FREE ACCESS
5,000–10,000 jobs/day

See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Tech Stack
Tools & technologiesCyber Security
About the role
Key responsibilities & impact- Promote good risk management practices and governance across the organization in line with CSC Enterprise Risk management Framework (ERMF). This includes close cooperation with Enterprise Security and Business Unit technology teams.
- Ensure enterprise risk management requirements are incorporated into enterprise and product governance forums and provide independent challenge to technology and business leaders on risk posture.
- Provide risk advisory for new product launches, technology and AI adoptions and vendor integrations.
- Support and guide risk and control owners during initial control design of in-house and third party applications and emerging technologies including AI.
- Support and drive compliance with regulatory expectations.
- Provide 1st line teams with the necessary tools (policy, standards, templates, advice and guidance) to embed a structured, consistent way of risk identification, evaluation, monitoring and reporting across Cyber Security, Technology, Data and AI risk taxonomies.
- Participate and/or facilitate IT & cyber risk assessments and deep dives across key systems and applications including third party systems and SaaS solutions.
- Partner with Enterprise Security and BU Technology teams to ensure risks are properly recorded, tracked and remediated in CSC global GRC tool.
- Participate and drive the development of risk action and mitigation plans including root cause analysis.
- Promote and support the development of appropriate control frameworks to ensure Cyber security, Technology, Data and AI risks are managed responsibly.
- Driving firm-wide risk policy enhancements, consistent distribution of the policies, oversight of policy implementation and procedure/standard alignment.
- Ongoing assessment and recalibration of the global risk appetite across business units, shared services and locations across CSC.
- Targeted and thematic risk management deep dives. Undertake planned second line risk assessments, application control reviews and third party risk management.
- Assist with Executive and Board level risk reporting on Information Security and Technology themes.
Requirements
What you’ll need- Minimum of 7 years’ experience in Information Security and/or Technology Risk management within financial services ideally within regulated environments.
- Relevant certification(s) e.g. CISSP, CISM, CRISC or CISA
- Deep experience or equivalent experience in technology risk management, information security and cyber with a focus on risk identification, assessment and mitigation.
- Experience with industry frameworks such as COSO, COBIT, ISO27001, NIST and other including a solid understanding of the 3 lines of defense model.
- Knowledge of Operational resilience regulations and guidelines including DORA.
- Hands-on experience in targeted and thematic risk management deep dives from planning, scheduling and execution with good written and communication skills to all levels of management.
- Experience in using and implementing solutions with AI tools such as Claude Code / Github Copilot is an advantage.
Benefits
Comp & perks- Annual success-sharing bonuses or commission plans based on individual performance
- Health insurance
- 401(k) matching
- Flexible working hours
- Professional development opportunities
ATS Keywords
✓ Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
risk managementinformation securitytechnology risk managementrisk identificationrisk assessmentrisk mitigationcontrol designcyber securityAI adoptionvendor integration
Soft Skills
communication skillsleadershipcollaborationadvisory skillsanalytical skillsproblem-solvingreportingguidancepolicy implementationroot cause analysis
Certifications
CISSPCISMCRISCCISA
