Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Audit @ 4
Security @ 8
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
The Information Security Risk Oversight Lead will translate cybersecurity risk into executive insight and action. Sitting in the Company’s Second Line of Defense within the Chief Risk Office and reporting directly to the Head of Technology Risk, this role provides independent oversight and credible challenge across the firm’s enterprise-wide information security program. The role operates at the intersection of technology, risk management, cybersecurity, governance, and strategy, partnering with the Chief Information Security Office, Engineering, and CTO teams to ensure cyber risks are identified, measured, monitored, and aligned with the firm’s risk appetite.
Responsibilities
- Serve as the primary Second Line risk advisor for cybersecurity-related risks and lead independent oversight and credible challenge of First Line of Defense activities.
- Identify and measure threat-actor-initiated risks and risk scenarios that may impact the confidentiality, integrity, and availability of information systems.
- Evaluate the design and operating effectiveness of security controls, particularly across complex, high-risk, or enterprise-scale technology initiatives.
- Quantify risk and control posture to support executive decision-making through scenario analysis and metrics, including KRIs, KPIs, SLA/SLOs, and ALE.
- Review and challenge security-driven programs and initiatives to ensure alignment with enterprise risk appetite, industry control frameworks, and regulatory expectations.
- Partner closely with Information Security and Engineering teams to enhance risk awareness, accountability, and control ownership.
- Identify root causes of control failures, security incidents, or systemic weaknesses and support the development of actionable, preventative recommendations.
- Prepare and present risk oversight materials to senior leadership committees, internal audit, the Board of Directors, and regulatory bodies as required.
- Act as a strategic thought partner to senior leaders by advising on emerging threats, evolving regulatory requirements, and industry best practices.
Requirements
- Bachelor’s degree required.
- 10+ years of experience in Information Security.
- 10+ years of experience in IT or Cyber Risk Management.
- Demonstrated experience operating within a Second Line of Defense or independent risk oversight function.
- Strong understanding of cybersecurity control frameworks, including NIST CSF, NIST 800-53, MITRE ATT&CK, ISO 27001, COBIT, and CIS.
- Experience interacting with Boards, regulators, internal audit, and/or executive governance forums.
- Authorized to work in the United States.
Preferred Qualifications
- Relevant professional certifications, such as FAIR, CISSP, CISM, CRISC, or CISA.
- Experience in regulated industries, such as financial services.
- Strong understanding of cloud security, application security, identity and access management, and cyber resilience.
- Familiarity with enterprise risk management methodologies and risk appetite frameworks.
Core Competencies
- Strong analytical and critical thinking skills with the ability to provide constructive challenge.
- Executive-level communication and presentation skills.
- Ability to influence without direct authority.
- Strategic mindset with strong attention to detail.
- High integrity and independent judgment.
Compensation and Benefits
- Salary range: $215,000–$290,000 USD annually, plus benefits and bonus.
- Benefits may include merit increases, incentive compensation for exempt roles, paid holidays, paid time off, medical, dental, vision, short- and long-term disability benefits, 401(k) match, life insurance, and wellness programs.
More jobs at Bloomberg
Senior Data Management Professional - Company Financial Market Data
Bloomberg · Princeton, United States
USD 110,000-190,000 per year
Senior Data Management Professional – Macro Industries – ESG TPD/GOVS
Bloomberg · New York City, United States
USD 110,000-190,000 per year
Senior Data Management Professional - Data Product Owner - Entities
Bloomberg · New York City, United States
USD 110,000-190,000 per year
Data Quality Analyst – Enterprise Data
Bloomberg · New York City, United States
USD 110,000-225,000 per year
Senior Interaction Designer - Quant & Analytics
Bloomberg · San Francisco, United States
USD 160,000-210,000 per year
Similar jobs
Executive Support Senior Program Manager, Tech Advisor
Anthropic · Washington, United States, Boston, United States, New York City, United States, San Francisco, United States, Seattle, United States
USD 245,000-305,000 per year
Engineering Manager, Infrastructure
Stripe · New York City, United States, South San Francisco, United States, Seattle, United States
USD 236,000-354,000 per year
Security Engineer, Bridge
Stripe · United States, New York City, United States, San Francisco, United States
USD 196,900-343,600 per year
Sr. Security Engineer - GRC Fintech & Financial Services
SpaceXAI · Washington, United States, New York City, United States, Palo Alto, United States
USD 152,000-258,000 per year
Staff+ Software Engineer, Platform Distribution
Anthropic · New York City, United States, San Francisco, United States
USD 405,000-485,000 per year
IT Support Engineer, Application Administrator
Anthropic · New York City, United States, San Francisco, United States
USD 230,000-265,000 per year
Software Engineer, Infrastructure, Interpretability
Anthropic · New York City, United States, San Francisco, United States
USD 320,000-485,000 per year
Data Center Operations Lead - Partner Site Operations
Anthropic · San Francisco, United States
USD 320,000-405,000 per year