-00001
2 days a week onsite Iselin NJ or New York
Direct hire full time position
Salary up to $210 with bonuse and Fantastic benefits What will you be doing: The Cyber and Information Risk Program Support Lead is responsible for leading a team to support execution of company's Enterprise Risk Management and Operational Risk Management programs for cyber, information security, and data management risk. The successful candidate will provide review and credible challenge of the effectiveness of information security and data management risk governance, identification, assessment, response, monitoring, and reporting capabilities. This position is highly engaged with firm-wide Information Security and Data Management teams who provide risk and control solutions as well as all corporate departments that own cyber, information security, and data management risk. Essential Function / major duties and responsibilities of the job Strategic
• Broad-based technology experience at substantial scale and complexity in a global, highly regulated, high-volume transaction environment. Experience must include time operating within transaction services environments characterized by the need for continuous availability and the highest levels of security.
• Experienced developing and managing Enterprise and Operational Risk programs related to information security and data management, including implementing risk and control frameworks in accordance with best practices and Basel requirements.
• Experienced leading in a complex matrixed organization, ideally in a global firm with a dynamic and rapidly changing environment.
• Experienced leading within a highly regulated environment, with a preference for experience at the international and federal levels.
• Deep knowledge of information security and data management risk and control frameworks and a strong understanding of policies, procedures, guidelines, and structure.
• Functional expertise, with operational knowledge of and exposure to various current and emerging information security and data management areas such as: v Cyber resilience v Identity & privileged access management v Secure coding practices v Cloud security configuration and control frameworks v Artificial Intelligence v Third-party risk management v Incident management v Threat/vulnerability management v Network security v Data governance v Data quality v Data architecture/lineage Professional qualifications / certifications • B.S. in a technology discipline (Computer Science, Information Management, Computer Engineering, Cybersecurity or equivalent). M.S. desired.
• Relevant certification is desirable, e.g., CISSP, CISM, CISA, CRISC.
• Working knowledge of information security and data management life cycles based on an established framework: CRI, NIST CSF, NIST SP 800-53, ORX, ISO 27001, SANS, CERT, ENISA, CSA, OACA, ISACA, DAMA-DMBOK.
• Proficiency in MS PowerPoint and Excel.
• Experience in broader MS Office suite, including Project and Visio is a plus
• Experience with enterprise GRC tools, e.g. Archer is a plus
2 days a week onsite Iselin NJ or New York
Direct hire full time position
Salary up to $210 with bonuse and Fantastic benefits What will you be doing: The Cyber and Information Risk Program Support Lead is responsible for leading a team to support execution of company's Enterprise Risk Management and Operational Risk Management programs for cyber, information security, and data management risk. The successful candidate will provide review and credible challenge of the effectiveness of information security and data management risk governance, identification, assessment, response, monitoring, and reporting capabilities. This position is highly engaged with firm-wide Information Security and Data Management teams who provide risk and control solutions as well as all corporate departments that own cyber, information security, and data management risk. Essential Function / major duties and responsibilities of the job Strategic
- Risk Culture - Assist the Head of Technology and Information Security Risk Management and Head of Enterprise Risk and Operational Risk Management in driving the culture of engagement, teamwork and accountability.
- Risk Assessments - Work with the Information Security and Data Management teams to challenge risk assessments, and lead in efforts to strengthen the control environment in line with the evolving threat landscape.
- Enterprise and Operational Risk Management Framework - Support the CRO and Head of Enterprise Risk and Operational Risk Management in furthering the use and efficacy of the ERM and ORM framework while enhancing its applicability to manage information security and data management risk.
- Review and Credible Challenge - Provide review and credible challenge of information security and data management risk profile and associated framework components, e.g., risk and control self-assessments, control testing, event management, metrics and indicators, risk appetite, finding management, and reporting.
- Risk Oversight - Lead in executing oversight of information security and data management risks by performing the following:
- Provide subject matter expertise to business units to drive, guide and influence risk ownership, clarity and assessment of risks & controls.
- Review and monitor the progress of actions and validate appropriateness of closure evidence.
