Seattle, WA, USA
4 days ago
Risk Assurance Investigator - Integrations

Opportunity to shape risk culture and ensure technological safeguards in a dynamic, collaborative environment.

As a  Risk Assurance Investigator - Integrations in Cybersecurity Technology & Controls, you will lead expert technical risk assurance and control oversight to ensure the firm's products and lines of business achieve their objectives while effectively managing risk. Utilizing your background in technology risk management, you will work with cross-functional teams to identify, assess, and mitigate emerging risks and vulnerabilities. Your tactical and strategic decision-making will significantly impact the firm's operations, financial management, and public image. You will play a crucial role in fostering a robust risk culture and catalyzing continuous improvement, contributing to the development and implementation of comprehensive risk management policies, standards, and controls.

Job responsibilities:

Lead comprehensive risk assessments to identify potential threats and vulnerabilities in the Firm's processes, systems, and operations, developing risk mitigation strategies Advise stakeholders on risk management, controls development and adherence to mitigate risks Proactively monitor key risk indicators, analyze control metrics, and offer insights on risk management effectiveness to senior management, driving continuous improvement initiatives Engage with regulators, clients, and stakeholders on risk-related issues, provide necessary oversight, ensuring compliance with laws, regulations, and internal policies 

Required qualifications, capabilities, and skills:

5+ years of experience or equivalent expertise in technology risk management, information security, or a related field, with a focus on risk assessment and control evaluation Developed experience in roles such as security engineering, security architecture, security assurance, security operations, vulnerability management, threat modeling, assessments and penetration testing, or risk management will be helpful.    Experience with integrations and automations tooling (Python, Jupyter, etc)  Experience connecting systems and data sets to provide signal intelligence.   Experience performing structured investigations into security related incidents.   Demonstrable ability to craft technical risk reports, adjusted for audience.   Formal knowledge in Application/Security, Threat Modeling, Penetration Testing / Red Teaming   Familiar knowledge in development, security, and operations (DevSecOps) / Coding Security Practices.  Ability to collaborate and communicate with a diverse range of stakeholders, of varying seniority, to effectively articulate risk and drive change.   Understanding of offensive and defensive security tools/technologies, such as penetration testing and red team testing platforms, firewalls, IDS/IPS, Web Proxies, and DLP.  

Preferred qualifications, capabilities, and skills:

CISM, CRISC, CISSP, or similar industry-recognized risk and risk certifications are useful Offensive Security (OSCP, OSEP, OSDA) 

 

Confirm your E-mail: Send Email