Demo

Information Security Risk Assessor Lead

Northwest Opportunities
Columbus, OH Full Time
POSTED ON 1/7/2025
AVAILABLE BEFORE 3/6/2025

Information Security Risk Assessor Lead is responsible for the assessment, verification, review, and audit of technology controls and/or business process controls across the enterprise related to GLBA Appendix B (Information Security Risk Assessment) and Authentication and Access to Systems and Services leveraging the provided FDIC Guidance. The Assessor will be responsible for risk assessments which will require review and evaluation of IT and/or business systems and processes. Additionally, the Assessor will assist with 3rd party and 4th party vendor risks, evaluation of control deficiencies, and recommendation on remediation efforts consistent with IT organizational policies, standards, procedures, and regulatory requirements.

Essential Functions
• Execute compliance reviews; facilitate remediation planning, exposure tracking and communicating risk all done in accordance with regulatory frameworks, e.g., FDIC Guidance as needed
• Provide security architecture knowledge and design concepts by partnering with the Enterprise Risk function to help manage technology related risk
• Provide technical expertise to support the Vendor Management Team with 3rd and 4th party supply-chain security and risk assessments, audits, tests, and verification activities, and when appropriate make recommendations to mitigate risk
• Apply or recommend adaptive security requirements and/or measurements based on investigative findings and threat monitoring including performing security risk assessments prior to changes in the production environment occurring to ensure changes do not violate regulatory requirements
• Assess systems of various scope and complexity to obtain, review, and interpret evidence provided to validate controls are performed effectively with a primary focus regulatory prescribed compliance when required. Interpret regulatory requirements into easy to understand language for constituents
• Conduct and lead assessment interviews and tests to identify technology control gaps that introduce risk to the organization
• Execute and assist management with IT audits and regulatory compliance requirements as needed
• Buildout the development of risk assessments, risk meditation, and performance reporting, through working within the IT function and other partners within the business
• Participate as the liaison between Enterprise Risk and Information Technology/Information Security to improve the overall ability to identify operational risk, with a focus on continuous control monitoring and emerging cyber security threats

Additional Essential Functions
• Ensure compliance with Northwest’s policies and procedures, and Federal/State regulations
• Navigate Microsoft Office Software, computer applications, and software specific to the department in order to maximize technology tools and gain efficiency
• Work as part of a team
• Work with on-site equipment

Safety and Health for those without supervisory duties
• Abide by the rules of the safety and loss prevention program
• Perform work tasks in a safe manner
• Report any and all injuries to supervisor
• Know what to do in case of an emergency

QUALIFICATIONS
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

Education
Technical Degree Information/Cyber Security or Risk Management Or
Associate's Degree Information/Cyber Security or Risk Management Or
Bachelor's Degree Information/Cyber Security or Risk Management

Work Experience
2 - 6 years Direct PCI Assessor Experience
2 - 6 years General IT Functional Experience

General Employee Knowledge, Skills, and Abilities
• Ability to establish effective working relationships among team members and participate in solving problems and making decisions
• Ability to present and express ideas and information clearly and concisely in a manner appropriate to the audience, whether oral or written
• Ability to actively listen to what others are saying to achieve understanding, sharing information with others and facilitating the open exchange of ideas and information 
• Ability to establish courses of action for self to accomplish specific goals, develop and use tracking systems for monitoring own work progress, and effectively use resources such as time and information 
• Ability to make right decisions based on perceptive and analytical processes, practicing good judgment in gray areas 

Additional Knowledge, Skills and Abilities
Assesses systems security requirements by studying business requirements; conducting system security and vulnerability analyses and risk assessments and studying architecture/platform
Perform risk assessments and execute tests of data processing systems to ensure functioning of data processing activities and security measures
Subject Matter Expert in FFIEC IT Handbook, GLBA 501B, and Authentication and Access risks
Knowledge of best practices for security architecture and design 
Ability to assess cybersecurity controls and technology configurations
Ability to build update and maintain a global policy governance framework 
Experience and ability to build, manage and update controls related to policies, standards, and FDIC requirements and other frameworks as business needs dictate. 

Licenses and Certifications
Certification in Information Security such as Security , CISSP, CISA, etc. Upon Hire
CISA Upon Hire

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Information Security Risk Assessor Lead?

Sign up to receive alerts about other jobs on the Information Security Risk Assessor Lead career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$194,072 - $240,547
Income Estimation: 
$220,784 - $286,649
Income Estimation: 
$70,462 - $84,818
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$123,246 - $161,441
Income Estimation: 
$152,549 - $188,894
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553

Sign up to receive alerts about other jobs with skills like those required for the Information Security Risk Assessor Lead.

Click the checkbox next to the jobs that you are interested in.

  • Business Analytics Skill

    • Income Estimation: $57,949 - $80,705
    • Income Estimation: $61,990 - $82,600
  • Compliance Management Skill

    • Income Estimation: $94,513 - $153,877
    • Income Estimation: $100,736 - $140,328
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Northwest Opportunities

Northwest Opportunities
Hired Organization Address Columbus, OH Full Time
Job Summary The IT and InfoSec Operational Risk Officer within the second line of defense Operational Risk organization ...
Northwest Opportunities
Hired Organization Address Columbus, OH Full Time
The Customer Service Technician II is the midlevel midcareer position at the help desk for seasoned and highly skilled t...
Northwest Opportunities
Hired Organization Address Columbus, OH Full Time
The Regulatory Relations and Enterprise Risk Management (ERM) Manager will serve as a key point of contact between North...
Northwest Opportunities
Hired Organization Address Columbus, OH Full Time
The Head of Corporate Development is responsible for managing all aspects of Corporate Development activities, both inte...

Not the job you're looking for? Here are some other Information Security Risk Assessor Lead jobs in the Columbus, OH area that may be a better fit.

IT/INFORMATION RISK ASSESSOR

Northwest Opportunities, Columbus, OH

Information Security Risk Analyst

EverStaff, Columbus, OH

AI Assistant is available now!

Feel free to start your new journey!