Head of Information Security Risk - Chief Risk Office

USD 215,000-290,000 per year
SENIOR
✅ On-site

Tech Stack

Audit @ 4 Communication @ 7 Security @ 8

Details

The Head of Information Security Risk will translate cybersecurity risk into executive insight and technical solutions. Reporting to the Head of Technology Risk within the Chief Risk Office, this role provides independent oversight, technical consultation, and credible challenge across the enterprise-wide information security program. The role operates across cybersecurity, risk management, governance, and strategy, serving as a senior cyber-risk partner to the Chief Information Security Office, Engineering, and Chief Technology Office.

Responsibilities

  • Serve as the primary Second Line advisor for cybersecurity-related risks and lead independent oversight and credible challenge of First Line of Defense activities.
  • Evaluate and consult on the design and operating effectiveness of security programs and controls, particularly across complex, high-risk, or enterprise-scale technology initiatives.
  • Review and challenge security-driven programs and initiatives to ensure alignment with enterprise risk appetite, industry control frameworks, and regulatory expectations.
  • Partner with Information Security, CISO, ERM, and Engineering teams to enhance risk awareness, accountability, and control ownership.
  • Identify root causes of control failures, security incidents, or systemic weaknesses and support actionable, preventative recommendations.
  • Prepare and present risk oversight materials to senior leadership committees, internal audit, the Board of Directors, and regulatory bodies as required.
  • Advise senior leaders on emerging threats, evolving regulatory requirements, and industry best practices.
  • Attract, hire, and manage a team of technical risk professionals focused on identifying and measuring threat-actor-initiated risks and risk scenarios affecting the confidentiality, integrity, and availability of information systems.

Requirements

  • Bachelor's degree required.
  • 10+ years of experience in one or more technical information security disciplines, such as security architecture, penetration testing, application security, or cyber defense.
  • Demonstrated experience operating within an independent oversight function as part of a Risk, Information Security, or Architecture team.
  • Strong understanding of cybersecurity frameworks, including NIST CSF, NIST 800-53, TLPT/TIBER-EU, MITRE ATT&CK, ISO 27001, COBIT, and CIS.
  • Experience interacting with Boards, regulators, internal audit, and/or executive governance forums.
  • Authorized to work in the United States.
  • Relevant technical or professional certifications are preferred, such as GIAC GPEN/GDAT, CREST, FAIR, CISSP, CISM, CRISC, or CISA.
  • Experience in regulated industries, such as financial services, is preferred.
  • Strong understanding of cloud security, application security, identity and access management, and cyber resilience.
  • Familiarity with enterprise risk management methodologies and risk appetite frameworks.
  • Strong analytical and critical-thinking skills, executive-level communication and presentation skills, ability to influence without direct authority, strategic mindset, attention to detail, high integrity, and independent judgment.

Benefits

Benefits may include merit increases, incentive compensation for exempt roles, paid holidays, paid time off, medical, dental, vision, short- and long-term disability benefits, 401(k) matching, life insurance, and wellness programs.

More jobs at Bloomberg

Similar jobs