Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Information Security Risk Oversight Lead - Second Line of Defense)

$185k - $245k

Bloomberg

Information Security Risk Oversight Lead - Second Line of Defense)

Location

New York

Business Area

Legal, Compliance, and Risk

Ref #

10050628

Description & Requirements

Position Overview

The energy of a newsroom, the pace of a trading floor, the buzz of a recent tech breakthrough; we work hard, and we work fast - while keeping up the quality and accuracy we're known for. It's what keeps us inventing and reinventing, all the time. Our culture is wide open, just like our spaces. We bring out the best in each other through collaboration. Through our countless volunteer projects, we also help network with the communities around us, too. You can do amazing work here. Work you couldn't do anywhere else. It's up to you to make it happen.

About the Role:

We're looking for an Information Security Risk Oversight Lead who can translate cybersecurity risk into executive insight and action. Sitting firmly in the Second Line of Defense, you will provide independent oversight and credible challenge across the firm's enterprise-wide information security program. Operating at the intersection of technology, risk governance, and strategy, you will partner with Information Security, Engineering, and Risk teams to ensure risks are appropriately identified, measured, monitored, and aligned with the firm's risk appetite. The "so what" is critical: your oversight will enable leadership to understand not only what the risks are, but whether they are being managed effectively-and where decisive action is required to strengthen the firm's overall security posture.

Key Responsibilities

  • Lead independent review, oversight, and credible challenge of enterprise-wide information security risk assessments, control testing results, and key risk metrics.

  • Serve as the primary Second Line risk advisor for cybersecurity and technology-related risks.

  • Partner closely with Information Security and Engineering teams to enhance risk awareness, accountability, and control ownership.

  • Evaluate the design and operating effectiveness of security controls, particularly across complex, high-risk, or enterprise-scale technology initiatives.

  • Review and challenge security-driven programs and initiatives to ensure alignment with enterprise risk appetite and regulatory expectations.

  • Monitor information security findings, remediation plans, and validation activities to ensure timely and sustainable risk reduction.

  • Identify root causes of control failures, security incidents, or systemic weaknesses and support the development of actionable, preventative recommendations.

  • Prepare and present risk oversight materials to senior leadership committees, internal audit, and regulatory bodies as required.

  • Contribute to the integration and maturation of information security within the firm's enterprise risk management framework.

  • Maintain governance documentation, including policies, standards, and procedures related to information security oversight.

  • Act as a strategic thought partner to senior leaders by advising on emerging threats, evolving regulatory requirements, and industry best practices.

Required Qualifications

  • Bachelor's Degree required.

  • 10+ years of experience in Information Security.

  • 10+ years of experience in IT Risk Management.

  • Demonstrated experience operating within a Second Line of Defense or independent risk oversight function.

  • Strong understanding of cybersecurity control frameworks (e.g., NIST CSF, ISO 27001, COBIT, CIS).

  • Experience interacting with regulators, internal audit, and executive governance forums.

  • Authorized to work in the United States.

Preferred Qualifications

  • Relevant professional certifications (e.g., CISSP, CISM, CRISC, CISA).

  • Experience in regulated industries (e.g., financial services).

  • Strong understanding of cloud security, application security, identity and access management, and cyber resilience.

  • Familiarity with enterprise risk management methodologies and risk appetite frameworks.

Core Competencies

  • Strong analytical and critical thinking skills with the ability to provide constructive challenge.

  • Executive-level communication and presentation skills.

  • Ability to influence without direct authority.

  • Strategic mindset with strong attention to detail.

  • High integrity and independent judgment.

Salary Range = 185,000 - 245,000 USD Annual + Benefits + Bonus

The referenced salary range is based on the Company's good faith belief at the time of posting. Actual compensation may vary based on factors such as geographic location, work experience, market conditions, education/training and skill level.

We offer one of the most comprehensive and generous benefits plans available and offer a range of total rewards that may include merit increases, incentive compensation (exempt roles only), paid holidays, paid time off, medical, dental, vision, short and long term disability benefits, 401(k) +match, life insurance, and various wellness programs, among others. The Company does not provide benefits directly to contingent workers/contractors and interns.

Discover what makes Bloomberg unique - watch our for an inside look at our culture, values, and the people behind our success.

Bloomberg is an equal opportunity employer and we value diversity at our company. We do not discriminate on the basis of age, ancestry, color, gender identity or expression, genetic predisposition or carrier status, marital status, national or ethnic origin, race, religion or belief, sex, sexual orientation, sexual and other reproductive health decisions, parental or caring status, physical or mental disability, pregnancy or parental leave, protected veteran status, status as a victim of domestic violence, or any other classification protected by applicable law.

Bloomberg is a disability inclusive employer. Please let us know if you require any reasonable adjustments to be made for the recruitment process. If you would prefer to discuss this confidentially, please email View email address on click.appcast.io

Vacancy posted 7 days ago
Similar jobs that could be interesting for youBased on the Information Security Risk Oversight Lead - Second Line of Defense) in New York, NY vacancy
  • $104k - $147k

     ...Senior Vice President, Operational Risk Coverage We're seeking a...  ...providers, covering a wide array of debt securities: Corporates, Specialty Debt,...  ...provide appropriate independent second line of defense review, challenge, oversight, and advice to the first line of... 
    Risk
    Temporary work
    Work experience placement

    BNY

    New York, NY
    1 day ago
  •  ...Group Risk Specialist The Group Risk Specialist...  ...to business leaders. Leads and supports the implementation...  ...area. May provide oversight, commentary, and...  ...is guided by the Three Lines of Defense (LOD) Risk Framework:...  ...Internal Audit (3LOD). The second line is independent of... 
    Risk

    TD Bank

    New York, NY
    2 days ago
  • $90.6k - $150.44k

     ...Position Title Cloud/Cyber Risk Management Analyst Sr...  ...As a key member of the second line of defense Technology, Cyber, Third Party...  ...manage the Cybersecurity/Information Security ("Cyber") risk profile of...  ...effective, outcome-based oversight and challenge for the risk... 
    Risk
    Local area

    Flagstar Bank

    New York, NY
    1 day ago
  •  ...level and is generally a lead or SME for a given...  ...guided by the Three Lines of Defense (LOD) Risk Framework: Risk Ownership (1LOD), Risk Oversight (2LOD), and Internal Audit (3LOD). The second line is independent of...  ...multiple sources of information Conveys business context... 
    Risk

    TD Bank

    New York, NY
    2 days ago
  •  ...Senior Group Risk Analyst The Senior...  ...support and/or provide oversight, commentary, and...  ...by the Three Lines of Defense (LOD) Risk...  ...Audit (3LOD). The second line is independent...  ...resource for others Leads projects of...  ...handle confidential information with discretion... 
    Risk

    TD Bank

    New York, NY
    2 days ago
  • IDBNY is seeking an experienced Operational Risk Manager to strengthen the execution of the Bank’s operational risk program. Responsibilities include evaluating end-to-end processes to identify risks and control effectiveness, supporting risk framework enhancements, and... 
    Risk

    IDBNY

    New York, NY
    4 days ago
  • $207.9k

     ...Executive As the company's second line of defense, Corporate Risk - or Independent Risk...  ...- provides independent oversight of risk-taking activities...  ...functions. Manage and lead team with the implementation...  ...Benefits ~ Information about Wells Fargo's employee... 
    Risk
    Work experience placement

    Phenom People

    New York, NY
    5 days ago
  • $140k - $250k

     ...The Institutional Securities Group (ISG) has established an...  ...initiatives. This ranges from the defensive risk reduction aspects of...  ...IDG, serving as a lead for Information Security oversight within ISG. The role is...  ...escalated, and remediated in line with Firm standards.... 
    Risk
    Temporary work
    Work at office

    Morgan Stanley

    New York, NY
    5 days ago
  • $118.98k - $195.47k

     ...Lead, Cybersecurity/IT Control Design and Monitoring (First Line) Position Summary Do you want to...  ...who enjoys diving into security risk, translating complex...  ...in Cybersecurity, Information Technology, Computer...  ...management, remediation oversight, and risk trending... 
    Risk
    Full time
    Work at office
    Visa sponsorship
    Work visa
    Flexible hours
    3 days per week

