Sr. Manager, IT & Security Risk

CAREER DEVELOPERS INC
Reston, VA, United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Compensation
$185,000.0 - $200,000.0
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Software System Penetration Testing Software as a Service Cyber Security Python (Programming Language) Power BI Phishing Tableau (Software) Cloud Platform System Information Technology Tools for Reporting CIS Benchmarks

Job description

IT Risk Management, Information Security Governance, Cybersecurity Frameworks (NIST/ISO 27001), Third-Party Risk Management, Regulatory Compliance, Financial Services Experience, Vendor Risk Assessments, Incident Response Oversight, KRIs & Reporting, Cross-Functional Leadership, Our growing client is seeking a Senior Manager, IT & Information Security Risk to lead enterprise-wide oversight of technology, cybersecurity, AI, and information security risk management initiatives. This individual will partner closely with executive leadership, enterprise risk teams, technology stakeholders, compliance, and third-party vendors to strengthen cyber resilience and ensure alignment with regulatory expectations and organizational risk appetite., * Lead second-line oversight for IT and Information Security risk governance across the enterprise.

  • Evaluate and challenge the alignment of cybersecurity and IT strategies with business objectives, risk appetite, and regulatory expectations.
  • Review and assess information technology and cybersecurity risk assessments across applications, infrastructure, cloud environments, and operational processes.
  • Partner with technology and project teams on system implementations, architecture decisions, cybersecurity controls, and operational risk mitigation.
  • Evaluate SaaS platforms, technology integrations, and emerging technologies for security and compliance risk exposure.
  • Conduct third-party and vendor security risk assessments, including SOC 1/SOC 2 reviews, SIG questionnaires, penetration testing analysis, and remediation tracking.
  • Provide oversight and risk guidance related to cybersecurity incidents, operational disruptions, and emerging technology threats.
  • Collaborate with business units and technology teams to identify, document, monitor, and remediate risk findings.
  • Oversee cybersecurity policies, procedures, governance standards, and incident response planning.
  • Support enterprise cyber awareness initiatives, phishing simulations, tabletop exercises, and employee education programs.
  • Monitor remediation efforts tied to IT and security findings to ensure timely resolution.
  • Track cybersecurity and financial sector threat intelligence trends and communicate emerging risks to leadership.
  • Develop and maintain KRIs, dashboards, metrics, and executive reporting for risk committees and senior leadership.
  • Support a collaborative, inclusive, and high-performing risk culture across the organization.

Requirements

Do you have experience in Supplier risk evaluation?, Do you have a Bachelor’s degree?, * 8 10+ years of experience in IT Risk, Information Security, Cybersecurity Risk Management, or related disciplines.

  • Prior experience within financial services, banking, fintech, payments, or regulated industries strongly preferred.
  • Strong understanding of cybersecurity and governance frameworks including NIST CSF, NIST 800-53, ISO 27001, and CIS Controls.
  • Experience conducting third-party/vendor risk assessments and evaluating SOC reports.
  • Strong knowledge of regulatory expectations related to cybersecurity and operational risk.
  • Ability to communicate technical risk concepts clearly to executive leadership and business stakeholders.
  • Experience supporting incident response oversight and operational resilience initiatives.
  • Strong analytical, documentation, and problem-solving skills.
  • Experience with reporting tools such as Power BI, Tableau, or Python is preferred.
  • Bachelor’s degree in Cybersecurity, Information Security, Risk Management, Information Technology, or related field preferred.
  • Industry certifications such as CISSP, CISM, CRISC, CGEIT, or Security+ preferred.
  • Must be authorized to work in the United States.

About the company

Career Developers Inc., a distinguished staffing and consulting firm, is proud to celebrate 30 years of service excellence. As a GSA Contract holder, we offer comprehensive staffing solutions for both commercial and government sectors nationwide. By selectively partnering with clients who share our values, we ensure productive collaborations that set us apart in the industry. Our dedication to candidates involves managing expectations with precision through business intelligence, thorough interview preparation, transparent communication, and exceptional feedback throughout the process.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:17 min

Understanding AI risk tiers and compliance obligations

Jaap Kersten Jaap Kersten +1 · WWC 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

1:46 min

Traditional data architecture before Microsoft Fabric

Dr. Alexander Wachtel Dr. Alexander Wachtel +1 · WWC 2025

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all