> Markdown version of [/jobs/ext/3140704-head-of-information-security-risk-chief-risk-office](https://www.wearedevelopers.com/jobs/ext/3140704-head-of-information-security-risk-chief-risk-office). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Head of Information Security Risk - Chief Risk Office - **Company:** Bloomberg L.P. - **Location:** New York, NY, United States - **Experience:** Expert - **Salary:** $215,000.0 - $290,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cloud Computing Security, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Information Systems, Identity and Access Management, Software Security, Mitre Att&ck, Cyber Warfare - **Published:** September 29, 2026 - **Apply:** https://www.manhattanjobs.com/job.asp?id=3410959605&tx=FJ6562FFI&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role * Bachelor's Degree required. * 10+ years of experience in one or more technical Information Security disciplines (security architecture, penetration testing, application security, cyber defense, etc.) * Demonstrated experience operating within an independent oversight function as part of a Risk, Information Security, or Architecture team. * Strong understanding of cybersecurity frameworks (e.g., NIST CSF, NIST 800-53, TLPT/TIBER-EU, MITRE ATT&CK, ISO 27001, COBIT, CIS). * Experience interacting with Boards, regulators, internal audit, and/or executive governance forums. * Authorized to work in the United States., * Relevant technical and/or professional certifications (e.g., GIAC GPEN/GDAT, CREST,FAIR, CISSP, CISM, CRISC, CISA). * Experience in regulated industries (e.g., financial services). * Strong understanding of cloud security, application security, identity and access management, and cyber resilience. * Familiarity with enterprise risk management methodologies and risk appetite frameworks. Core Competencies * Strong analytical and critical thinking skills with the ability to provide constructive challenge. * Executive-level communication and presentation skills. * Ability to influence without direct authority. * Strategic mindset with strong attention to detail. * High integrity and independent judgment. ## Description We're looking for a Head of Information Security Risk who can translate cybersecurity risk into both executive insight and technical solutions. Reporting directly to our Head of Technology Risk as part of the Chief Risk Office, you will provide independent oversight, technical consultation and credible challenge across the firm's enterprise-wide information security program. Operating at the intersection of cybersecurity, risk management, governance, and strategy, you will be the senior cyber-risk partner to the Chief Information Security Office, Engineering, and Chief Technology Office. You will engage on topics ranging from technical security findings to programmatic decisions and regulatory strategy to ensure the company is operating within its target risk appetite and regulatory expectations. Your oversight will enable Bloomberg's senior leadership to understand not only what the risks are, but where decisive action is required to strengthen the firm's overall security posture., * Serve as the primary Second Line advisor for cybersecurity-related risks and lead independent oversight and credible challenge of First Line of Defense activities. * Evaluate and consult on the design and operating effectiveness of security programs and controls, particularly across complex, high-risk, or enterprise-scale technology initiatives. * Review and challenge security-driven programs and initiatives to ensure alignment with enterprise risk appetite, industry control frameworks, and regulatory expectations. * Partner closely with Information Security, CISO, ERM, and Engineering teams to enhance risk awareness, accountability, and control ownership. * Identify root causes of control failures, security incidents, or systemic weaknesses and support the development of actionable, preventative recommendations. * Prepare and present risk oversight materials to senior leadership committees, internal audit, Board of Directors, and regulatory bodies as required. * Act as a strategic thought partner to senior leaders by advising on emerging threats, evolving regulatory requirements, and industry best practices. *Attract, hire and manage a team of technical risk professionals to identify and measure threat-actor initiated risks and risk scenarios that may impact the confidentiality, integrity, and availability of information systems. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Best Companies to Work For in Berlin: Top 14 Companies in 2023 ](https://www.wearedevelopers.com/magazine/188-best-companies-to-work-for-in-berlin-top-14-companies-in-2023)