The Lead Information Security Officer for Asset Management is a critical leadership position responsible for defining, implementing, and overseeing the comprehensive information security and cybersecurity risk posture specifically within the Asset Management Private business.
Requirements
- 5+ years of progressive experience in Multi domain Information Security experience such as vendor security, application security, vulnerability management, data loss prevention, data encryption, and infrastructure security.
- Expert knowledge of global financial regulations (e.g., SEC, FINRA, GDPR, CCPA) and proven experience applying risk management methodologies such as FAIR (Factor Analysis of Information Risk) or similar frameworks.
- Proven ability to build, mentor, and lead high-performing global teams of security professionals.
- Proven track record involving collaboration with engineering, technology, second line risk functions and audit partners to deliver projects and facilitate resolution of audit issues within committed timelines.
- Exceptional written and oral communication skills, with the ability to articulate complex technical risks and solutions clearly to both technical and executive audiences.
- Expertise in performing risk assessments, identifying gaps in compliance with information security policies, and recommending effective mitigation strategies.
- Familiarity with leading security standards and frameworks such as NIST, OWASP, SANS Top 20, PCI DSS, and CIS Controls.
- Expertise in Technology Risk data analytics (metrics reporting and dashboarding) and Reviewing Software Development Lifecycle best practices e.g., code reviews, vulnerability scan report analysis to advise application development teams on for secure practices and frameworks, and other application security best practices
Benefits
- Competitive salary
- Benefits, wellness and personal finance offerings and mindfulness programs
- Training and development opportunities and firmwide networks