- Document credible challenge of information security and data management risk appetite to support the Enterprise Risk management (ERM) program.
- Regular review and challenge of key risk indicators including thresholds and applicability to risk appetite.
- Prepare monthly and quarterly ORM/ERM reports and present to Technology Leadership, Audit, and regulatory bodies as required.
- Project Oversight - Lead in executing project oversight for information security and data management risks by performing the following:
- Provide challenge of risk management of material information security and data management projects that may impact the firm's risk profile.
- Work with business partners to challenge the quality of the project inherent risk assessments and contribute to the independent risk review for projects.
- Review project benefits and closure artifacts in preparation for transition to BAU.
- Governance - Actively present to various committees and forums to keep management educated on changes and challenges to risk appetite.
- Relationship Management - Be a respected point of contact to stakeholders across the business and technology functions in providing credible operational risk coverage for information security and data management risk.
- Mentorship - Provide guidance and support to junior members of the team.
- Lead projects in co-ordination with Operational Risk team to enhance the ORM framework and assist with implementation of best practices
- Interact with and / present to Client Client in regular continuous monitoring meetings
- Ability to influence and gain credibility with the business
• Broad-based technology experience at substantial scale and complexity in a global, highly regulated, high-volume transaction environment. Experience must include time operating within transaction services environments characterized by the need for continuous availability and the highest levels of security.
• Experienced developing and managing Enterprise and Operational Risk programs related to information security and data management, including implementing risk and control frameworks in accordance with best practices and Basel requirements.
• Experienced leading in a complex matrixed organization, ideally in a global firm with a dynamic and rapidly changing environment.
• Experienced leading within a highly regulated environment, with a preference for experience at the international and federal levels.
• Deep knowledge of information security and data management risk and control frameworks and a strong understanding of policies, procedures, guidelines, and structure.
• Functional expertise, with operational knowledge of and exposure to various current and emerging information security and data management areas such as: v Cyber resilience v Identity & privileged access management v Secure coding practices v Cloud security configuration and control frameworks v Artificial Intelligence v Third-party risk management v Incident management v Threat/vulnerability management v Network security v Data governance v Data quality v Data architecture/lineage Professional qualifications / certifications • B.S. in a technology discipline (Computer Science, Information Management, Computer Engineering, Cybersecurity or equivalent). M.S. desired.
• Relevant certification is desirable, e.g., CISSP, CISM, CISA, CRISC.
• Working knowledge of information security and data management life cycles based on an established framework: CRI, NIST CSF, NIST SP 800-53, ORX, ISO 27001, SANS, CERT, ENISA, CSA, OACA, ISACA, DAMA-DMBOK.
• Proficiency in MS PowerPoint and Excel.
• Experience in broader MS Office suite, including Project and Visio is a plus
• Experience with enterprise GRC tools, e.g. Archer is a plus
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Director, Cyber and Information Risk Lead in United States vacancy
- ...is currently seeking an Associate Director, Regional Information Security Awareness Lead to join our Global Technology and... ...implementation of KPMG information risk and security standards / requirements... ...to plan and execute regional cyber adoption campaigns Aid the Regional...CyberRiskH1bLocal area
$120.77k
...oversight of our Group Security functions in Discovery Group Information Services (GIS), Information, Security and Governance (IGS),... ..., regular reporting and maintaining the overall posture and risk of the cyber posture. Build, implement and maintain the Information Security...CyberRiskRemote work- ...Information Security Risk Management Program Leader This position aims to provide highly skilled technical... .../resource estimates. Risk Lead the development and implementation of... ...e.g., industry standards such as NIST Cyber Security Framework). Prefer well...CyberRiskContract workFor contractorsLocal areaRemote work
