Search jobs > Columbus, OH > Cyber risk manager

Cyber Risk Manager

Huntington National Bank
Columbus, OH
Full-time

Description

Huntington is on a journey to move applications and infrastructure computing to leverage various Cloud provider services and deploy a hybrid cloud and on premises network.

This cyber risk position is tasked with partnering with the cyber security segment providing risk support, control and metric design, and overall challenge on various technical implementations.

This resource will help ensure cyber offerings are following defined governance processes, standards, and control requirements.

As a Cyber Security Risk Manager, you'll be a subject matter expert in cyber security solutions that will balance the need for speed and flexibility of cloud and on premises infrastructure while ensuring Huntington is protected against ongoing and potential security threats.

Seeking an individual who has supported financial services and helped assess and develop their cloud strategy, information security / cybersecurity and IT risk management programs against regulatory requirements and industry best practices.

This person will be influential in our transition to securing our cloud computing and on premises platforms and help build compliant governance programs.

Responsibilities :

  • Provide oversight and challenge to technical configurations, solutions and implementation of cyber security tools, systems, and platforms.
  • Evaluate effective of controls and escalate as appropriate.
  • Direct self-monitoring and testing activities to ensure that they are performed in accordance with Corporate Risk Management requirements.
  • Evaluate the adequacy and effectiveness of enterprise and regulatory controls and the resulting risk and control self-assessments.
  • Deliver timely escalation of all issues requiring attention to senior management.
  • Work with business segment management to ensure that the overall risk function is effectively supporting strategic goals.
  • Collaborate with audit / business segment / corporate risk to address issues with plausible action plans and target dates.
  • Act as the central point for receipt and distribution of important risk information for the business segment and reciprocate the flow of information back to corporate risk management.
  • Ensure business segment adheres to corporate and business unit policies and procedures.
  • Must be aware of and keep abreast of Third-Party risk associated with assigned business segment.

Basic Qualifications :

Bachelor’s degree in computer science, cyber security, information technology, computer engineering or equivalent. Five years of any of the combined experience below in Cyber Security, Audit and Risk Management

  • 2. years experience Anti-Virus / Malware.
  • 2 years’ experience in network security, firewalls, WAF, Tufin or similar.
  • 2 years’ application and network segmentation.
  • 2 year’s breach and attack simulation with tools like MITRE ATT&CK, AttackIQ or similar.
  • 2 years in threat management, vulnerability management
  • 2 years using SAST, DAST, IAST, MAST or SCA tools.
  • 2 years as a security engineer or architect.

Preferred Qualifications :

  • Excellent communication skills required to negotiate internally, often at a senior level.
  • Some external communication may be necessary.
  • Understanding of FFIEC guidance, COBIT and NIST framework
  • Willingness to learn, able to learn on the job and a desire to continually learn and develop new technical skills Strong written and oral communication skills.
  • Organized, responsive, and highly thorough problem solver demonstrable cyber risk knowledge based on working in real-world environments & situations.
  • Understanding of security requirements, best practices, and execution in various cloud implementation scenarios : IaaS, PaaS, SaaS Mid-level professional with 5-10 years of experience in consulting, financial services, technology / fintech or government regulatory agency with an IT risk-related role.
  • Master’s degree or relevant professional qualifications with Risk / Security management.
  • CISSP, CISM, CRISC, CISA, GIAC, CIPP / US or other security / privacy certifications preferred, but not required.

LI-Hybrid

LI-SG1

Exempt Status : (Yes not eligible for overtime pay) ( No eligible for overtime pay)

Workplace Type :

Huntington is an equal opportunity and affirmative action employer and is committed to providing equal employment opportunities for all regardless of race, color, religion, sex, national origin, age, disability, sexual orientation, veteran status, gender identity and expression, genetic information, or any other basis protected by local, state, or federal law.

Tobacco-Free Hiring Practice : Visit Huntington's Career Web Site for more details.

Agency Statement : Huntington does not accept solicitation from Third Party Recruiters for any position

30+ days ago
Related jobs
Huntington National Bank
Columbus, Ohio

This cyber risk position is tasked with partnering with the cyber security segment providing risk support, control and metric design, and overall challenge on various technical implementations. As a Cyber Security Risk Manager, you'll be a subject matter expert in cyber security solutions that will ...

Promoted
Newberry Group
Columbus, Ohio

Newberry Group's Public Sector Division is seeking Real Time Cyber Analysts with the expertise to support a 24/7 Cyber Network Defense (CND) Operation for Department of Defense networks in Columbus, OH. This includes performing real-time cyber threat intelligence analysis, correlating actionable sec...

Promoted
Northwest Bank
Columbus, Ohio

Business Intelligence Analyst, Data Analyst, Business analyst or equivalent And. Business Intelligence Analyst will work with Credit Admin / Credit Risk / Model Dev team leaders and specialists to understand business goals and needs and translate these into requirements and solution designs with a f...

Promoted
STRS Ohio
Columbus, Ohio

The State Teachers Retirement System of Ohio (STRS Ohio) is seeking a Business Systems Analyst 1, 2 or 3 to join the ITS Investment Services team. The Business Systems Analyst 3 will coach, train, and mentor others in addition to leading key technology initiatives across the organization. Monitor tr...

Promoted
Leidos Inc
Whitehall, Ohio

The Leidos Digital Modernization sector is continuously looking for cleared Cyber Security Analysts who are interested in joining the DISA GSM-O II program in Columbus, OH. In this position, you will be joining a team providing 24x7 cybersecurity monitoring services for Department of Defense network...

Promoted
Ohio State University Wexner Medical Center
Columbus, Ohio

This position resolves errors and completes root cause analysis; works closely with revenue cycle analyst and end-users to identify optimization opportunities and works with end-users to prevent errors. ...

Promoted
V3 Companies
Columbus, Ohio

We're on the hunt for a Structural Project Manager who's ready to join our Columbus, OH office and take the lead on some of the most exhilarating projects on the drawing board-and beyond!. Elevate Your Career as a Structural Project Manager with Our Team!. Project management mastery, steering projec...

Promoted
Centric Consulting
Columbus, Ohio

At Centric Consulting, we've cultivated a unique approach to business. Our business is built on three fundamental principles: Enjoy the people you work with, have fun, and do great work. Founded in 1999 with a remote workforce, we combine the benefits of experience, flexibility, and cost efficiency ...

Promoted
Upstart Network, Inc.
Columbus, Ohio

Marketing Operations Manager, Auto Retail**. As the **Marketing Operations Manager** at Upstart, you will **own the strategy and execution of our marketing automation platform with a focus on lead management, email automation and database segmentation. B2B marketing experience either in marketing op...

Promoted
Huntington Bancshares Inc
Columbus, Ohio

Seeking an individual who has supported financial services and help assess and help develop their cloud strategy, information security/cybersecurity and IT risk management programs against regulatory requirements and industry best practices. Develop and update best practice documentation to support ...