Senior Information Security & Privacy Advisor at USAA providing expertise in managing Information Security risks and controls.
Responsible for fostering a proactive risk management culture while collaborating with engineering and product teams.
Responsibilities
Provide critical support and hands-on expertise in managing Information Security and Privacy risks and controls across various technology initiatives
Identify and assess risks, drive remediation efforts for audit and exam findings, manage security-related issues, and conduct rigorous control testing and validation
Partner closely with engineering, product, and other business units to ensure robust security controls are implemented and maintained
Foster a proactive risk management culture
Responsible for supporting business leader adherence to the established risk framework and ongoing supervision of business controls
Perform ongoing supervision and oversight of business controls and share knowledge with team members to evaluate their effectiveness
Responsible for risk data analysis, report preparation, and trend analysis
Anticipate business needs and proactively identify opportunities to improve and strengthen the control environment
Requirements
Bachelor’s degree; OR 4 years of related experience may be substituted in lieu of degree
6 years of experience supporting risk-related, compliance-related, or business control design activities; OR 6 years of experience in a relevant quantitative discipline; OR Advanced degree or designation in a risk management or quantitative discipline, and 4 years of experience supporting risk-related, and/or compliance-related, or business control design activities; OR PhD in a risk management or quantitative discipline, and 2 years of experience supporting risk-related, and/or compliance-related, or business control design activities
Deep technical understanding of Cybersecurity principles, common vulnerabilities, and security control mechanisms across various domains (e.g., network security, endpoint security, cloud security, application security)
Certifications such as CISSP, CISM, CRISC, CIPP, or GIAC certifications are highly desirable
Familiarity with security frameworks (e.g., NIST Cybersecurity Framework, ISO 27001) and their application in control design and assessment.
Demonstrated ability to manage complex issues and drive them to resolution in dynamic and uncertain environments
Excellent communication and interpersonal skills, with the ability to influence and collaborate effectively with technical and non-technical stakeholders.
Benefits
comprehensive medical, dental and vision plans
401(k)
pension
life insurance
parental benefits
adoption assistance
paid time off program with paid holidays plus 16 paid volunteer hours
various wellness programs
career path planning and continuing education
Job title
Senior Information Security & Privacy Advisor – Risk & Controls
Safety Coordinator ensuring workplace safety and compliance on client sites in Lisbon. Managing prevention activities and coordinating worksite safety for Bureau Veritas.
Internship in Cybersecurity at Mapfre, gaining hands - on experience in incident response and data analysis. Working within a collaborative team to develop cybersecurity skills and knowledge.
Senior Cybersecurity GRC Specialist shaping Orion Pharma's cybersecurity governance, risk management, and compliance. Engaging with teams to enhance security posture and meet regulatory standards.
Product Security expert ensuring secure software development at NETGEAR. Championing security practices and monitoring vulnerabilities while collaborating with development teams.
System Architect driving secure cloud - native applications using cutting - edge technologies for Product Security at Nokia. Leading AI - driven design and architecture with collaboration across global teams.
Cyber Security Engineer protecting data from threats in a fintech startup. Collaborating with the Information Security Team and implementing security controls for technical projects.
Junior Security Incident Responder in an innovative IT service company protecting clients against cyber threats. Collaborating with teams to enhance IT security and respond to incidents.
Security Incident Responder managing IT security incidents in the Security Operations Center, analyzing threats and coordinating responses effectively for clients' safety.
Senior Security Engineer developing and enhancing security infrastructure for Bank Frick, a pioneer in blockchain banking. Responsible for managing security processes and collaborating with IT teams.
Werkstudent Cyber Security bei Wavestone, Unterstützung im IT - Consulting und Entwicklung im Bereich Cyber - Sicherheit. Analyse von Trends und aktive Teilnahme an Teamaktivitäten.