Responsibilities
- Develop and manage security risk processes that align with enterprise risk management, covering identification, assessment, prioritization, and tracking.
- Keep an updated, practical security risk register that supports business decisions rather than serving as a compliance formality.
- Ensure leadership teams regularly review and understand the organization's security risk status.
- Translate technical security findings into business impact terms, including operational, financial, and reputational consequences.
- Produce straightforward risk reports for senior leadership and executives, including visual risk heat maps and progress tracking.
- Assist in preparing cyber risk disclosures for board-level review in coordination with senior technology leaders.
- Partner with business and technology leads to assign ownership of risks, define mitigation plans, and monitor resolution timelines.
- Review and challenge decisions to accept risk, ensuring they are documented, justified, and time-limited.
- Monitor progress on risk mitigation actions and escalate unresolved or delayed items appropriately.
- Detect recurring risk trends and present them as strategic concerns for executive leadership.
- Lead the evaluation and ongoing review of third-party and vendor security risks based on their criticality.
- Collaborate with procurement teams to integrate cybersecurity standards into vendor onboarding and contract renewal processes.
- Track and report on overreliance on specific technology providers and associated cyber dependencies.
- Support business continuity and disaster recovery planning by aligning cyber recovery priorities with business impact.
- Engage in incident follow-up activities to identify systemic risks and update the risk register with lessons learned.
- Help interpret threat intelligence and assess how emerging cyber threats could affect business operations.
- Coordinate with the GRC team to ensure compliance activities are driven by risk and that audit outcomes update risk records.
- Work with security engineering and operations teams to understand vulnerabilities and express technical risks in business terms.
- Assist senior security leadership in unifying risk, compliance, and operational functions into a coordinated security strategy.
Work Arrangement
Hybrid
Other
- We aim to foster an inclusive workplace where all employees feel valued and empowered to contribute meaningfully.
- Applicants are encouraged to disclose if they require accommodations during the hiring process due to a disability.