> Markdown version of [/jobs/ext/121045-sr-manager-information-security-governance](https://www.wearedevelopers.com/jobs/ext/121045-sr-manager-information-security-governance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Manager Information Security Governance - **Company:** CIBC Delaware Holdings Inc - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $160,000.0 - $190,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Identity and Access Management, Network Security, Software Vulnerability Management, Computer Network Operations, Software Security, RSA Archer Platform - **Published:** May 30, 2026 - **Apply:** https://www.juju.com/job/00000000g3jwk0 ## About the Role + 10 years in Information Security, IT Risk Management, regulatory compliance or audit functions, within a US or Canadian bank (preferably at least 5 years in a leadership role) + Deep knowledge of key information security domains including network security, IAM, data protection, vulnerability management, application security, etc. + Awareness of emerging technologies and risks + Proven track record of managing banking regulatory examinations (e.g. FRB) and state specific oversight (e.g. NYDFS) + Demonstrated experience with FFIEC IT/Cyber Exam Handbook and GLBA Safeguards rule compliance. + Strong understanding of control frameworks (e.g. NIST CSF) + Ability to identify regulatory themes, assess control effectiveness and spot emerging gaps + Hands on experience preparing and delivering materials for regulatory agencies and internal/external auditors. + Skilled in exam logistics + Ability to determine and draft formal regulatory responses to information security issues which are clear, defensible and aligned with the overall risk posture + Experienced influencing and presenting to sr. leadership, boards and regulators + Exceptional written and verbal communication skills, with the ability to translate technical requirements into clear actionable language for regulators and executives. + Strong interpersonal skills to influence without direct authority + Experience with GRC platforms (e.g. MetricStream,OneTrust, Archer) + Certified professional with current Industry recognized certifications such as CISSP, CISM, CISA + You see the big picture and operate strategically + You act like an owner. You are action oriented, thriving when you're empowered to take initiative, go above and beyond, and deliver results. + You have a passion for excellence, holding yourself and others accountable. + You know that details matter. You notice and question things that others don't. Your critical thinking skills help to inform your decision-making. + You are a strong communicator, verbally and in writing, with the ability to flex to needs of executives and team members within and outside of US Information Security. + You're goal-oriented. You're motivated by accomplishing individual and team based goals and consistently delivering your best to make a difference. + You are a curious learner, staying current on industry trends. + You challenge the status quo and have a passion for continuous improvement., + You need to be legally eligible to work at the location(s) specified above and, where applicable, must have a valid work or study permit., Analytical Thinking, Group Problem Solving, Information Security, Network Operations, Security Operations, Security Risk Assessment, Technical Knowledge ## Description Protect the bank's regulatory standing by ensuring compliance and exam readiness, managing regulatory risk. This is a high visibility/high impact role. There are 3 primary components of the role: regulatory support, internal audit support, regulatory program compliance. The Sr Manager, Information Security Regulatory & Exam is responsible for regulatory exam support, quarterly regulatory briefings and adhoc regulator asks. You will also support Internal Audit activities. You will also be responsible for overall regulatory compliance, including regulatory compliance program ownership (e.g. NY-DFS, GLBA, FFIEC), performing/overseeing assessments, monitoring regulatory changes and recommending action. Provide regulatory reporting requirements and ensure timely, accurate and message appropriate reporting. Support may also include other teams under the Chief Security Office. Support may include and is not limited to Fraud, Operational Resilience, Third Party Governance & Physical Security. This is a hands on role with prep, coordination, direct activity ownership and oversight., + Regulatory Exams + End to end exam management + Ensure regulatory exam readiness + Review and suggest approach (responses, evidence) to regulatory exam letters + Coordinate response and evidence collection (which may include direct response/fulfillment), evaluating and questioning, aligning on strategic messaging, presenting to sr. leadership to align on audit ready responses + Regulatory Remediation + Actively engage in regulatory remediation activities, which may include analysis of regulatory feedback, suggesting recommended action, coordinating and evaluating responses, performing remediation actions, preparing regulatory update decks, creating speaking notes, ensuring messaging alignment with internal stakeholders and addressing any post meeting follow ups. + Regulatory Briefings + Prepare oversight briefing materials, which includes recommendations on approach/key themes, with speaking notes + Coordinate follow up activities + Internal Audit + Ensure internal teams are prepared for Internal Audit activities + Manage and socialize Internal Audit calendar + Coordinate audits, including fulfillment and evaluation of responses and evidence provided + Escalate potential issues before formal identification + Ensure timely review and response to audit reports + Oversee creation of new audit related deficiencies + Serve as point for monthly continuous monitoring + Program Management - Regulatory Program Compliance + Ensure NY DFS program annual activities are completed, including the NY Branch assessment, surveys, with risks identified and actioned + Ensure FFIEC/GLBA program activities are completed, including the annual assessment with risks identified and actioned + Complete annual Regulatory Control Management activities + Complete annual Regulatory Control Requirement Assessment + Reporting + Ensure overall CSO organization regulatory reporting dashboard is delivered + Monitor relevant laws, regulations and standards to ensure organization's security practices align with regulatory requirements. Create and distribute monthly regulatory development update reporting. + Assist with creation of materials for Annual Cyber Security Board Review and Quarterly Board Risk Committee Meetings + Creation of materials for various reporting committees and forums, including weekly status + Creation of materials for various reporting committees and forums, including weekly reports, business unit reviews and horizontal reviews + Projects + Oversee or complete specific enterprise, US region or department initiatives + General + Build strong relationships with internal and external partners, seen by them as a trusted partner + Complete ad hoc and urgent requests from internal and external partners, and recommend new controls to reduce risks + Work closely with US TI&I Risk & Controls Team, Regulatory Affairs, Operational Risk Management (ORM) and Internal Audit as required. + Teamwork and Relationship Building - Foster collaborative relationships with a wide range of stakeholders to identify opportunities to enhance Information Security processes and controls, understand pain-points and priorities, influence direction, solve problems, and ensure successful adoption and operation of policies and standards. + Will be required to foster relationships with middle to senior management, and senior executives across a range of functions including Risk Management and Technology. + Share governance best practices, based on regulatory and audit observations and feedback identified + Provides ongoing advice and direction on a variety of complex conceptual or interpretative issues + Perform regulatory controls as assigned control performer + Implement continuous improvement areas + Create and maintain procedural documentation ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Small, Secure, Interconnected: The next Internet Protocol](https://www.wearedevelopers.com/videos/100062-small-secure-interconnected-the-next-internet-protocol) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)