What are the responsibilities and job description for the Information Security Risk Manager position at Mountain America Credit Union?
Please reference the schedule and minimum qualifications listed below before applying.
If you need assistance with filling out our application form or during any phase of the application, interview, or employment process, please notify our Human Resources Team at 801-366-6947 option 1 or email macurecruiting@macu.com and every reasonable effort will be made to accommodate your needs in a timely manner.
Job Summary
Information Security Risk Manager (ISRM) position requires a seasoned risk professional with strong knowledge of risk management, control testing and assurance, cybersecurity, and information technology best practices. This role involves managing, guiding, and training a team to oversee IT and information security risk and controls assurance efforts. The ISRM is responsible for assisting in the design, implementation, monitoring, testing, reporting, and governance of the second line information security risk management framework and managing a team to ensure information assets and associated technology, applications, systems, infrastructure, and processes are protected. Strong leadership skills, a deep understanding of information security risks, and the ability to effectively communicate and implement risk management strategies is required.
Job Description
To be effective, an individual must be able to perform each job duty successfully.
- Assist the VP Information Security Officer (VP ISO) in monitoring and continuous improvement of a risk-based comprehensive enterprise security program across all IT and cyber-security risk domains including cyber risk management and oversight, threat intelligence and collaboration, cybersecurity controls, external dependency management, cyber incident management, and resilience.
- Direct team members in the design and performance of quarterly IT risk assessments and testing of controls across all IT and cyber-security risk domains to ensure that appropriate controls are in place, are effective, and any findings are reported.
- Train 2nd line Information Security Risk team members in testing strategies and documentation of IT and information security controls assessments.
- Direct team in monthly reporting of reportable incidents, risk assessments, metrics / KRIs, and control validation results.
- Manage team in quality assurance (QA) reviews and intake of IT and information security :
Issues for the Issues Management program
KNOWLEDGE, SKILLS, and ABILITIES
The requirements listed are representative of the knowledge, skills, and / or abilities required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential job functions.
Experience
Education
Bachelor's degree in Information Security, Computer Science, Information Management, Business or related field OR 2 additional years combined experience in information technology, risk or information security setting. Education must be from an accredited institution and will be verified.
Licenses, Certifications, Registrations
At least one of the following certifications :
Managerial Responsibility
Has leadership / managerial responsibilities that are direct or through work leaders or assistants, typically with a subordinate group of 3 to 10 employees. Estimates personnel needs and assigns work to meet these needs. Supervises, coordinates and reviews the work of assigned staff. Recommends candidates for employment, conducts performance evaluations and salary reviews for assigned staff, and applies company policy.
Computer / Office Equipment Skills
Language Skills
Other Skills and Abilities
PHYSICAL ABILITIES / WORKING CONDITIONS
Physical Demands
Ability to sit, talk and hear consistently
Ability to stand, walk, and use hands to handle or reach occasionally
Vision Requirements
Close vision (clear vision at 20 inches or less)
Distance vision (clear vision at 20 feet or more)
Weight Lifted or Force Exerted
Ability to lift up to 25 pounds occasionally may need to lift up to 40 pounds.
Environmental
There are no unusual environmental factors (such as a typical office)
Noise Environment
Moderate noise (business office with computers and printers, light traffic)
Mountain America Credit Union is an EEO / AA / ADA / Veterans employer.