1

Cyber Risk Assessment Jobs in Massachusetts (NOW HIRING)

Includes design of the cyber organization, governance, and risk assessments. Qualifications: Required: * BA/BS Degree in Computer Science, Cyber Security, Information Security, Engineering ...

Includes design of the cyber organization, governance, and risk assessments. Qualifications Required: * BA/BS Degree in Computer Science, Cyber Security, Information Security, Engineering ...

Cyber Data Protection Manager

Boston, MA ยท Remote

$120K - $163K/yr

If so, consider joining Deloitte & Touche LLP's growing Cyber Risk Digital Trust & Privacy practice ... Serve as a subject matter expert and trusted advisor to clients, helping them assess strategic and ...

Bitsight is a cyber risk management leader transforming how companies manage exposure, performance ... Conduct quality assurance on consultant deliverables, assessments, and client communications before ...

Bitsight is a cyber risk management leader transforming how companies manage exposure, performance ... Conduct quality assurance on consultant deliverables, assessments, and client communications before ...

Bitsight is a cyber risk management leader transforming how companies manage exposure, performance ... assessment methodologies * Collaborate with the product and engineering organizations to align ...

Bitsight is a cyber risk management leader transforming how companies manage exposure, performance ... Conduct quality assurance on consultant deliverables, assessments, and client communications before ...

Bitsight is a cyber risk management leader transforming how companies manage exposure, performance ... Conduct quality assurance on consultant deliverables, assessments, and client communications before ...

Showing results 21-40

Cyber Risk Assessment information

What is the difference between Cyber Risk Assessment vs Cyber Security Analyst?

AspectCyber Risk AssessmentCyber Security Analyst
Primary FocusIdentifying and evaluating cybersecurity risks and vulnerabilitiesMonitoring, detecting, and responding to security threats
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CEH, CISSP
Work EnvironmentRisk management teams, consulting firms, security departmentsSecurity operations centers, IT departments, incident response teams
ResponsibilitiesRisk analysis, vulnerability assessments, complianceThreat detection, incident response, security monitoring

While both roles involve cybersecurity, Cyber Risk Assessments focus on evaluating potential risks and vulnerabilities to inform security strategies, whereas Cyber Security Analysts actively monitor and respond to ongoing security threats. Understanding these differences helps organizations assign the right roles for comprehensive cybersecurity management.

What is a cyber risk assessment?

A cyber risk assessment is a process used to identify, evaluate, and prioritize potential threats and vulnerabilities in an organization's information systems. It helps organizations understand the potential impact of cyber threats and determine the likelihood of such events occurring. By conducting a cyber risk assessment, businesses can implement appropriate security controls and strategies to mitigate risks, comply with regulatory requirements, and protect sensitive data from cyberattacks. Regular assessments are essential to adapt to evolving threats and maintain a strong cybersecurity posture.

What are some common challenges faced by professionals in cyber risk assessment, and how can they be addressed?

Professionals in Cyber Risk Assessment often encounter challenges such as rapidly evolving threat landscapes, keeping up with regulatory changes, and ensuring clear communication of technical risks to non-technical stakeholders. To address these, staying current with industry trends through continuous learning, leveraging robust risk assessment frameworks, and developing strong communication skills are essential. Additionally, collaborating closely with IT, compliance, and business units helps ensure comprehensive and effective risk management.

What are the key skills and qualifications needed to thrive as a cyber risk assessor?

To thrive as a Cyber Risk Assessor, you need a strong understanding of cybersecurity principles, risk management frameworks, and relevant regulations, often backed by a degree in information security or related certifications like CISSP or CISA. Familiarity with security assessment tools, vulnerability scanners, and risk analysis platforms is typically required. Analytical thinking, attention to detail, and effective communication are vital soft skills for accurately identifying threats and conveying risks to stakeholders. These skills and qualities are crucial for protecting organizational assets and ensuring compliance in an evolving threat landscape.
What are popular job titles related to Cyber Risk Assessment jobs in Massachusetts? For Cyber Risk Assessment jobs in Massachusetts, the most frequently searched job titles are:
What job categories do people searching Cyber Risk Assessment jobs in Massachusetts look for? The top searched job categories for Cyber Risk Assessment jobs in Massachusetts are:
What cities in Massachusetts are hiring for Cyber Risk Assessment jobs? Cities in Massachusetts with the most Cyber Risk Assessment job openings:

Head of Cybersecurity & Information Security Oversight (SVP)

The Security Executive Council

Boston, MA โ€ข On-site

$225 - $337.50/hr

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted 5 days ago


Job description

Head of Cybersecurity & Information Security Oversight (SVP) Organization:

State Street

Description:

About the job

SVP, Head of Cyber & Information Security Oversight

Why this role is important to us

Enterprise Technology Risk Management (ETRM) is responsible for thought leadership, oversight, monitoring, and advisement around the discovery and remediation of Cyber and Technology Risks across the enterprise.

ETRM plays an important role in the overall success of the organization, and our mission is to establish a world class Technology Risk Management program that aligns business and technology risk to enable effective decision making. The organization is going through a significant transformation, and you will lead key cyber risk assessments on material projects and ensure the identified risks are being prudently managed. This position will also include providing thought leadership and support to both your peers in ETRM and your stakeholders in the business and corporate areas. You will need to periodically participate in meetings with our key regulators and provide support and advice to your stakeholders during regulatory exams and regulatory finding validations.

