CRO - Information Security & Risk Oversight Lead Location New York Business Area Legal, Compliance, and Risk Ref # 10052405 Description & Requirements The energy of a newsroom, the pace of a trading ...
CRO - Information Security & Risk Oversight Lead Location New York Business Area Legal, Compliance, and Risk Ref # 10052405 Description & Requirements The energy of a newsroom, the pace of a trading ...
Governance, Risk, Compliance (GRC) Lead
New York, NY · On-site
$171K/yr
ABOUT THE ROLE Aaru is building out its governance, risk, and compliance function and is hiring its ... Customer trust and enterprise security review. Own the response to security questionnaires, due ...
Governance, Risk, Compliance (GRC) Lead
New York, NY · On-site
$171K/yr
ABOUT THE ROLE Aaru is building out its governance, risk, and compliance function and is hiring its ... Customer trust and enterprise security review. Own the response to security questionnaires, due ...
IT Systems Analyst - Cybersecurity, Risk & Compliance
Parsippany, NJ · On-site
$94K - $95K/yr
This role offers structured training and practical exposure to security, compliance, risk management, and enterprise system governance initiatives. Key Responsibilities: * Assist in supporting ...
IT Systems Analyst - Cybersecurity, Risk & Compliance
Parsippany, NJ · On-site
$94K - $95K/yr
This role offers structured training and practical exposure to security, compliance, risk management, and enterprise system governance initiatives. Key Responsibilities: * Assist in supporting ...
Support the CISO with the day-to-day management of the security function, including security operations, security engineering & architecture, governance, risk & compliance and physical security.
Support the CISO with the day-to-day management of the security function, including security operations, security engineering & architecture, governance, risk & compliance and physical security.
Data Security Manager - Information Security & Risk Management
Raritan, NJ · On-site
$150 - $200/hr
Assess exception requests and coordinate risk reviews, approvals, remediation actions, and ... Partner with EUS, ISRM teams, Compliance, Privacy, Legal, HR, and business partners to design and ...
New
Data Security Manager - Information Security & Risk Management
Raritan, NJ · On-site
$150 - $200/hr
Assess exception requests and coordinate risk reviews, approvals, remediation actions, and ... Partner with EUS, ISRM teams, Compliance, Privacy, Legal, HR, and business partners to design and ...
New
Security & Compliance Lead
Lawrence, NY · Remote
$160K - $200K/yr
You will build Maigrate's security and compliance program from the ground up. You will lead SOC 2 ... Own the HIPAA security program, including security risk analysis, risk management, policies ...
Quick apply
Security & Compliance Lead
Lawrence, NY · Remote
$160K - $200K/yr
You will build Maigrate's security and compliance program from the ground up. You will lead SOC 2 ... Own the HIPAA security program, including security risk analysis, risk management, policies ...
Security & Compliance Lead
Lawrence, NY · On-site
$160K - $200K/yr
You will build Maigrate's security and compliance program from the ground up. You will lead SOC 2 ... Own the HIPAA security program, including security risk analysis, risk management, policies ...
Security & Compliance Lead
Lawrence, NY · On-site
$160K - $200K/yr
You will build Maigrate's security and compliance program from the ground up. You will lead SOC 2 ... Own the HIPAA security program, including security risk analysis, risk management, policies ...
M0 Labs - Head of Security & Risk
New York, NY · On-site +1
$117K - $153K/yr
The information security and risk posture we establish in the next 12 months will define how M0 is ... Own M0's compliance posture across SOC 2, ISO 27001, and other applicable frameworks - driving all ...
M0 Labs - Head of Security & Risk
New York, NY · On-site +1
$117K - $153K/yr
The information security and risk posture we establish in the next 12 months will define how M0 is ... Own M0's compliance posture across SOC 2, ISO 27001, and other applicable frameworks - driving all ...
Deputy Chief Information Security Officer
Manhattan, NY · On-site
$250/hr
Support the CISO with the day-to-day management of the security function, including security operations, security engineering & architecture, governance, risk & compliance and physical security.
New
Deputy Chief Information Security Officer
Manhattan, NY · On-site
$250/hr
Support the CISO with the day-to-day management of the security function, including security operations, security engineering & architecture, governance, risk & compliance and physical security.
New
Deputy Chief Information Security Officer
New York, NY · On-site
$450K/yr
Support the CISO with the day-to-day management of the security function, including security operations, security engineering & architecture, governance, risk & compliance and physical security.
Deputy Chief Information Security Officer
New York, NY · On-site
$450K/yr
Support the CISO with the day-to-day management of the security function, including security operations, security engineering & architecture, governance, risk & compliance and physical security.
Partners with Information Security & Risk Management (ISRM), Information Technology, Enterprise ... Ensure compliance with Corporate and Information Security policies, standards, procedures ...
Partners with Information Security & Risk Management (ISRM), Information Technology, Enterprise ... Ensure compliance with Corporate and Information Security policies, standards, procedures ...