- ...Cyber And Information Risk, Independent Risk Review Lead The Cyber and Information Risk, Independent Risk Review Lead is responsible for leading the execution of independent reviews of the efficacy of Information Security and Data Management programs, including review...CyberRisk
- ...organization in developing and refining information security strategy, creating... ...the GSS team (namely Security Risk and Trust, Security Product... ...'s risk posture forward. Lead program delivery for GSS's... ...governance, and the data-driven cyber risk and control framework — with...CyberRiskRemote workFlexible hours
$61.9k - $141k
Phase2 Technology in Honolulu, Hawaii is seeking an information systems security specialist to design and manage security... ...in implementing security measures, monitoring for cyber threats, and contributing to risk management processes. Salary is $61,900 to $141,000 annually...CyberRisk- ...Houston, TX office, the Information Security & Privacy... ...Reporting directly to the Director, Information Technology... ...Kiwa's resilience against cyber threats and data... ...Act as the primary lead for North American business... ...security assessments, perform risk management, and serve...CyberRiskWork at officeRemote workWorldwide
- ...Lead Information Assurance/Cyber Security Program Manager - Information Security Analyst EPS Corporation is looking for a Lead Information Assurance... .... Experience in transitioning applications, systems, or Risk Management Framework (RMF). Experience supporting information...CyberRiskWork at officeLocal area
$140k - $250k
...initiatives. This ranges from the defensive risk reduction aspects of data security (... ...‑level role within IDG, serving as a lead for Information Security oversight within ISG. The role... ...including Technology Operational Risk (TOR), Cyber, the Firmwide Data Office (FDO), and...CyberRiskTemporary workWork at office$105.5k - $196.5k
...Lead, HR Business Partner (Employee & Labor Relations) L3Harris... ...the space, air, land, sea and cyber domains in the interest of... ...teams. Focus on mitigating risk and improving positive employee... ...veteran status, disability, genetic information, citizenship status,...CyberRiskLocal areaFlexible hours$185k - $245k
...Information Security Risk Oversight Lead - Second Line of Defense) Location New York Business Area Legal, Compliance, and Risk Ref # 10... ...application security, identity and access management, and cyber resilience. Familiarity with enterprise risk...CyberRiskTemporary workFor contractorsWork experience placement- ...business platforms. We leverage leading-edge secure systems and... ...and oversight in applying the Risk Management Framework (RMF) and... ...science, engineering, STEM, information technology, or cybersecurity... ...Security Controls, Encryption, Cyber Risk, Federal Government, Cleared...CyberRiskTemporary workMonday to Friday
- ...Title: Privacy and Controlled Unclassified Information Lead Program: SBA Enterprise Cybersecurity... ...This position aligns with the HACS SIN Cyber Task Manager labor category and provides... ...compliance activities, CUI governance processes, risk management coordination, data protection...CyberRisk
- ...Security Analyst Sr (SOC Shift Lead - Information Security) Cyber Security Threat Management Schedule : 8-4 EST Location: Preference for Indianapolis... ...support to business and technology associates in risk assessments and implementation of appropriate information...CyberRiskTemporary workWork at officeLocal areaRelocationShift work2 days per week1 day per week
- Senior Lead Information Security Office Consultant. As a Senior Lead Consultant in Capital One’s Cyber Information Security Office (ISO), you will work closely with our cybersecurity... ...and practical in your understanding of risk and security, but also willing to know when...CyberRiskWork at officeLocal areaShift work
$130k - $200k
...with unmet medical needs. As a leading innovator of Digital... ...digital therapeutics. For more information, visit and connect with us on... ...SOC 2, IEC 81001-5-1 and UK Cyber Essentials Plus). Lead the... ...Oversee all third-party and vendor risk management activities...CyberRiskPermanent employmentTemporary workWork at officeLocal areaVisa sponsorshipFlexible hours- ...Flexible Work Experience: Hybrid The Lead Information Security Analyst The Lead Information Security... ...security and supply chain security risks with applications, vendors and key... ...reporting of security metrics Support the Cyber Security Incident Response Team (CSIRT)...CyberRiskContract workWork experience placementWork at officeFlexible hours
$132.4k - $251.6k
...Site Lead And Information System Security Manager (ISSM) Our cybersecurity team is seeking a Site... ...You will provide advice and counsel on risk levels, security posture and... ...will interface and disseminate necessary cyber event information to appropriate internal...CyberRiskContract workTemporary workWork experience placementWork at officeRemote workRelocation packageFlexible hours$157k - $250k
...Cleared Senior Information Systems Security Engineer (ISSE) L4 Lead Lorton, VA ( Description Are you looking to... ...ll deliver enterprise services and cyber network defense capabilities. As... ...guide leadership on cybersecurity risks, vulnerabilities, and mitigation strategies...CyberRiskContract workRelocationFlexible hours$152.7k - $294k
Global Information Security Strategist Associate Director Other locations: Anywhere in Country Date: May 13, 2026 Requisition... ...work closely with the Global Lead for Information Security Strategy... ...of evolving business demands and cyber risks. Key Responsibilities Strategic...CyberRiskSummer holidayFlexible hoursShift work$93k - $189k
We are looking for an experienced Information Classification Senior Lead to establish and mature the enterprise... ...sensitivity-based handling, and AI risk mitigation, ensuring consistent enterprise... ...alignment. Partner closely with Cyber and Data Governance to ensure...CyberRiskWork experience placementWork at officeRemote workWork from homeFlexible hours$229.9k - $262.4k
Senior Lead Information Security Office Consultant At Capital One, you will help consult on initiatives... ...and practical in your understanding of risk and security, but also willing to know... ...Service, Endpoint Security and Cyber Intelligence services Coordinate and execute...CyberRiskWork at officeLocal areaShift work$112.8k - $165.4k
...Scope We are seeking an Information Security Analyst who is responsible... ...of systems to secure against cyber threats. The primary... ...and more. Interpret security risk assessments, review security scan... .... Recommend and take the lead on implementing changes to enhance...CyberRiskFull timeWork experience placementRemote work$160k - $175k
...Fortress Investment Group LLC is a leading, highly diversified global... ...we strive to generate strong risk adjusted returns for our... ...the long term. For additional information on Fortress, please visit the... ...degree in Computer Science, Cyber Security, Business Administration...CyberRiskPermanent employmentLocal areaWorldwide$99k - $225k
A leading consulting firm is seeking an Information Systems Security Officer in Washington, DC. You'll assess cyber risks, develop mitigation strategies, and translate security concepts for clients. Ideal candidates have 8+ years in cybersecurity, NIST standards experience...CyberRisk- ...the primary driver for Zoox's Information Security modernization roadmap... ...Governance, Identity & Zero Trust, Cyber Resilience, and Security... ...programs to operationalizing Risk-Based Vulnerability Management... ...expertise, with the ability to lead architecture discussions and align...CyberRiskTemporary workRelocation package
$50 - $55 per hour
...Title: IAM Triage analyst - Information Security Analyst 3 Position... ...Triage analyst, you would: Lead the assessment and resolution... ...issues to identify and mitigate risks, potential improvements, and... ...IAM Issues Partner with IAM, Cyber and the broader organization...CyberRiskHourly payFull timeContract workTemporary workWork experience placementImmediate startWorldwideFlexible hours$248.1k - $400k
Pcaob As in Washington, DC is seeking a Chief Information Security Officer to lead their information security program. This full-time role involves collaborating... ...operations, developing strategies to mitigate risks, and ensuring compliance with relevant standards. The...CyberRiskFull time- Job Summary The Associate Director, Americas Network Lead will be responsible for end‑to‑end leadership of... ...Security. Communicate network performance, risks, planned maintenance, and major... ..., segmentation, cloud expansion, cyber controls, and service reliability. Plan...CyberRiskContract workRemote work
- A leading technology company is seeking a strategic leader for its Information Security team in Natick, Massachusetts. The role demands significant expertise in cybersecurity, risk management, and compliance with regulations. Responsibilities include developing a cybersecurity...CyberRiskWork at officeRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director, Cyber and Information Risk Lead. Be the first to apply!
Related searches
- quality risk manager United States
- enterprise risk manager United States
- energy risk manager United States
- risk management specialist United States
- risk management associate United States
- security risk manager United States
- clinical risk manager United States
- group risk manager United States
- director credit risk United States
- risk management manager United States