Who We Are Looking For

We are looking for a proven Cyber and Information Security Risk Leader with more than 15 years of experience in the financial services and/or technology industry. The qualified candidate will have a combination of:

  • Deep Technical Experience: Handsโ€‘on Cybersecurity leader in roles as a CISO or CTRO at comparable organizations with a global footprint or at a Deputy CISO level in a Gโ€‘SIB. The candidate will be well versed in identifying, assessing, managing and monitoring cyber risks across several domains such as Identity and Access, Information Protection, Threat and Vulnerability Management, Cyber Incident and Response, Application security, Secure configuration, Security Architecture and Cyber Risks related to Third parties.
  • Strong Business background: Proven capability for translating this technical understanding into business risk to be able to provide guidance to and challenge senior level IT executives such as the group level State Street CIO, CISO and CTO. The individual will also serve as an advisor to the Head of ORM, Group CRO, regional CROs and the State Street Board of Directors to manage Cyber Risk adequately.
  • Strong Executive Presence: effectively communicate with senior executives at the EVP and Cโ€‘level, the Board and with regulators globally to foster confidence in the Bankโ€™s risk management capabilities and to drive enhancements where needed. Candidates must demonstrate strong initiative, be able to perform well under pressure and be capable of managing multiple and diverse assignments.

The successful candidate will report into the Global Head of Technology and Cyber Risk, who reports to the Chief Operational and Technology Risk Officer within the Operational Risk Management second line function. They will lead, guide and mentor a team of seasoned ETRM Cyber risk professionals to provide Second Line of Defense (SLoD) oversight, review and challenge on Global Cybersecurity and Global Technology Services First Line Organization. The ETRM function is currently being enhanced, and the role is expected to provide significant expertise and experience to shape the Cybersecurity governance function, aligned to industry peers and leading practices.

What You Will Be Responsible For
  • Establish and Operate the global Cybersecurity Risk Oversight function in ETRM.
  • Be a risk advisor and challenge function to the State Street Global CISO function and program.
  • Establish State Streetโ€™s Cyber Risk Appetite, with corresponding policies and Metrics and thresholds, reporting breaches, escalating exceptions and challenging risk acceptances and provide guidance on improving the risk position to support the business.
  • Be an acknowledged thought leader in the industry, with a strong understanding of attributes of an effective Cybersecurity program at peer organizations.
  • Analytics and Reporting
  • Establish an analytics capability to provide cyber risk insights, leveraging AI for greater effectiveness.
  • Develop risk reports customized to the business needs of legal entities and regions to drive risk reduction in a costโ€‘effective way.
  • Cyber Risk Governance
  • Lead or coโ€‘Chair various senior governance forums like the Cybersecurity Risk Committee and the Vulnerability Governance Forum that manage Cybersecurity risk to State Street.
  • Communicate and drive effective implementation of ETRM risk management policies, framework, tools, guidelines and standards across the business ensuring cyber risks are identified and managed effectively.
  • Ensuring cyber risks and nonโ€‘compliance with internal and external standards are proactively identified, prudently managed, and effectively challenged.
  • Identifying/assessing/controlling/monitoring risks and supporting FLOD in planning/executing controls and additional compensating controls.
  • Review and challenge the first line cyber controls assurance program and the constituent cyber processes.
  • Provide challenge to the EVPs leading the Cyber Enterprise Processes and foster deeper and integrated FLOD/SLOD relationships and embedded, proactive risk management.
  • Advise FLOD in prioritization of risks, risk initiatives, risk mitigation alternatives.
  • Regulatory
  • Lead second line regulatory interaction for Cyber Risk with regulators, including the FCA/PRA, HKMA, MAS, APRA and ECB, including resolution of issues and concerns.
  • Be a thought leader for managing emerging Cybersecurity risks to provide credible risk management guidance to the regulators.
  • Consistent, Global Risk Management
  • Collaborate with and support regional and Business Unit Risk Management peers in matters related to cyber and information security risks.
  • Develop and deliver the ETRM Cybersecurity annual Book of Work (risk assessments, continuous monitoring, issues management and reporting) through the established risk leads within the team while leveraging the ETRM India GCC.
  • Coordinate across multiple risk types in Operational Risk Management, like Data Risk, Fraud and Thirdโ€‘Party Risk programs. Utilize available Enterprise Risk and Operational risk management tools (NBPRA, MRI, RCSA, KRIโ€™s, Incident data, Loss event data) in conjunction with other environmental changes to proactively monitor the control environment and identify and address potential weaknesses and/or gaps in a timely manner.
  • Keep abreast of new products, services, technologies and applications as well as their respective impact on the organizationโ€™s risk profile.
What We Value
  • Strong ability to collaborate effectively
  • This position requires interacting with โ€œCโ€ level suite, so superior communication, interpersonal, negotiation, presentation and intergroup skills are critical for success.
  • The ability to translate technical issues into risk terms that business can understand is necessary.
  • Experience with regulatory exams and responses is strongly desired.
  • Being an effective mentor and coach.
  • Ability to be a strong voice for review and challenge while continuing to maintain positive relationships with business stakeholders.
  • An ability to be a leader within their team, as well as being a leader amongst your peers.
Qualifications:
  • Education & Preferred Qualifications: Minimum 15 years of experience in the financial, and or technology industries, with at least 5 years in executive roles as a CISO, Deputy CISO or equivalent in a Gโ€‘SIB.
  • Advanced degree or undergraduate degree in technology / cyber disciple or equivalent.
  • Experience in first line cybersecurity operations.
  • CISSP or equivalent is required.
  • Working knowledge of industry and regulatory risk and control standards and frameworks such as FFIEC, DORA, NISTโ€‘CSF, 800โ€‘53, COBIT, CCM, and MITRE ATT&CK is expected.
Compensation:
  • Salary Range: $225,000 - $337,500 Annual โ€“ the range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.
  • Employees are eligible to participate in State Streetโ€™s comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, longโ€‘term disability, and other optional additional coverages; paidโ€‘time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performanceโ€‘based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain taxโ€‘advantaged savings plans.
#J-18808-Ljbffr