Principal, Cybersecurity Risk
Fidelity Investments
Job Description:Note: Fidelity will not provide immigration sponsorship for this positionThe RoleThe Enterprise Cybersecurity Risk (ECS Cyber Risk) team is seeking an experienced Principal-level risk professional to lead in the creation of cyber risk analysis pertaining to ECS. The candidate will understand current and emerging cybersecurity risks and determine key risk scenarios for the ECS Product Areas. The candidate will participate in risk / threat modeling sessions to prioritize top risks. The candidate will advise on both exceptions and audit finding risk levels to drive down the number of exceptions and accurately risk rate audit findings. The candidate will quantify cyber risk and present analyses at the technical and executive level that will allow senior management to make informed decisions based on resulting risk data.The Expertise and Skills You BringMinimum 3-5 years of risk experience quantifying cyber risk scenarios and presenting data in a meaningful and insightful way to senior leaders.Demonstrated experience in cybersecurity risk management, assessment frameworks, and metrics reporting.Experience managing projects end-to-end, from initial stages of acquiring data from multiple sources and subject matter experts to the tracking, maintenance, and closure of a project, with proven ability to integrate data into risk analysis tools and communicate progress effectively across multiple lines and levels.Use and understanding of governance, risk, and compliance tools.Advanced understanding of NIST 800-53 Cybersecurity Framework, Cybersecurity Risk Institute (CRI), and FAIRCRISC, CISSP, or CISM certifications are preferred.You have effective communication and excellent presentation skills to senior leaders.You can deep dive into metrics that will both (1) quantify the work being done and (2) quantify how cyber risk position has improved.Critical thinking skills to ask detailed questions and fully vet answers to uncover discrepancies and gaps others may not have found is a must.You can work across business lines to influence change and help mitigate cyber risk.You have an intermediate understanding of risks pertaining to the following: cloud security, access controls, encryption, vendor security, data exfiltration, application security, perimeter security, customer protection, privileged access, denial of service, unpatched vulnerabilities, and end of life software.You operate in a fast-paced environment and can complete analyses quickly and accurately integrating new cybersecurity data into risk models as it emerges.You bring an investigator mindset to deep dive into metrics to understand and communicate actionable risk to business and technology groups.Determining the appropriate controls for cybersecurity risksWorking with asset inventory and asset managementEvaluating multiple sources, reports, industry trends to compare risk related findings to existing ECS policies and uncover gaps and opportunities for process improvement.Determining what, who, and where changes are warranted to close gaps, working with appropriate contacts to draft policy enhancement ensuring continued progress.The TeamECS Cyber Risk provides cybersecurity risk analyses pertaining to existing and emerging risk scenarios and communicates these risks to appropriate ECS technical teams and senior leadership. This team focuses on identifying, measuring, prioritizing, and reporting on cyber risk scenarios and will work both independently and across business units and technology teams to assist senior management with informed decisions and directions in strategy to either maintain the course or if needed, change direction.Fidelity’s Onsite Working ModelFidelity is transitioning to a full-time onsite working model through a phased rollout across regions and roles. Currently, some roles and locations require 100% onsite presence, while others require less. Onsite expectations are likely to evolve as the rollout continues. This transition does not apply to fully remote roles.Certifications:Category:Information TechnologyPlease be advised that Fidelity’s business is governed by the provisions of the Securities Exchange Act of 1934, the Investment Advisers Act of 1940, the Investment Company Act of 1940, ERISA, numerous state laws governing securities, investment and retirement-related financial activities and the rules and regulations of numerous self-regulatory organizations, including FINRA, among others. Those laws and regulations may restrict Fidelity from hiring and/or associating with individuals with certain Criminal Histories.SummaryLocation: Durham, NCType: Full time
