Cybersecurity Governance Manager
Baltimore, MD - USA
Job Summary
We are seeking aManagerof Cybersecurity Governance to join our dynamic teamreporting to theDirectorof Cybersecurity Governance and Risk.This rolewillleadthedevelopmentof a comprehensive technology and cybersecuritygovernanceframework tailored to ouron-premiseandcloudenvironments. This role is critical in ensuring that our companystechnology and cybersecuritypractices are compliant with regulatory requirements and industry standards while alsoeffectivelyidentifyingrisks.
Members of the Cybersecurity Governance team are motivated detail-oriented and thrive in a collaborative environment where they will add value to key business partners. This position will require you to be adaptive willing to drive change and innovation and work in a fast-paced environment requiring collaboration and the ability to organize and prioritize assignments.
Responsibilities:
Establish andmaintainasecurity governance frameworkbased on the National Institute of Standards and Technology (NIST) Cybersecurity Frameworkto ensure effective oversight and accountability.
Oversee thetechnology and cybersecurity policy program which includes policyand controldraftingfacilitatingcross-functional inputand enforcement of policies procedures and controls.
Maintain the companys technology and cybersecurity riskandcontrolsmatrix in alignment with multiple frameworks including SOC2CISPCI NIST CSFNIST 800-53 and NYDFS Part 500.
Leadtheannualenterprisetechnology and cybersecurity riskassessment.
Establish an automatedtechnology and cybergovernance risk and compliance (GRC) program to continuouslymonitorand report on technology and cyber risk and control effectiveness.
Lead the companys annual NYDFS Part 500 Cybersecurity self-assessment.
Oversee andfacilitatethe annual SOC2 audit and any exams and assessments focused on technology and cybersecurity controlsfrom state examiners regulators and OneMain partners.
Educateinfluenceandprovide clear directives for technology projects either directly or through committees to ensure the consistent application of policiesstandardsand controlsacross all technology projectssystemsand services.
Partnerand coordinatewith the enterprise risk management team internal audit and otherfunctions withinthe cyber risk team to ensureappropriateoversightand management of cyber risks and controls in-line with OneMains enterprise riskmanagementframework.
Partner with cybersecurity architects engineers andtechnologyoperations teams to ensuregovernance programsforaccess privilegesapplications cloud environments asset management artificial intelligence and other technology functionsareimplementedandmaintainedaccording tocybersecuritystandardsand guidelines.
Lead a metrics and reporting program to measure the efficiency and effectiveness of the cybersecurity program for senior management providing insightstrendsand recommendations.
Qualifications:
Bachelors Degree with a focus in Cybersecurity Information Technology disciplines or equivalent experience.
Minimum of 5 - 7 yearsofexperience inplanning designingimplementingand managingtechnology and cybersecurity governanceandcontrolsframeworkin the financial industry or other regulated industry.
Minimum 3 - 5 years in a leadership rolewith a strong ability to influence peersleadersand team members at all levels and across functional lines.
In-depth knowledge of cybersecurity frameworks such as NIST SOC2andCIS.
In-depth knowledge of cybersecurity laws and regulations industry standards and best practicesincludingGLBA 501(b)NYDFSand PCI.
Excellent verbal and written communication and presentation skillswith the ability to prepare and deliver complex data in a way that is concise/understandable.
Strong organizational and program management skills. Ability to effectively respond to shifting priorities and assignments.
Sound analytical problem solving andresearchskills.
Proficient incomputerskills in Microsoft Office suite - Word Excel and PowerPoint.
Familiarity withGRC metrics and reporting tools likeArcherAnecdotesPower BI or equivalent software a plus.
Self-motivation with proven ability to be adaptable to a dynamic fast-pacedwork environment with multiple priorities and strict timelines.
OneMain Holdings Inc. is an Equal Employment Opportunity (EEO) employer. Qualified applicants will receive consideration for employment without regard to age ancestry citizenship status color creed culture disability ethnicity gender gender identity or expression genetic information or history marital status military status national origin nationality pregnancy race religion sex sexual orientation socioeconomic status transgender or on any other basis protected by law.
Required Experience:
Manager
About Company
Sometimes unexpected costs occur, so trust OneMain to provide personal loans for home improvement, debt consolidation, car purchases, & more.