Technical consultant addressing information security risks for USAA and guiding strategic security direction. Leading peers in assessing security strategies and educating on best practices.
Responsibilities
Provide technical consultation and guidance to the business for the interpretation and assessment of information security risk for projects, technologies, and environments
Integrate risk management strategies and educate risk owners across the enterprise on information security requirements and best practices
Evaluate, administer, and implement systems, policies and processes which serve to enhance the mitigation, reporting, and analysis of Information Security risk
Stay current on the latest Information Security risks
Leads peers and junior team members in the execution of Information Security domain activities while anticipating efforts that will impact their team
Develops, publishes, maintains and/or interprets complex Information Security governance requirements (e.g. policies and standards)
Designs, develops and optimizes repeatable methods and measurements for Information Security risk management program
Performs security risk assessments of complex projects, new technologies, environments, business partners and third parties
Influences Information Security risk management strategies; educates and consults with risk owners on best practices
Consults across the enterprise (advice, guidance and assistance) on Information Security risk; guides the strategic security direction of USAA technical projects, initiatives and other special projects
Recommends risk treatment options for technical projects, initiatives and other special projects
Responds both verbally and in writing to moderately complex inquiries and periodic exams from both internal control partners (e.g. legal, compliance, audit, risk) and external control partners (e.g. regulators, external auditors, third parties)
Ensures process owners identify, develop and test Information Security controls for risk mitigation effectiveness
Ensures risks associated with business activities are effectively identified, measured, monitored, and controlled in accordance with risk and compliance policies and procedures
Requirements
Bachelor’s degree; OR 4 years of related experience (in addition to the minimum years of experience required) may be substituted in lieu of degree
6 years of work experience in two or more of the eight areas Security and Risk Management, Asset Security, Security Architecture and Engineering, Communication and Network Security, Identity and Access Management (IAM), Security Assessment and Testing, Security Operations, and/or Software Development Security
4 years of related experience in conducting risk assessments, recommending risk treatment options and/or developing program governance (e.g. policies and standards)
Advanced level of business acumen in the areas of business operations, risk management, industry practices and emerging trends
Demonstrated risk management experience in a complex institution and/or highly matrixed environment related to banking, insurance and/or financial services
Knowledge of current IT risks and experience implementing security solutions
Knowledge of a wide range of security technologies, such as network security, database security, tokenization platforms, Data Leakage Prevention, Data Leakage Protection, Database Monitoring, Identity and Access Management systems
Experience with development of enterprise level policies/standards/Controls Experience with IT General Controls, Control Execution, Control Testing, etc. & Process Improvement, including identification of risk and controls
Advanced knowledge of applicable information security frameworks, standards, regulatory requirements, and controls
Advanced knowledge and application of security controls/mechanisms and threat/risk assessment techniques pertaining to complex data, application, and networking environments
Benefits
comprehensive medical, dental and vision plans
401(k)
pension
life insurance
parental benefits
adoption assistance
paid time off program with paid holidays plus 16 paid volunteer hours
IS Security Administrator managing all aspects of cyber security and data protection at Avita Health System. Responsible for risk assessments and IT security strategies across various platforms.
Senior Security Engineer strengthening security at fintech startup Flanks, focusing on security initiatives and practices across applications and infrastructure.
Director of Control Assurance leading IT risk management and controls testing at RBC. Propelling technology, risk, and security advancements across the organization.
OT Security Architect at Orange Cyberdefense providing security solutions for operational technology environments. Leading efforts in OT/ICS security and ensuring stable production for clients.
Physical Security Technology Manager overseeing design and implementation of security technologies across global offices. Collaborates with teams to ensure compliance and optimize security solutions.
Security Consultant for NTT DATA tackling client cybersecurity challenges through assessments and customized solutions. Responsible for implementing security measures and managing risk effectively.
Design and manage cybersecurity strategies protecting critical information assets for a retail company. Oversee compliance and lead information security initiatives in Mexico City and Culiacán.
Technical Capture Manager at Hadean responsible for delivering defence technology proposals. Translating technology capabilities into solutions for military and defence organisations.
Senior Product Manager driving cloud security strategy and development at ESET. Overseeing product lifecycle and collaborating with engineering teams to deliver innovative solutions.
Senior Product Manager leading the strategy and development of ESET's Identity Security portfolio. Driving innovation across identity protection areas such as ITDR and risk - adaptive authentication.