    Guardian Life Insurance Company

    New York, NY
    1 day ago
  • $270k - $345k

     ...Compliance Governance & Oversight Lead San Francisco, CA | New York City...  ...that give leadership a clear line of sight into program health,...  ...of record for I&C, including risk tracking, control...  ...for money, fees, or banking information before your first day. If you... 
    Risk
    Interim role
    Work at office
    Visa sponsorship
    3 days per week

    Anthropic

    New York, NY
    5 days ago
  •  ...talent for our Personal Lines Actuarial Pricing team...  ...through Verisk's industry-leading products. In...  ...robust data to identify risk trends and pricing dynamics...  ...ways to communicate that information. Responsibilities...  ...Spain, and India, and the second consecutive year in... 
    Risk
    Work at office
    Flexible hours

    Verisk Analytics

    Jersey City, NJ
    3 days ago
  • $205k

     ...Investment Banking Structured Finance Credit Risk organization (2nd line of defense), responsible for the project...  ...Provide independent approval, oversight, and challenge on all U.S. PF and Tax...  ...regulators. Leadership & Risk Culture Lead and develop a high‑performing team,... 
    Risk
    Contract work
    Work at office

    Santander Consumer USA Inc.

    New York, NY
    3 days ago
  • $28.99 - $34.06 per hour

     ...You’ll Do The FLOD Corporate Risk & Compliance Specialist will...  ...Specialist will engage with the three lines of defense at FourLeaf as well as...  .... Collaborate with the second and third lines of defense functions...  .... Support business line leads when performing quality assurance... 
    Risk
    Hourly pay
    Flexible hours

    FourLeaf Federal Credit Union

    New York, NY
    1 day ago
  •  ...Regulatory Compliance Lead to join our growing North...  ...America Regulatory Oversight Compliance team....  ...manage their regulatory risk, helping ensure Wise remains...  ...shape and evolve our second-line compliance framework,...  ...Additional Information For everyone, everywhere... 
    Risk
    Work at office

    WISE Inc

    New York, NY
    4 days ago
  •  ...Compliance, Conduct And Operational Risk Management Lead Vice President Bring your...  ...Vice President within the Securities Services division of JPMorgan'...  ...integrity. You will work within the second line of defense, providing independent oversight, challenge, and subject matter... 
    Risk
    Work experience placement

    Chase

    Brooklyn, NY
    5 days ago
  • $150k - $163k

     ...partnerships with leading real estate...  ...sits within the Risk & Compliance Management...  ...operates as a second line of defense, partnering...  ...committees, partner oversight meetings)....  ...Assessments, ACH audits, security audits, and...  ...Risk Management, Information Security, and Data... 
    Risk
    Work experience placement
    Remote work

    Esusu

    New York, NY
    1 day ago
  • $115k - $160k

     ...opportunities and challenges. As an Oversight & Compliance Lead on the Card Payment Networks Team,...  ...MasterCard). You will drive governance, risk management, and operational...  ...disability needs. Visit our FAQs for more information about requesting an accommodation.... 
    Risk
    Contract work
    Work at office
    Work visa

    JPMorgan Chase Bank, N.A.

    New York, NY
    2 days ago
  •  ...Market Risk Governance & Volcker Analyst Market Risk Management...  ...operates within the second line of defense and reports to the U.S. Bancorp...  ...provides independent oversight, governance, monitoring, and...  ...audit engagements by gathering information and assisting with... 
    Risk
    Temporary work
    Work experience placement
    Work at office
    3 days per week

    U.S. Bancorp

    New York, NY
    6 days ago
  • $220k - $265k

     ...(O&R) Group’s first line of defense risk management department...  ...of the sufficiency of Second District customers’ BSA...  ...customers. Lead meetings with existing...  ...after analyzing multiple information sources, identify gaps...  ...Category Internal Oversight & Governance Family... 
    Risk
    Permanent employment
    Full time
    Temporary work
    Part time
    Bank staff
    Work at office
    Flexible hours
    Shift work

