Title: AVP Information Security Strategy, GRC & Data Privacy
Office Status: Hybrid New York, NY
Base Salary: Up to $150k + Bonus
ABOUT THE ROLE
This AVP-level opportunity sits within the CISO function of a well-established global financial institution, offering broad ownership across information security strategy, program management, governance, risk assessments, compliance, data privacy, and identity and access management. The role serves as a multi-disciplinary anchor for the institution's information security program coordinating strategy execution, managing CISO programs, refreshing policies and controls, overseeing regulatory compliance, and driving data privacy initiatives across the branch. It's an ideal fit for a technically grounded IT/IS risk professional with 5+ years of experience who combines strong program management skills with deep familiarity with regulatory frameworks and the ability to engage credibly across senior management, technical teams, and regulatory stakeholders.
RESPONSIBILITIES
Coordinate Information Security strategy in alignment with broader branch goals;maintain strategic initiative tracking and KRIs;conduct quarterly CISO strategy reviews and adjust as necessary
Provide end-to-end project management for all CISO-led initiatives;manage all CISO programs including the Information Security Program, Data Privacy Program, and Training & Culture Program covering security training, phishing campaigns, and tabletop exercises
Establish and maintain Information Security policies and procedures;ensure CISO roles and responsibilities are clearly delineated across first and second lines;periodically refresh TISR controls guidance and track policy adherence measures and metrics
Provide all administrative functions for the Information Security Committee and all sub-committees
Establish and enhance a TISR framework;conduct risk assessments across projects, third-party engagements, new activities, and applications;develop and execute an annual TISR work plan covering risk identification, assessment, control evaluation, and testing
Catalog and oversee remediation of TISR issues arising from audits, regulatory exams, root cause analyses, and control testing;track control gaps and annually refresh CISO policies to reflect new and enhanced controls
Prepare and submit audit evidence packages;develop proactive audit readiness strategies;prepare regulatory exam response evidence and recommend policy changes to align with OCC and applicable federal guidelines
Develop and implement data privacy strategies ensuring compliance with applicable privacy laws and regulations;oversee privacy risk assessments, maintain privacy policies and procedures, and deliver privacy training programs
Manage all CISO metrics and reporting across operational, executive, board-level, budget, headcount, and dashboard formats
Establish and periodically update policies, procedures, and guidelines related to identity and access management and access recertification;manage end-to-end user access reviews including planning, execution, tracking, and resolution;conduct periodic User Recertification and Access Reviews across all applications;collaborate with IT, OSD, and business units to align access governance with broader organizational goals
Numbers & Facts
Location
New York, NY
Skills
Administrative Skillsunmatched
Budgetingunmatched
Global Financial Marketsunmatched
Identity Data Managementunmatched
Information/Data Security (InfoSec)unmatched
Maintain Complianceunmatched
Metricsunmatched
Privacy Regulationsunmatched
Project Planningunmatched
Project/Program Coordinationunmatched
Project/Program Managementunmatched
Regulationsunmatched
Regulatory Complianceunmatched
Reporting Dashboardsunmatched
Riskunmatched
Risk Analysisunmatched
Root Cause Analysisunmatched
Strategic Planningunmatched
Testingunmatched
Training Programunmatched
Training/Teachingunmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.