Serve as second line of defense subject matter expert for cybersecurity and technology risks across operating entities
Develop and maintain Information Security Risk oversight program to identify, assess, mitigate, manage, monitor and report technology risk
Perform planned or ad-hoc technical risk reviews and challenge, review Technology or Business initiatives
Oversee ongoing monitoring, formal review and challenge activities, targeted risk reviews, and technology policy and standard assurance
Participate in governance committees and working groups (Operational Risk Committee, Technology Executive Working Group, Information Security & Data Management Committee, Architectural Review Board, AI Enablement Working Group)
Initiate timely escalations to Sr. Director, Cyber & Digital Risk and leadership team
Contribute to updating or developing policies and frameworks for safe adoption of technologies
Implement and sustain independent risk oversight of cloud operating platform and vendor software development activities
Participate in independent oversight of digital transformation initiatives and evaluate new products/projects for information risks
Participate in evaluation and management of cybersecurity risks related to third-party suppliers
Advise on remediation of regulatory findings and monitor resolution
Perform review and challenge of first line risk management processes, data and outcomes and communicate risk opinions
Analyze risk data to identify levels of risk, concentration, trends and patterns
Provide second line leadership during response to major technology or cyber incidents and coordinate second line engagement
Requirements
Bachelor's Degree in a technical discipline or equivalent work experience (Computer Science, Information Technology, Information Systems, Information Security)
Master's Degree in related technical disciplines preferred
Professional Certifications in Cybersecurity required
Professional Certifications in Cloud Security (AWS, Azure) preferred
Practitioner and management experience in one or more areas of Cybersecurity Risks
Overall professional experience of 15+ years or more in cybersecurity risk management roles in a matrix organization
Experience in Cybersecurity risk consulting in the financial services sector, Cyber security audit, Chief Information Security Officer / Deputy or similar second line of defense role preferred
Experience within a highly regulated environment such as the financial services industry and knowledge of the current and evolving regulatory landscape
Experience leading high performance teams
Strong understanding of technology infrastructure, information security, and enterprise resilience
Experience with developing and implementing technology & cyber risk oversight programs, preferably in a 2nd or 3rd line of defense
Technical skills: Resilient Security Architecture; Identity and Access Management; Network/Firewall Management; Vulnerability and Patch Management; Cloud Security Architecture; Secure Application Development/Containerization; Encryption/Tokenization; Data Loss Prevention; Security Logging and Monitoring; Incident Detection and Response Management; Offensive Security
Demonstrated expertise in technology risk management, advanced knowledge of cyber risk management best practices
Ability to engage effectively with senior management and operational teams, strong judgment, communication, analytical and project management skills
Benefits
Base Pay Range Minimum: $123,750.00 USD Maximum: $225,000.00 USD
Link to Santander Benefits: Santander Benefits - 2025 Santander OnGoing/NH eGuide (foleon.com)
Inclusive and accessible application process with accommodations available upon request
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
CybersecurityInformation Security Risk ManagementCloud SecurityIdentity and Access ManagementNetwork ManagementVulnerability ManagementSecure Application DevelopmentData Loss PreventionIncident Detection and ResponseResilient Security Architecture
Bachelor's Degree in Computer ScienceMaster's Degree in related technical disciplinesProfessional Certifications in CybersecurityProfessional Certifications in Cloud Security