IT Risk Manager
Listed on 2026-01-01
-
IT/Tech
Cybersecurity, Information Security
Overview
This position is responsible for execution of a Technology first-line of defense (LOD1) risk and internal control program for Early Warning. The role will be required to execute with the company's Enterprise Risk Management Leadership around the structure of the three lines of defense program to ensure the consistency in the implementation and operationalization across the enterprise.
Essential Functions- Develop and maintain technology policies, standards, procedures, and guidelines.
- Ensure that the policy approval process is followed.
- Help maintain Technology's process inventory and internal control environment inventory.
- Act as point of contact for technology focused external and internal audits and assessments (SOC2, PCI DSS, & others).
- Effectively communicate technology and security related risks and vulnerabilities.
- Validate solutions being implemented are in line with currently approved policy, in conjunction with Technology and Security teams.
- Act as business-line liaison to Enterprise Risk Management and Operational Risk Management.
- Perform control testing of technology controls for correct implementation and operation.
- Create, facilitate, and manage risk identification and remediation processes.
- Ensure risk remediation plans exist and are sufficient; track remediation plans to completion and ensure remediation is on-time and sustainable; ensure action plans and remediation of issues by Risk Owner.
- Assist Technology teams in driving improvements in confidentiality, integrity, and availability.
- Identify and implement processes improvement efforts.
- Work with process and control owners to better define and implement control performance requirements.
- Support the company's commitment to risk management and protecting the integrity and confidentiality of systems and data
- Education and/or experience typically obtained through completion of a bachelor's degree in Computer Science, Business Administration, Finance or Accounting or equivalent experience.
- 5 or more years of related experience.
- Familiarity with ISO 27000, PCI DSS, NIST 800-53a, COBIT, FFIEC handbook, SOC2 Type II, GLBA, FCRA, FISMA.
- Effective communication, organization, and presentation skills.
- Background and drug screen.
- 5+ years work experience in security, governance, compliance, IT audit, information technology, or related.
- Certification in one of CISA, CISSP, CCSP, CRISC, or equivalent or ability to sit for one of the certifications within the first 12 months of hire.
- Experience with security-related technologies including firewalls, IDS, SIEM, vulnerability scanners, anti-virus, data leak prevention, two factor authentication, and VPN.
- Experience in managing business continuity and disaster recovery initiatives.
- Additional related education and/or experience.
The above job description is not intended to be an all-inclusive list of duties and standards of the position.
Physical RequirementsWorking conditions consist of a normal office environment. Work is primarily sedentary and requires extensive use of a computer and involves sitting for periods of approximately four hours. Work may require occasional standing, walking, kneeling, and reaching. Must be able to lift 10 pounds occasionally and/or negligible amount of force frequently. Requires visual acuity and dexterity to view, prepare, and manipulate documents and office equipment including personal computers.
Requires the ability to communicate with internal and/or external customers. Incumbents will follow instructions and perform other related duties as assigned by their supervisor.
The base pay scale for this position in:
Phoenix, AZ/ Chicago, IL in USD per year is: $116,000 - $145,000.
New York, NY/ San Francisco, CA in USD per year is: $139,000 - $174,000.
Additionally, candidates are eligible for a discretionary incentive plan and benefits.
This pay scale is subject to change and is not necessarily reflective of actual compensation that may be earned, nor a promise of any specific pay for any specific candidate, which is always dependent on legitimate factors considered at the time of job offer. Early Warning Services takes into consideration a variety of factors when determining a competitive salary offer, including, but not limited to, the job scope, market rates and geographic location of a position, candidate's education, experience, training, and specialized skills or certification(s) in relation to the job requirements and compared with internal equity (peers).
The business actively supports and reviews wage equity to ensure that pay decisions are not based on gender, race, national origin, or any other protected classes.
- Healthcare Coverage-Competitive medical (PPO/HDHP), dental, and vision plans as well as company contributions to your Health Savings Account (HSA) or pre-tax savings through flexible spending accounts (FSA) for commuting, health & dependent care expenses.
- 401(k) Retirement…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).