- ...functions. Primary Responsibilities:Makes information security risk determinations based on intelligence analysis.Develops plans... ...education equivalent) and five (5) years of experience as a Principal Cybersecurity Analyst (or closely related occupation) designing and...PrincipalRiskFull time
- ...continuously improve a security program aligned with the NIST Cybersecurity Framework, including controls mapping, evidence collection, gap... ...assessments. Manage remediation efforts through closure Risk Managemen t: Identify, document, assess, and track information...RiskFor contractorsWork at office
- ...Cybersecurity Analyst Fidelity TalentSource is your destination for discovering your next temporary role at Fidelity Investments. We are... ...and assessing business process controls, identifying risks and linking business risks to the relevant IT application controls...RiskTemporary workWorldwide
$100k - $155k
...hands-on experience with FedRAMP compliance processes and federal risk management frameworks, including exposure to FedRAMP High and... ...Monitor FedRAMP PMO, NIST, and DoD SRG updates and federal cybersecurity directives, flagging relevant changes to the GRC team Participate...RiskFull timeLive inWorldwideFlexible hours$170k - $412.5k
...Architecture, Engineering, Infrastructure, Product Security, and Risk Management teams to ensure security is embedded into... ...degree in Computer Science, Information Systems, Engineering, Cybersecurity, or related field.12+ years of experience in information security...RiskFull timeWork experience placementWork at officeLocal areaImmediate start2 days per week- ...compliance monitoring platforms. ~ Conduct internal audits, risk assessments, and generate reports. ~ Conduct Incident Response... ...'s Degree from an accredited university in a Technology or Cybersecurity field OR 4+ years of direct experience in listed areas. ~3+...RiskWork experience placementSummer workRemote work
- ...vulnerability assessments and remediation planning.Collaborate with cybersecurity teams to ensure compliance with organizational security... ...expenditures, and evaluate operational expenditures.Identify operational risks and recommend mitigation strategies.Evaluate emerging...RiskRemote work
- ...including both COOs, on information technology strategy, investments, risk, and innovation. Owns the implementation, operation,... ...on IT performance, project delivery, system availability, cybersecurity posture, and resource utilization to executive leadership....RiskWork at office
- ...including both COOs, on information technology strategy, investments, risk, and innovation. Owns the implementation, operation,... ...on IT performance, project delivery, system availability, cybersecurity posture, and resource utilization to executive leadership....RiskContract workWork at officeLocal area
- ...deep semiconductor industry knowledge and the ability to align cybersecurity with business strategy. The CISO will manage a team,... ...business units, and report to the executive leadership and board on risk posture, regulatory compliance, and incident response readiness...Risk
$164.6k - $208.9k
...Language (SPL); experience developing and optimizing correlation and risk-based alerting rules.Security Frameworks: Expertise in Assets... ..., including forwarding architecture and technical add-ons.Cybersecurity Domain: Solid foundation in security operations, forensics,...RiskFull timeTemporary workLocal areaRemote workFlexible hours$98.2k - $273.2k
Position SummaryWe are seeking a Principal Statistical Programmer to provide full end‑to‑end statistical programming support across clinical... ...Clinical Operations, and Regulatory teamsProactively identify risks and propose efficient, compliant solutions within...PrincipalRiskFull timePart timeImmediate startWorldwide$118.69k - $189.91k
...services. Monitors market shifts, competitive actions, and customer demand signals to proactively identify pricing opportunities and risks. Evaluates the impact of competitor and market pricing changes on portfolio performance and strategic positioning. Synthesizes...PrincipalRiskFull timeLocal areaRemote workFlexible hoursShift work$126k - $234k
...manufacturing and make a meaningful impact on patients’ lives. As a Principal Engineer, MS&T, you will serve as a scientific and technical... ..., Quality Compliance, Regulatory Compliance, Resilience and Risk Management (Inactive), Technical Leadership, Technology TransferSummaryLocation...PrincipalRiskFull timeRelocation package- ...strategic Chief Information Security Officer to build and lead global cybersecurity and information assurance programs. You will protect IP,... ...business goals. Responsibilities include designing a global risk program, leading a security team, managing incidents and business...Risk
