Senior Business Information Risk Manager

Amazon.com
FANWOOD, NJ, US
Full-time

Good storytelling starts with great listening. At Audible, that means each role and every project has our audience in mind.

Because the same people who design, develop, and deploy our products also happen to use them. To us, that speaks volumes.

ABOUT THIS ROLE

As a Senior Business Information Risk Manager at Audible, you'll be at the forefront of safeguarding our digital landscape, championing information security across our entire ecosystem.

In this pivotal role, you'll shape the direction of Audible's security strategy, working closely with business and product teams to protect key assets and data.

You'll conduct comprehensive security assessments, develop risk mitigation strategies, and provide expert guidance on complex security challenges.

Your influence will extend beyond the security team as you partner with cross-functional groups to embed security best practices, fostering a culture of cybersecurity awareness.

You'll drive continuous improvement by developing metrics, monitoring trends, and implementing pragmatic solutions that balance security needs with business goals.

As a mentor and educator, you'll empower security engineers, champion initiatives, and provide training to both internal teams and external partners.

Join us in building a secure future for Audible, where your expertise will directly impact the protection of our customers and the integrity of our business.

As a Senior Business Information Risk Manager, you will...

Play a leadership role in Audible InfoSec & Security Engineer org and work closely with the Audible business and product community, setting direction for security of key assets, data, and business processes;

serving as a subject matter expert resource for security engineers, security champions, and business leaders inside and outside of our organization

  • Proactively assess, identify and develop recommendations regarding data protection, insider threat, data sharing, identity and access management, and third party risk issues and vulnerabilities by working with multiple stakeholder teams, including Privacy, Legal, HR, IT, etc
  • Lead and execute internal security and data usage assessments, investigations and security audits, while also supporting enterprise wide information security and cyber risk assessments with technical and non-technical teams
  • Contribute to the development of business risk, insider threat, and third party risk management strategic control requirements and roadmaps
  • Contribute to new, and provide feedback on existing security standards and control requirements, GRC policy exceptions and risk issue management process
  • Develop and maintain relevant security risk metrics to promote transparency across the organization; measures, monitors and reports on information security risks to management
  • Provide guidance on risk, compliance, and policy to technical and non-technical internal customers, including security training and outreach to internal teams and external supply chain partners
  • Apply your security and business knowledge to drive secure and pragmatic improvements broadly to Audible people, process, and assets, while making technical trade-offs between short versus long term security and business goals
  • Strong organizational and communication skills, with a demonstrated ability to work in a multi-tasking dynamic environment while maintaining a high level of ownership and accountability is a must

ABOUT AUDIBLE

Audible is the leading producer and provider of audio storytelling. We spark listeners’ imaginations, offering immersive, cinematic experiences full of inspiration and insight to enrich our customers daily lives.

We are a global company with an entrepreneurial spirit. We are dreamers and inventors who are passionate about the positive impact Audible can make for our customers and our neighbors.

This spirit courses throughout Audible, supporting a culture of creativity and inclusion built on our People Principles and our mission to build more equitable communities in the cities we call home.

BASIC QUALIFICATIONS

  • BS in Cybersecurity, Computer Science, or other relevant degree
  • 6+ years of experience in cyber and information security functions, especially in areas including Governance, Risk and Controls (GRC), Privacy, insider threat, business information security, identity and access management, third party risk, incident response, threat modeling
  • 2+ years of experience in an information security leadership role
  • Knowledge in navigating risk mitigation and risk issue management, policy and standards, security frameworks (e.g. NIST, ISO, etc.

managing a GRC function, and business information security / risk officer function

  • Experience in web and mobile application security, and cloud technologies threats and risks
  • Experience in written and verbal communication
  • Experience in mentoring a non-tech community on complex technical issues or ambiguous technical challenges

PREFERRED QUALIFICATIONS

  • MS in Cybersecurity, Computer Science, or other relevant degree
  • Ability to identify security issues and risks, and develop mitigation plans or solutions
  • Knowledge of web and mobile application security, and cloud technologies, common vulnerabilities, attacks, and mitigation methods
  • Demonstrated experience using communication skills to advocate security for both technical and non-technical audiences
  • Experience in driving large scale, cross-organization initiatives
  • Sharp analytical abilities and proven innovation skills to unblock adoption of security mechanisms
  • Relevant industry certifications (e.g., CISSP, SANS / GIAC, CISA, OSCP / OSWA / OSWE, AWS)

Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.

For individuals with disabilities who would like to request an accommodation, please visit https : / / www.amazon.jobs / en / disability / us .

20 hours ago
Related jobs
Promoted
Capital One
Nutley, New Jersey

This position – Senior Manager, Cyber Risk and Analysis – will play a high impact role in enhancing the methodology and practices for how the organization assesses cybersecurity and technology risk. West Creek 3 (12073), United States of America, Richmond, VirginiaSenior Manager, Methodologies and P...

Promoted
EisnerAmper
Woodbridge Township, New Jersey

A Senior Manager of Settlement Administration & Business Development will be responsible for directing and implementing EisnerAmper's national marketing and growth initiatives in the class action, mass tort and mass arbitration markets by performing a variety of duties related to identifying, develo...

Promoted
Capital One
Kearny, New Jersey

This position – Senior Manager, Cyber Risk and Analysis – will play a high impact role in enhancing the methodology and practices for how the organization assesses cybersecurity and technology risk. West Creek 3 (12073), United States of America, Richmond, VirginiaSenior Manager, Methodologies and P...

Promoted
Deloitte
Morristown, New Jersey

Do you enjoy building new client relationships to grow an already existing and successful federal tax practice? Are you ready to make a greater impact on organizations by having the right people on your team to combine tax consulting solutions and innovative technology that align the tax function wi...

Promoted
Capital One
Rutherford, New Jersey

Center 3 (19075), United States of America, McLean, VirginiaSenior Manager, Enterprise Services Issues & Events (ES Risk)Enterprise Services Risk (ESR) Senior Managers are experienced and progressive individuals that operate within a highly collaborative team environment to deliver value-added risk ...

Promoted
Audible
Newark, New Jersey

As a Security Engineer II at Audible you will advocate for information security throughout all our software development and business processes. This role will be focused on managing risk across our business functions. Apply your security and business knowledge to drive secure and pragmatic improveme...

Johnson and Johnson
Raritan, New Jersey

Johnson & Johnson is seeking a passionate leader with an interest in working within the life science industry for the Senior Manager, Business Information Security, CBT This role can be based in New Brunswick, NJ ; Raritan, NJ or Remote US. Support the strategy for embedding cyber security into...

Bristol Myers Squibb
New Brunswick, New Jersey

The Senior Manager, Strategy & Business Excellence (SBE) Analytics will work directly with the Associate Director, SBE Analytics to develop analytic tools and data science capabilities in support of the GPS Strategy & Business Excellence (SBE) organization and end-to-end planning activities within G...

Prudential Financial
Newark, New Jersey

Developing robust reporting and tracking mechanisms for key risk indicators across top risks, emerging risks, and third-party risks. Help lead the implementation of the Enterprise operational risk framework across PGIM Private Capital (PPC) and ensure compliance with operational risk policy requirem...

CVS Health
Work from home, NJ, US
Remote

Through the collaboration with key teams and business units, the senior manager will develop financial modeling to support pharmacy new business, partnerships, and net new opportunities and ventures. The Senior Manager of Pharmaceutical Strategic Business Insights will administer, manage, and optimi...