The prime responsibilities of the Information Security Manager (ISM) Enterprise Technology - Infrastructure Platforms is to identify, quantify and proactively address security issues and changes in the businesses risk profile.
The ISM will focus on improving the end-to-end risk posture for the assigned Line of Business (LOB) or product group, and ensure appropriate controls are implemented across the technology landscape to operate within risk appetite.
This includes a threat driven approach to enable secure-from-the-start adoption of emerging technology and application development.
The ISM will be expected to drive effective risk & controls management and support the technology teams through identification of control weaknesses and recommendations for improved security, articulation of the business impact and associated risk, and proactive remediation of risk.
Job responsibilities Build and cultivate a security focused culture through partnership and collaboration with the business and technology teams to deliver customer value and improve security posture Ensure technology risk impacting the business is effectively identified, quantified, communicated and managed, including recommendations for resolution and identifying the root cause / key themes Proactively monitoring Key Risk Indicators to identify non-compliance and assist in remediation with compensating controls to address security, risk and control gaps Serve as a point of escalation and subject matter expert for IT Risk and Cyber domains, including vulnerability management, data protection, cloud and application security Collaborate with team members and stakeholders on firm-mandated, cross-LOB, and regional audits Interact with Technology Leadership, Product Owners, and Application Development teams on an on-going basis for business as usual risk activities, reporting and project initiatives Maintain an understanding of Technology teams strategies, product roadmaps and key investment programsRequired qualifications, capabilities, and skills Security and / or Risk Management and / or Corporate Technology with 5+ years of experience with an aptitude in application and platform security Bachelor's degree in computer science, information technology, or related field is preferred, but not required Industry-recognized information security certifications are preferred, but not required Strong written and verbal communication skills with ability to effectively communicate and present security risk concepts with business and technology partners Strong personal leadership, collaboration, bias for action and experience working within fast paced, complex and high performing Digital / Agile / Scaled Agile teams Strong analytical skills including solving and communicating complex problems, data analytics, measurement and reporting needed to drive continuous improvement Knowledge and experience with Cloud technology (AWS, Google, Azure), virtual environments, or infrastructure management.
Certifications are a plus Apply working experience in multiple security domains (e.g., application security, vulnerability reduction, data protection, encryption, logging and monitoring, network security)Preferred qualifications, capabilities, and skill Experience working in regulated industries, in particular leveraging technology standards, frameworks, compliance, and industry recognized best practice / standards (e.
g. ITIL, NIST, ISO, PCI, SOC) Experience working with diverse global teams to deliver strategic initiatives and commitments, ideally leveraging product and Agile principles Collaborate on internal and external technology audits, CCOR Operational Risk Management deep dives and testing, and the ability to advocate on behalf of subject matter experts Expertise in Office 365 with proficiency manipulating data in Excel