Toyota logo

TFSB Information Security Risk Manager

Toyota
  • Plano, Texas
    2 days ago
    Toyota

    Job Description

    Overview

    Who we are

    Collaborative. Respectful. A place to dream and do. These are just a few words that describe what life is like at Toyota. As one of the world’s most admired brands, Toyota is growing and leading the future of mobility through innovative, high-quality solutions designed to enhance lives and delight those we serve. We’re looking for talented team members who want to Dream. Do. Grow. with us.

    An important part of the Toyota family is Toyota Financial Services (TFS), the finance and insurance brand for Toyota and Lexus in North America. While TFS is a separate business entity, it is an essential part of this world-changing company- delivering on Toyota's vision to move people beyond what's possible. At TFS, you will help create best-in-class customer experience in an innovative, collaborative environment.

    Toyota does not offer support or sponsorship of job applicants for employment-based visas or any other work authorization for this role now or in the future. You must have the right to work in the United States and not require Toyota support or sponsorship for immigration-related employment (e.g., H-1B, O-1, E-3, H-1B1, TN, F-1 OPT, F-1 STEM OPT, F-1 CPT, ‘job flexibility benefits’ [also known as I-140 or Adjustment of Status portability], etc.) now or in the future. You should not apply for this role if you will require Toyota to assist with immigration support or sponsorship now or in the future.


    Who we’re looking for


    The Toyota Financial Savings Bank is looking for a passionate and highly motivated TFSB Information Security Risk Manager.   


    Reporting to the TFSB Chief Information Security Officer (CISO), this person will be the primary owner responsible for building, implementing, and managing the bank's enterprise-wide Cyber Risk Management Framework (RMF).


    The ideal candidate will be a strategic leader who can establish a structured, repeatable, and transparent process for managing cyber risk across the organization. You will serve as the central point of authority for Cyber Risk Management, interfacing with senior leadership, internal audit, and regulators to ensure the program's effectiveness and drive a mature, risk-aware culture throughout the bank.


    What you’ll be doing


    • Develop, document, and maintain all cyber risk management policies, standards, procedures, and methodologies based on the NIST Risk Management framework.
    • Lead the execution of the cyber risk management lifecycle for all in-scope information systems, including system categorization, security control selection, implementation guidance, and effectiveness assessments.
    • Manage the formal system authorization process, preparing risk-based recommendations and authorization packages for senior leadership to review and approve.
    • Oversee the bank's master security control catalog and ensure it is kept current with emerging threats and regulatory requirements.
    • Establish and mature a continuous monitoring strategy to ensure systems maintain an acceptable security posture.
    • Administer and configure the Governance, Risk, and Compliance (GRC) platform that underpins the RMF program.
    • Develop and report on Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs) to provide leadership with a clear view of the enterprise risk landscape.
    • Serve as the primary liaison between system owners, IT teams, and security functions to facilitate risk assessments and track remediation activities.

    What you bring


    • A core understanding of banking-specific Information Technology & Security regulations, including deep familiarity with FDIC and FFIEC Examination Handbooks.
    • Minimum 7 years of previous experience in Information Security, IT Audit, or Technology Risk Management, with at least 3 years in a program management or leadership capacity.
    • Demonstrable expertise in developing and implementing risk management frameworks, specifically the NIST Risk Management Framework (NIST 800-37).
    • In-depth knowledge of security control frameworks, particularly NIST 800-53.
    • Strong understanding of FFIEC, GLBA, and SOX and their applicability to technologies and applications.
    • Proven ability to engage with and present complex security risk concepts to executive leadership to encourage prioritization and drive decision-making.
    • Bachelor’s Degree from an accredited institution, or equivalent professional experience.

    Added bonus if you have


    • Relevant security certification (CGRC, CRISC, CISSP, or CISM).
    • Hands-on experience building a risk management program from the ground up.
    • Experience implementing or serving as the primary administrator for a GRC platform (e.g., ServiceNow GRC, Archer).
    • Advanced degree with a concentration in an IT or Cybersecurity-related area.

    What we’ll bring 


    During your interview process, our team can fill you in on all the details of our industry-leading benefits and career development opportunities. A few highlights include:


    • A work environment built on teamwork, flexibility, and respect
    • Professional growth and development programs to help advance your career, as well as tuition reimbursement
    • Team Member Vehicle Purchase Discount
    • Toyota Team Member Lease Vehicle Program (if applicable)
    • Comprehensive health care and wellness plans for your entire family
    • Toyota 401(k) Savings Plan featuring a company match, as well as an annual retirement contribution from Toyota regardless of whether you contribute (if applicable)
    • Paid holidays and paid time off
    • Referral services related to prenatal services, adoption, childcare, schools and more
    • Tax Advantaged Accounts (Health Savings Account, Health Care FSA, Dependent Care FSA)
    • Relocation assistance (if applicable)

    Belonging at Toyota


    Our success begins and ends with our people. We embrace all perspectives and value unique human experiences. Respect for all is our North Star.


    Applicants for our positions are considered without regard to race, ethnicity, national origin, sex, sexual orientation, gender identity or expression, age, disability, religion, military or veteran status, or any other characteristics protected by law.


    Have a question, need assistance with your application or do you require any special accommodations? Please send an email to

    talent.acquisition@toyota.com

    .

    Numbers & Facts

    LocationPlano, Texas
    IndustryAutomotive and Parts Mfg
    Company Size10,000 employees or more
    Websitehttps://www.toyota.com/usa/

    About Company

    How do we create some of the most advanced, reliable and safe vehicles? It starts with our manufacturing principles and management philosophy. We’re always looking for ways to improve our operations, always challenging ourselves to innovate, always looking to collaborate, always improving each day in everything we do.

    Skills

    • Bank Managementunmatched
    • Banking Servicesunmatched
    • CISM - Certified Information Security Managerunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Computer Securityunmatched
    • Customer Experienceunmatched
    • Establish Prioritiesunmatched
    • Federal Deposit Insurance Corp (FDIC)unmatched
    • Financeunmatched
    • Financial Servicesunmatched
    • Flexible Spending Accountsunmatched
    • Healthcareunmatched
    • Information Technology & Information Systemsunmatched
    • Information Technology/Systems Auditunmatched
    • Information/Data Security (InfoSec)unmatched
    • Insuranceunmatched
    • Internal Auditunmatched
    • Internet Securityunmatched
    • Leadershipunmatched
    • Performance Metricsunmatched
    • Product Lifecycleunmatched
    • Program Evaluationunmatched
    • Project/Program Managementunmatched
    • Regulationsunmatched
    • Regulatory Requirementsunmatched
    • Reporting Skillsunmatched
    • Riskunmatched
    • Risk Analysisunmatched
    • Risk Managementunmatched
    • Risk Management Framework (RMF)unmatched
    • Sarbanes-Oxley Act (SOX)unmatched
    • Savings Bankunmatched
    • ServiceNowunmatched
    • Systems Administration/Managementunmatched
    • Team Foundation Server (TFS)unmatched
    • Team Playerunmatched
    • Technical Leadershipunmatched
    • Tuition Reimbursementunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • Web Application Frameworkunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder