Lead or support cybersecurity governance, risk, and operational processes across applications, systems, and business managed application environments
Perform application and associated technology security risk assessments using threat modeling methodology
Lead or assist with tracking, analyzing, and reporting on security issues, control gaps, vulnerabilities, findings, remediation activities, and related action items
Manage multiple priorities across competing workstreams, while maintaining clear ownership, follow-up, and communication
Work across organizational boundaries with business, technology, cybersecurity, risk, and control partners to clarify needs, resolve issues, and drive work forward
Oversee maintenance of accurate records, dashboards, trackers, reports, and documentation used for security oversight and management reporting
Coordinate and lead follow-ups with application owners, technology teams, risk partners, and other stakeholders to support timely completion of required activities
Review data from multiple sources to identify gaps, inconsistencies, trends, or items requiring escalation
Build and continuously look to enhance program metrics, prepare materials for governance forums, leadership updates, audits, assessments, or regulatory inquiries
Document procedures, process flows, and manage evidence of completed security program activities as needed for audit or regulatory inquiries
Requirements
3-5 years of experience managing team or leading as individual contributor in cybersecurity, risk management, compliance program management, technical delivery/program manager or technology operations in regulated industry