- ...in concert with the production support organization.Advises on risk assessment and risk management strategies. Mentors junior product... ...education equivalent) and five (5) years of experience as a Principal Systems Analyst (or closely related occupation) administering and...PrincipalRiskFull time
$102.17k
...Security Analyst, where you will operate at the intersection of cybersecurity and DevSecOps to protect critical software systems that... ...with Mend for software composition analysis (SCA), open‑source risk management, and vulnerability remediation. Experience working...RiskH1b- Morpheus Software Principal UI/UX engineerThis role has been designed as ‘Hybrid’ with an expectation that you will work on average 2 days... ...on fraudulent communication is at the individual’s own risk, and HPE disclaims legal liability for any resulting damages. If...PrincipalRiskFull timeWork experience placementWork at officeLocal areaImmediate start2 days per week
- ...Principal Medical WriterViiV Healthcare is a global specialty HIV company, the only one that is 100% focused on researching and delivering new medicines for people living with, and at risk of, HIV. ViiV Healthcare is highly mission-driven in our unrelenting commitment...PrincipalRiskLocal areaRemote work
- ...critical to success. This person will work closely with Information Risk on the execution and enforcement of our information security... ..., you will have: Bachelor’s Degree required – major in Cybersecurity, Information Security Management, Computer Science or...RiskSummer workWork at officeRemote workFlexible hours2 days per week
- ...Responsible for meeting project goals on-time and on-budget.Advises on risk assessment and risk management strategies for projects.Plans... ...education equivalent) and five (5) years of experience as a Principal Data Engineer (or closely related occupation) designing and...PrincipalRiskFull time
- ...Principal Statistical ProgrammerThe Principal Statistical Programmer will lead programming activities for one or more studies, ensuring... ...for emerging tools when needed.Communicate technical concepts, risks, and timelines clearly to stakeholders.Mentor junior programmers...PrincipalRiskWorldwide
- ...Responsible for meeting project goals on-time and on-budget.Advises on risk assessment and risk management strategies for projects.Plans... ...education equivalent) and five (5) years of experience as a Principal Software Engineer/Developer (or closely related occupation)...PrincipalRiskFull time
- ...Responsible for meeting project goals on-time and on-budget.Advises on risk assessment and risk management strategies for projects.Plans... ...education equivalent) and five (5) years of experience as a Principal Cloud Engineer (or closely related occupation) building,...PrincipalRiskFull time
- ...sound judgment and a results-driven approach to focus efforts on risks with the greatest potential business impact. Minimum one year... ...while maintaining compliance and security best practices. Cybersecurity Fundamentals: Apply a strong understanding of network security...Risk
- Principal Cloud DeveloperThis role has been designed as 'Hybrid' with a requirement that you will work on average 2 days per week from an... ...systems portions or subsystems and advise on dealing with high-risk situations.Identifies and evaluates new technology innovations...PrincipalRiskFull timeWork experience placementWork at officeLocal areaImmediate start2 days per week
$169k - $224k
...compliance. Minimal applicable standards for this position include:Cybersecurity principles, tools, and control frameworks (e.g., ISO 27001,... ...11)AI governance, software validation, data integrity, and risk management principles applicable to regulated environmentsDeep...RiskFull timeTemporary workWork at officeLocal areaFlexible hoursShift work- ...Principal Systems EngineerAutomates processes in native Cloud environments using Agile development practices, Continuous Integration/Continuous... ...procedures, programming, and documentation.Advises on risk assessment and management strategies for projects.Acts as a primary...PrincipalRisk
- ...Responsible for meeting project goals on-time and on-budget.Advises on risk assessment and risk management strategies for projects.Plans... ...education equivalent) and five (5) years of experience as Principal Full Stack Engineer (or closely related occupation) developing...PrincipalRiskFull time
- ...edge, and cloud. Cohesity helps organizations defend against cybersecurity threats with comprehensive data security and management capabilities... ..., and evaluations. Identify customer requirements and risk areas, helping shape proofs of concept that highlight Cohesity...RiskRelocation
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Principal, Cybersecurity Risk. Be the first to apply!


