
Director, IT Security Risk
Posted 5 days ago

Posted 5 days ago
This is a fully remote position, open to applicants in Illinois.
• Direct the governance, risk, and compliance initiatives in cybersecurity to safeguard R1 and customer information assets, as well as technology infrastructure.
• Report directly to the Deputy CISO.
• Lead a team based in the US and India, consisting of approximately two to three direct reports and a wider team of around five employees.
• Formulate and implement the strategy and operational program for evaluating, monitoring, and mitigating cybersecurity risks posed by third parties and suppliers.
• Supervise customer cybersecurity questionnaires, conduct cyber risk assessments for customers, manage risk-exception processing, and maintain the cyber risk register.
• Establish and enhance scalable governance and third-party risk management capabilities, including procedures, documentation, controls, reporting, and accountability among stakeholders.
• Evaluate and refine processes for improved efficiency and effectiveness, utilizing automation where suitable.
• Collaborate with customers and internal relationship leaders to address cybersecurity inquiries and urgent business requirements.
• Work together with IT, Product Development, Procurement, Compliance, business leaders, and Security teams to mitigate risk and meet customer, contractual, regulatory, and operational obligations.
• Ensure conformity with regulatory mandates, industry standards, company policies, and cybersecurity best practices.
• Develop and uphold program procedures, standards, and essential documentation.
• Define and relay program performance, risk trends, priorities, and recommendations to senior management and stakeholders.
• Keep abreast of industry trends, emerging threats, and the evolution of cybersecurity governance and third-party risk practices.
• Promote security awareness, accountability, collaboration, and ongoing improvement.
• Manage relationships with external partners, including security vendors and consultants.
• Bachelor's degree or an equivalent combination of education and relevant experience.
• Over 10 years of experience in cybersecurity, technology risk, governance, risk and compliance, or related fields.
• At least five years in a leadership role involving people management.
• Proven experience in leading cybersecurity governance, risk, and compliance initiatives, especially with significant responsibilities in third-party cyber risk management.
• Experience in establishing a new cyber GRC or third-party risk capability from scratch, or significantly enhancing an existing program.
• Proficiency in managing customer cybersecurity questionnaires, risk assessments, exceptions, and risk-register processes.
• Experience in leading and developing teams across different regions, ideally with US- and India-based employees.
• Strong skills in customer engagement and stakeholder management.
• Ability to effectively collaborate with senior leaders, business partners, Procurement, Compliance, IT, Product Development, and Security teams.
• Capability to translate cybersecurity risks into business impacts, recommendations, metrics, and executive-level reporting.
• Experience in enhancing processes through standardization, workflow design, and automation.
• Strong judgment, organizational skills, responsiveness, and the ability to manage multiple priorities and quick-turnaround requests.
• CISM certification is required.
• CISSP or another relevant cybersecurity or risk certification is highly preferred.
• Experience in cybersecurity risk within healthcare, banking, financial services, or another highly regulated industry is preferred.
• Experience in operating within a global, acquisition-oriented, or rapidly evolving organization is preferred.
• Annual bonus plan with a target of 20.00%.
• Competitive benefits package.
• Opportunities for continuous learning, collaboration across teams, and exploration of new career paths.
• Meaningful work that contributes to communities served worldwide.
• Equal employment opportunity and a harassment-free workplace.
• Reasonable accommodations during the job application process for applicants with disabilities.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.