Lead client-facing discussions on our security governance framework, risk management approach, regulatory compliance posture (SOC 2, ISO 27001, PCI DSS, DORA, GDPR, etc.), and control environment.
Lead client-facing discussions on our security governance framework, risk management approach, regulatory compliance posture (SOC 2, ISO 27001, PCI DSS, DORA, GDPR, etc.), and control environment.
Lead client-facing discussions on our security governance framework, risk management approach, regulatory compliance posture (SOC 2, ISO 27001, PCI DSS, DORA, GDPR, etc.), and control environment.
Lead client-facing discussions on our security governance framework, risk management approach, regulatory compliance posture (SOC 2, ISO 27001, PCI DSS, DORA, GDPR, etc.), and control environment.
Deputy Chief Information Security Officer (New York)
Manhattan, NY · On-site
$450K/yr
Support the CISO with the day-to-day management of the security function, including security operations, security engineering & architecture, governance, risk & compliance and physical security.
New
Deputy Chief Information Security Officer (New York)
Manhattan, NY · On-site
$450K/yr
Support the CISO with the day-to-day management of the security function, including security operations, security engineering & architecture, governance, risk & compliance and physical security.
New
Deputy Chief Information Security Officer (New York)
Manhattan, NY · On-site
$450K/yr
Support the CISO with the day-to-day management of the security function, including security operations, security engineering & architecture, governance, risk & compliance and physical security.
New
Deputy Chief Information Security Officer (New York)
Manhattan, NY · On-site
$450K/yr
Support the CISO with the day-to-day management of the security function, including security operations, security engineering & architecture, governance, risk & compliance and physical security.
New
Global Lead Security Compliance & Enforcement - Director
Hoboken, NJ · On-site
$250/hr
Global Lead Security Compliance & Enforcement - Director Other locations: Anywhere in Country Date ... Using policy, compliance-posture data, risk appetite, escalation protocols, and executive decision ...
Global Lead Security Compliance & Enforcement - Director
Hoboken, NJ · On-site
$250/hr
Global Lead Security Compliance & Enforcement - Director Other locations: Anywhere in Country Date ... Using policy, compliance-posture data, risk appetite, escalation protocols, and executive decision ...
Assess exception requests and coordinate risk reviews, approvals, remediation actions, and ... Partner with EUS, ISRM teams, Compliance, Privacy, Legal, HR, and business partners to design and ...
New
Assess exception requests and coordinate risk reviews, approvals, remediation actions, and ... Partner with EUS, ISRM teams, Compliance, Privacy, Legal, HR, and business partners to design and ...
New
Assess exception requests and coordinate risk reviews, approvals, remediation actions, and ... Partner with EUS, ISRM teams, Compliance, Privacy, Legal, HR, and business partners to design and ...
New
Assess exception requests and coordinate risk reviews, approvals, remediation actions, and ... Partner with EUS, ISRM teams, Compliance, Privacy, Legal, HR, and business partners to design and ...
New
Global Risk & Compliance creates and maintains the overall risk management framework, performs ... security, and service. As part of Team Amex, you'll experience our powerful backing with ...
Global Risk & Compliance creates and maintains the overall risk management framework, performs ... security, and service. As part of Team Amex, you'll experience our powerful backing with ...
Data Security Manager - Information Security & Risk Management
Raritan, NJ · On-site
$150 - $200/hr
Assess exception requests and coordinate risk reviews, approvals, remediation actions, and ... Partner with EUS, ISRM teams, Compliance, Privacy, Legal, HR, and business partners to design and ...
Posted today
Data Security Manager - Information Security & Risk Management
Raritan, NJ · On-site
$150 - $200/hr
Assess exception requests and coordinate risk reviews, approvals, remediation actions, and ... Partner with EUS, ISRM teams, Compliance, Privacy, Legal, HR, and business partners to design and ...
Posted today
Security Risk Compliance information
What is security risk compliance?
What are the key skills and qualifications needed to thrive as a security risk compliance professional?
What are some common challenges faced by security risk compliance professionals when balancing regulatory requirements with business objectives?
What is the difference between Security Risk Compliance vs Security Analyst?
| Aspect | Security Risk Compliance | Security Analyst |
|---|---|---|
| Certifications | ISO 27001 Lead Implementer, CISSP, CISA | CISSP, CompTIA Security+, GIAC Security Certifications |
| Work Environment | Policy development, compliance audits, risk assessments | Monitoring security systems, incident response, vulnerability analysis |
| Employer & Industry Usage | Financial, healthcare, government sectors focusing on regulatory adherence | IT departments across various industries focusing on security operations |
Security Risk Compliance professionals focus on ensuring organizations meet regulatory standards and manage security risks through policies and audits. Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within similar environments, their core responsibilities differ: compliance versus active security monitoring.
What cities in New York are hiring for Security Risk Compliance jobs?
