Director - Cybersecurity Governance, Risk & Assurance

United States, New York
Permanent
Job ID: 2582

Job Description


[Up to c. $220k Base Salary + Discretionary Bonus | Hybrid Working]


Role Overview

We’re representing a large, highly regulated financial-services organisation strengthening the governance, risk and assurance capability within its cybersecurity function. This Director will take responsibility for an established GRC team spanning cyber risk, assurance, issue management, assessments and governance, with a particular focus on improving the quality and consistency of execution rather than simply producing oversight and reporting.

The position combines functional leadership with hands-on involvement. You’ll inherit a small team, develop its capability and work closely with security engineering, control, audit and risk stakeholders to make sure cyber risks are understood, challenged and addressed. You’ll also operate as a senior representative of the Security & Assurance function, translating complex technical issues into concise decisions, risk positions and updates for executive audiences...


Role Snapshot

  • Own the day-to-day cybersecurity governance, risk and assurance capability, including risk oversight, issue management, assessments, control governance and assurance activity
  • Bring 10+ years of relevant experience across cybersecurity, cyber risk, GRC, technology risk, assurance or audit, with established leadership responsibility in a regulated organisation
  • Lead and develop an existing team of c. 3-4 professionals, raising the bar from reporting-led activity towards stronger ownership, challenge and execution
  • Apply sufficient cybersecurity technical depth to understand control design and engineering discussions, challenge specialists effectively and translate technical exposure into business and risk terms
  • Oversee cyber risk, control and maturity assessments, ensuring weaknesses are clearly evidenced, prioritised, assigned and escalated where necessary
  • Establish effective governance routines, management information and executive reporting that create accountability across risk owners, control owners and security leadership
  • Coordinate cybersecurity input into internal audit, regulatory and broader assurance activity, maintaining clear evidence and driving findings through to sustainable remediation
  • Act as a senior representative and deputy within the Security & Assurance function, including preparing concise executive materials and handling senior stakeholder discussions at short notice
  • Maintain appropriate oversight of supporting governance programmes including security awareness, phishing effectiveness and cybersecurity evidence required for insurance assessments
  • (Preferred) Previous cybersecurity or technology-risk consulting experience, particularly alongside financial-services exposure, would provide strong preparation for the pace, executive interaction and breadth of this role


...


Apply for this role

All fields marked with * are required.

I confirm I have a pre-existing right to work in the role’s location *
I require visa sponsorship now or will require it in the future

Back to Job Listings