
Senior Risk Manager – Information Security
Posted Jul 22

Posted Jul 22
This is a fully remote position, open to applicants in United States.
• Take charge of the enterprise risk management framework, which includes risk appetite statements, risk registers, and risk reporting schedules.
• Conduct regular risk assessments across various business functions, pinpointing emerging threats and assessing the effectiveness of current controls.
• Develop and enhance risk taxonomy, scoring methods, and heat maps in accordance with industry best practices (e.g., COSO ERM, ISO 31000).
• Facilitate the integration of risk management into strategic planning, product development, and change management processes.
• Create and deliver risk reports for senior leadership, the Board, and audit/risk committees, converting complex risk data into actionable insights.
• Establish and monitor key risk indicators (KRIs) while ensuring the prompt escalation of critical risk events.
• Oversee the maintenance of risk management policies, standards, and procedures; lead policy review cycles and updates.
• Act as a trusted advisor to business unit leaders on risk-related issues, fostering a risk-aware culture.
• Collaborate with IT Security, Legal, Privacy, and Internal Audit teams on integrated risk and control initiatives.
• Assist in third-party and vendor risk management efforts in coordination with Procurement and IT.
• Lead, mentor, and develop a team of risk analysts and specialists within the GRC function.
• Set objectives for the team, manage performance, and promote a culture of continuous improvement and professional growth.
• Propel process automation and tooling enhancements to improve the efficiency and scalability of the risk program.
• Coordinate risk management contributions to internal and external audits, regulatory reviews, and compliance evaluations.
• Keep abreast of the evolving regulatory landscape and evaluate its implications for the organization's risk profile.
• Over 8 years of experience in risk management, GRC, or a related field.
• More than 3 years in a leadership role managing people.
• Extensive knowledge of risk management frameworks (COSO ERM, ISO 31000, NIST RMF, or similar).
• Proven experience in managing an enterprise risk program within a mid-to-large organization.
• Bachelor’s degree in business, Finance, Information Systems, or a related discipline.
• Professional certifications such as CRISC, CISM, CGEIT, or their equivalents.
• Experience in regulated sectors (financial services, healthcare, technology).
• Familiarity with GRC platforms (e.g., ServiceNow GRC, Archer, OneTrust, LogicGate).
• Employee ownership
• Health insurance
• 401k with matching contributions
• Disability insurance
• Paid time off
• Growth opportunities
Lime
Threatscape
GFT Technologies
BeyondTrust
Get handpicked remote jobs straight to your inbox weekly.