Cities in New York with the most Security Risk Compliance job openings:

Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Re-posted 7 days ago
Bloomberg rating
9.4
Based on 11 frontline employees who took The Breakroom Quiz
11th of 247 rated software companies
Job description
Location
New York
Business Area
Legal, Compliance, and Risk
Ref #
10052405
Description & Requirements
The energy of a newsroom, the pace of a trading floor, the buzz of a recent tech breakthrough; we work hard, and we work fast - while keeping up the quality and accuracy we're known for. It's what keeps us inventing and reinventing, all the time. Our culture is wide open, just like our spaces. We bring out the best in each other through collaboration. Through our countless volunteer projects, we also help network with the communities around us, too. You can do amazing work here. Work you couldn't do anywhere else. It's up to you to make it happen.
About the Role:
We're looking for an Information Security Risk Oversight Lead who can translate cybersecurity risk into executive insight and action. Sitting in the Company's Second Line of Defense, the Chief Risk Office and reporting directly to our Head of Technology Risk, you will provide independent oversight and credible challenge across the firm's enterprise-wide information security program. Operating at the intersection of technology, risk management, cybersecurity, governance, and strategy, you will partner with the Chief Information Security Office, Engineering, and CTO teams to ensure cyber risks are appropriately identified, measured, monitored, and aligned with the firm's risk appetite. The "so what" is critical: your oversight will enable leadership to understand not only what the risks are, but whether they are being managed effectively-and where decisive action is required to strengthen the firm's overall security posture.
Key Responsibilities
* Serve as the primary Second Line risk advisor for cybersecurity -related risks and lead independent oversight and credible challenge of First Line of Defense activities.
*Identify and measure threat-actor initiated risks and risk scenarios that may impact the confidentiality, integrity, and availability of information systems.
* Evaluate the design and operating effectiveness of security controls, particularly across complex, high-risk, or enterprise-scale technology initiatives.
*Quantify risk and control posture to support executive decision-making through scenario analysis and metrics (e.g., KRIs, KPIs, SLA/SLOs, ALE).
* Review and challenge security-driven programs and initiatives to ensure alignment with enterprise risk appetite, industry control frameworks, and regulatory expectations.
* Partner closely with Information Security and Engineering teams to enhance risk awareness, accountability, and control ownership.
* Identify root causes of control failures, security incidents, or systemic weaknesses and support the development of actionable, preventative recommendations.
* Prepare and present risk oversight materials to senior leadership committees, internal audit, Board of Directors, and regulatory bodies as required.
* Act as a strategic thought partner to senior leaders by advising on emerging threats, evolving regulatory requirements, and industry best practices.
Required Qualifications
* Bachelor's Degree required.
* 10+ years of experience in Information Security.
* 10+ years of experience in IT or Cyber Risk Management.
* Demonstrated experience operating within a Second Line of Defense or independent risk oversight function.
* Strong understanding of cybersecurity control frameworks (e.g., NIST CSF, NIST 800-53, MITRE ATT&CK, ISO 27001, COBIT, CIS).
* Experience interacting with Boards, regulators, internal audit, and/or executive governance forums.
* Authorized to work in the United States.
Preferred Qualifications
* Relevant professional certifications (e.g., FAIR, CISSP, CISM, CRISC, CISA).
* Experience in regulated industries (e.g., financial services).
* Strong understanding of cloud security, application security, identity and access management, and cyber resilience.
* Familiarity with enterprise risk management methodologies and risk appetite frameworks.
Core Competencies
* Strong analytical and critical thinking skills with the ability to provide constructive challenge.
* Executive-level communication and presentation skills.
* Ability to influence without direct authority.
* Strategic mindset with strong attention to detail.
* High integrity and independent judgment.
Salary Range = 215,000 - 290,000 USD Annual + Benefits + Bonus
The referenced salary range is based on the Company's good faith belief at the time of posting. Actual compensation may vary based on factors such as geographic location, work experience, market conditions, education/training and skill level.
We offer one of the most comprehensive and generous benefits plans available and offer a range of total rewards that may include merit increases, incentive compensation (exempt roles only), paid holidays, paid time off, medical, dental, vision, short and long term disability benefits, 401(k) +match, life insurance, and various wellness programs, among others. The Company does not provide benefits directly to contingent workers/contractors and interns.
Discover what makes Bloomberg unique - watch our podcast series for an inside look at our culture, values, and the people behind our success.
What Bloomberg employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Bloomberg
Sourced by ZipRecruiter
Bloomberg runs on data. As the Data Management & Analytics team within Engineering, we support our organization's needs around managing data efficiently. The vision of the team is to build solutions that drive data quality, data dictionary, data stewardship, data lineage, reference, and master data management across various data domains (prospect, customer, vendor, material etc.). We partner with business teams across the organization in addressing their data needs and ultimately helping run business operations efficiently and make improved decisions.
Industry
Finance and insurance
Company size
10,000+ Employees
Headquarters location
New York, NY, US
Year founded
1981