    Federal Reserve Bank

    New York, NY
    4 days ago
  • $110k - $222k

     ...Role The Fraud Risk Oversight team works in close partnership with 1st line Fraud Operations teams...  ...role in developing and leading critical components...  ...Oversight team serves as second line of defense, providing oversight...  ..., Audit, and Security - in pursuit of our common... 
    Risk
    Work from home

    Fidelity Investments

    Jersey City, NJ
    3 days ago
  • $190.5k - $297.4k

     ...business. As part of the second line of defense, you'll bring...  ...rapport while keeping risk front and center. We'...  ...Provides market risk oversight, monitoring, and reporting...  ...issues and trends to inform decision-making....  ...Manages resources and leads the execution of strategic... 
    Risk
    Part time
    Immediate start

    Bmo

    New York, NY
    4 days ago
  •  ...Vice President, Interest Rate Risk in the Banking Book Oversight About the Company A well-capitalized...  ...candidate will be responsible for leading the assessment of key risk metrics,...  ...role is to drive enhancements to the second line oversight frameworks, governance... 
    Risk

    Confidential

    New York, NY
    2 days ago
  •  ...Compliance, Conduct And Operational Risk (CCOR) Bring your expertise to...  ...Risk (CCOR), you will provide second line of defense (2LoD) independent oversight across the Chief Data & Analytics...  ...orchestration layers), with a focus on secure control points and end-to-end... 
    Risk
    Work at office

    Chase

    Jersey City, NJ
    4 days ago
  • $300k

     ...Director/Principal, Risk Management...  .... This is a second-line risk role with...  ...ongoing portfolio oversight. Primary...  ...making clear, defensible credit...  ...achieve financial security by providing a...  ...be: The leading provider of retirement...  ...more detailed information on specific... 
    Risk

    Apollo Inc

    New York, NY
    4 days ago
  • A global financial services firm is seeking a Financial Crime Risk Oversight Specialist to join their team in New York. This senior role involves supporting the financial crime risk management program, advising on compliance with financial regulations, and assessing risks... 
    Risk

    Carlsbad Tech

    New York, NY
    1 day ago
  • $42k - $90k

     ...Information Security Program Manager This incumbent will provide Strategy, Programs, Governance, Risk and Compliance functions as required to fulfill...  ...across first and second lines Periodically refresh...  ...procedures Provide oversight and monitoring of privacy... 
    Risk
    Work experience placement
    Work at office

    Bank of China

    New York, NY
    5 days ago
  • $160k - $180k

     ...Internal Auditor Market Risk Job Code: 12872...  ...compensation and benefits information). Company overview...  ...with the First and Second Lines of Defense to evaluate and...  ...Line of Defense (2LoD) oversight of market risks within...  ...Responsibility Lead or co-lead audits of... 
    Risk

    Nomura

    New York, NY
    5 days ago
  • $229.9k - $262.4k

     ...Sr. Risk Manager, Data Protection This...  ...effective oversight, credible challenge...  ...Management (TRM)'s second line of defense function is a growing...  ...: Play a lead role in...  ...challenge, and risk-informed recommendations for...  ...Information Systems Security Professional (CISSP... 
    Risk
    Full time
    Part time
    Local area
    Immediate start

    Capital One Financial Corp

    New York, NY
    3 days ago
  •  ...regulatory and reputational risk across the firm and...  ...part of the firm's second line of defense, Compliance assesses...  ...and breaches; and leads the firm's responses...  ...governance, and emerging risk oversight, supporting both...  ...investment banking, securities and investment... 
    Risk

    The Goldman Sachs Group

    New York, NY
    5 days ago
  • $15k

     ...confidence. The Team Upstart’s Risk team is hiring to enhance its second line of defense function in support of its application...  ...as for providing independent oversight and credible challenge across...  ..., Enterprise Risk Management to lead and grow the Risk team’s ERM function... 
    Risk
    Temporary work
    Remote work

    UpStart

    New York, NY
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Information Security Risk Oversight Lead - Second Line of Defense). Be the first to apply!