Info Security Risk Advisor, Lead (REMOTE)
Job Description
We are seeking a dedicated Lead Information Security Risk Advisor for our Information Security Risk Advisory Services Team. Our team advises USAA's lines-of-business including bank, property and casualty, life insurance, and staff agency leaders and team members on information security risks, controls, and mitigations related to their business. This team is also responsible for completing the Information Security program maturity assessment on a quarterly basis with results reported to the board level.
USAA values a culture that is highly collaborative, and we have found that a hybrid work type helps employees gain the best of both worlds - collaborating in-person in the office and working from home when needed to achieve focused results. The actual days' onsite are resolved between each employee and the employee's manager. This position may also have the option of working remotely in the continental U.S. with occasional travel as requested.
Job Requirements
About USAA
USAA knows what it means to serve. We facilitate the financial security of millions of U.S. military members and their families. This singular mission requires a dedication to innovative thinking at every level.
About USAA IT
Our most meaningful qualification isn't technical, it's human. Here, we don't just sit in front of a screen. We stand behind our 13 million members who rely on us every day.
We're proud of USAA's strong history -- and we're even more passionate about our future. That's why we have a team of supportive and collaborative hardworking technology professionals focused on doing more for our members. And why we're continuing to add innovative problem solvers to our team. With us, you'll find exciting challenges that inspire you to continue learning and growing.
Job Responsibilities:
- Identifies and leads existing and emerging risks that stem from business activities and the job role.
- Ensures risks associated with business activities are effectively identified, measured, monitored, and controlled.
- Follows written risk and compliance policies, standards, and procedures for business activities.
- Influences and leads team efforts across the Information Security department and enterprise as a subject matter authority in their domain.
- Develops, publishes, maintains and/or interprets highly sophisticated Information Security governance requirements (e.g. policies and standards).
- Collaborates with business operations to resolve Information Security governance conflicts.
- Leads in the optimization, execution, and maintenance of repeatable methods and measurements for the Information Security risk management program in alignment with business objectives.
- Leads, performs and reviews security risk assessments of sophisticated projects, new technologies, business partners and third parties.
- Collaborates on Information Security risk management strategies with senior executive risk owners to enable risk-based decisions; educates and recommends risk treatment best practices in alignment with business objectives.
- Provides oversight on consulting (advice, guidance and assistance) to the enterprise, focusing on Information Security risk, to guide the strategic security direction of USAA.
- Responds both verbally and in writing to complex inquiries and periodic exams from both internal control partners (e.g. legal, compliance, audit, risk) and external control partners (e.g. regulators, external auditors, third parties).
- Contributes to the optimization and execution of methods to improve future inquiry responses.
- Provides oversight and peer-review of responses.
- Leads and provides guidance to team for identification, development, and testing of Information Security controls for risk mitigation effectiveness.
- Maintains expert level knowledge of USAA Information Security standards as well as industry information security standard processes, frameworks, laws and regulations.
Minimum requirements:
- Bachelor's degree; OR 4 years of related experience (in addition to the minimum years of experience required) may be substituted in lieu of degree.
- 8 years of work experience in three or more of the eight areas Security and Risk Management, Asset Security, Security Architecture and Engineering, Communication and Network Security, Identity and Access Management (IAM), Security Assessment and Testing, Security Operations, and/or Software Development Security.
- 6 years of related experience in conducting risk assessments, recommending risk treatment options and/or developing program governance (e.g. policies and standards).
- Expert level of business sense in the areas of business operations, risk management, industry practices and emerging trends.
- Advanced risk management experience in a sophisticated institution and/or highly matrixed environment related to banking, insurance and/or financial services.
- Advanced knowledge of current IT risks and experience implementing security solutions.
- Knowledge of a wide range of security technologies, such as network security, database security, tokenization platforms, Data Leakage Prevention, Data Leakage Protection, Database Monitoring, Identity and Access Management systems.
- Advanced experience with development of enterprise level policies/standards/Controls
- Experience with IT General Controls, Control Execution, Control Testing, etc. & Process Improvement, including identification of risk and controls.
- Expert knowledge of applicable information security frameworks, standards, regulatory requirements, and controls.
- Expert knowledge and application of security controls/mechanisms and threat/risk assessment techniques pertaining to complex data, application, IT design, secure architecture and/or networking environments.
Preferred experience:
- Strong knowledge of governance, risk, and compliance concepts pertaining to a Fortune 500 financial services company
- Knowledge and experience working in a Risk and/or Compliance and/or Information Security and/or Information Technology environment at a Fortune 500 financial services company
- Strong knowledge of laws, regulations and standards governing a Fortune 500 financial services company
- One or more of the following certifications:
- Certified in Risk and Information Systems Control (CRISC)
- Certified Information Privacy Professional (CIPP)
- Certified Information Systems Security Professional (CISSP)
The above description reflects the details considered necessary to describe the principal functions of the job and should not be construed as a detailed description of all the work requirements that may be performed in the job.
Compensation:
USAA has an effective method for assessing market data and establishing ranges to ensure we remain competitive. You are paid within the salary range based on your experience and market position. The salary range for this skill is: $117,600 - $211,700*
Employees may be eligible for pay incentives based on overall corporate and individual performance or at the discretion of the USAA Board of Directors.
Geographical Differential: Geographic pay differential is additional pay provided to eligible employees working in locations where market pay levels are above the national average.
Shift premium: will be addressed on an individual-basis for applicable roles that are consistently scheduled for non-core hours.
Benefits:
At USAA our employees enjoy best-in-class benefits to support their physical, financial, and emotional wellness. These benefits include comprehensive medical, dental and vision plans, 401(k), pension, life insurance, parental benefits, adoption assistance, paid time off program with paid holidays plus 16 paid volunteer hours, and various wellness programs. Additionally, our career path planning and continuing education assists employees with their professional goals.
Please click on the link below for more details.
USAA Total Rewards
Relocation assistance is Not Available for this position.
USAA is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Date Posted
10/30/2022
Views
0
Similar Jobs
Account Executive (Fully remote) - Branching Minds
Views in the last 30 days - 9
Branching Minds is a startup that aims to empower educators to support students holistic needs with a mission to create a path to academic and persona...
View DetailsSenior Financial Analyst (Remote First) - European Wax Center
Views in the last 30 days - 6
The job description is for a Network Administrator position at European Wax Center The role involves financial analysis data gathering and reporting T...
View DetailsSr. Communication Advisor, External Affairs - LyondellBasell
Views in the last 30 days - 7
LyondellBasell is seeking an External Affairs Advisor for their US Gulf Coast assets The role involves proactive stakeholder engagement media relation...
View DetailsDeployment Specialist (Remote) - Dominion Enterprises
Views in the last 30 days - 6
The text describes a job opening for a Deployment Specialist at Dominion VUE a company offering Microsoftbased cloudnative DMS software The role invol...
View DetailsWindows Engineer - Dynata
Views in the last 30 days - 17
The job posting is for a Senior Windows Engineer position at Dynata a company that offers a unique and international atmosphere The role requires stro...
View DetailsDigital Project Coordinator / Brand & Account Manager - Forthea Interactive Marketing
Views in the last 30 days - 6
Forthea is an awardwinning digital marketing agency that improves lead generation for clients by focusing on superior data analytics and creative exec...
View Details