Information Security Risk Manager

  • Westborough
  • The Judge Group Inc.
<b>Location: </b> Westborough, MA<br> <b>Salary: </b> Negotiable<br> <b>Description: </b> Our client is currently seeking a Information Security Risk Manager/<b>HYBRID 4 days ON SITE </b>one off site at Metro-West/Boston location<br>Reporting to the Director of Operational Risk, Information Security & Vendor Management, the Information Security Risk Manager is responsible for assisting the Director of Operational Risk, Information Security & Vendor Management with maintaining and continually enhancing the Bank's information security and second line testing programs. <br>In particular, responsibilities include the development, coordination, implementation, governance, and ongoing management of enterprise-wide policy and controls. <br>Responsibilities: <br> <br>&bull;Utilize industry experience and knowledge to provide expertise and support to ensure the Bank's information security program remains in compliance with applicable standards and regulations, including evolving data privacy regulations. <br> <br>&bull;Adhere/enhance control testing processes to ensure information security, risk, and vendor management policies are adhered to. <br> <br>&bull;Assist with the management of cyber security compliance functions including reporting on gaps, variances, and the assessment and disposition of <b>cyber risk</b>. Assist with completion and maintenance of the Bank's FFIEC Cybersecurity Assessment Tool and IT Risk Assessment. <br> <br>&bull;Perform assessments of the current information security and Information Technology framework and develop guidance that addresses gaps. <br> <br>&bull;Assist with development, evaluation, and adherence to IT, risk, and information security policies, standards, and procedures. <br> <br>Socialize policy & control recommendations to stakeholders across the enterprise in order to gain acceptance. <br> <br> &bull;Support the completion of risk assessments of IT processes and products to ensure that they align with Bank policies and objectives. <br> <br>&bull;Participate in information security, vendor management, and risk related projects and initiatives. <br> <br>&bull;Assist with the collection and review of vendor due diligence materials in line with <b>GLBA and TSP regulatory guidance. </b> <br> <br>&bull;Assist with tracking and resolution of internal audit and examination findings related to risk, information security, and vendor management. <br> <br>&bull;Maintain and effectively utilize the Bank's <b>Enterprise Risk Management </b>Software System. <br> <br>&bull;Assist with the annual facilitation of Incident Response tabletop exercises. <br> <br>&bull;Organizes daily department activities and supervises Information Security staff. Conducts performance reviews and provides for ongoing guidance, training, and direction to staff in developing and implementing plans and objectives. <br> <br>&bull;Stays up to date on industry trends, represents the Bank through active participation in community and industry organizations, and participates in user groups and conferences, as needed. <br> <br>&bull;Performs related and unrelated duties as may be required. <br> <br> Qualifications: <br> <br>&bull;5+ years of experience in Bank-specific information security, risk, and/or audit areas <br> <br>&bull;Bachelor's degree <br> <br>&bull;Comprehensive knowledge of technology auditing process,<b> GLBA compliance requirements</b>, and technology risk assessments <br> <br>&bull;Internal Audit, IT Assurance, and/or FDIC/OCC Regulatory experience required <br> <br>&bull;Working knowledge of applicable laws, regulations, and standards relating to security, data privacy, and vendor management <br> <br>&bull;Knowledge of bank operations and bank technology applications <br> <br>&bull;Effective communicator, relationship builder, and advocate for sound risk mitigation practice<br> <br>&bull;Strong organizational skills <br> <br>&bull;Management and supervisory experience required<br> <ul> </ul> <br>*Community banking (small to mid size Banks)<br> <br>*Interaction with regulators Info Secuirity (such as Patching, Vulnerability scanning, Systems) <br> <br> <b>Contact:</b> psalvatore@judge.com<br> <br>This job and many more are available through The Judge Group. Find us on the web at www.judge.com<img src="https://counter.adcourier.com/YmJnZW5lcmljLjAzODg4LjEyNTI0QGp1ZGdlY29tcC5hcGxpdHJhay5jb20.gif">