Senior Information Security & Risk Manager

National Futures Association
Chicago, IL, United States
3 months ago
Apply on indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Compensation
$152,950.0 - $272,000.0
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Information Systems

Job description

When you join NFA as a Senior Information Security & Risk Manager, you will play a critical role in supporting our mission by strengthening NFA’s information security compliance program and ensuring alignment with regulatory requirements, industry frameworks, and evolving cybersecurity best practices. As a subject matter expert you will ensure policy alignment with NIST CSF, NIST SP 800-53r5, and FISMA requirements.

Bring your analytical mindset and security expertise to solve complex challenges, evaluate risk, and identify opportunities for continuous improvement.

Beginning your first day and throughout your career at NFA, you will collaborate with Information Systems, Security Operations, and business stakeholders to assess compliance requirements, evaluate security controls, and support ongoing compliance initiatives. You will quickly become a trusted resource on security frameworks while helping NFA navigate an increasingly complex cybersecurity and technology landscape, including adoption of artificial intelligence.

What you’ll do: As a key contributor and SME, you will support the development and maturity of the information security compliance program while partnering with stakeholders across the organization to strengthen governance, manage risk, and ensure regulatory compliance. In addition, you will:

Support the development, implementation, maintenance, and improvement of NFA’s information security compliance program. Assess and monitor the effectiveness of information security controls, compliance activity, risk mitigation efforts to ensure alignment with regulatory, industry, and organizational requirements. Develop and enhance information security policy standards, procedures and related governance documentation. Collaborate with various departments and stakeholders to identify compliance gaps, evaluate risk, and support remediation activities. Help lead internal and external audits and prepare compliance materials for regulatory reporting and information requests, including those related to CFTC submissions. Monitor changes to applicable laws, regulations, frameworks and industry best practices to recommend appropriate updates to NFA’s compliance program. Prepare compliance documentation, risk assessments, metrics, and reports for management, regulatory agencies, and other stakeholders. Assess governance, risk, compliance, and control considerations associated with emerging technologies, including artificial intelligence and support the development of appropriate policies, and oversight practices. Maintain professional knowledge through continuous education, industry engagement, and awareness of evolving cybersecurity, compliance, privacy, and AI governance practices.

Requirements

Do you have experience in Stakeholder engagement?, Do you have a Bachelor’s degree?, We’re seeking a collaborative and intellectually curios professional who combines strong compliance expertise with business judgement. The successful candidate will be comfortable working independently and communicating with both technical and non-technical stakeholders. A commitment to continuous learning, attention to detail, and the ability to translate complex regulatory requirements into practical solutions will be critical to success in this role. Additional requirements and experience include:

Bachelor’s degree in Information Security, Cybersecurity, Risk Management, or related field. A minimum of 7 years of experience in information security, cybersecurity compliance, IT risk management, or related discipline. SME in NIST CSF, NIST SP 800-53, FISMA, and information security governance. Experience supporting regulatory examinations, audits, control assessments, or compliance reviews. Expertise in information security risk management methodologies and control frameworks. Knowledge and interest in emerging cybersecurity concepts, as well as AI governance considerations. Strong analytical, organizational, problem solving, and communication skills. Ability to collaborate and work with departments across multifaceted organizations. Skilled in developing executive reports and presentations that convey complex information security and risk concepts to both technical and non-technical audiences. Relevant certifications such as CISSP, CISM, CRISC, CGRC, or similar certifications are preferred.

Benefits & conditions

The salary range for this position is $152,950 to $272,000

Customers and market participants depend on NFA to act with integrity and impartiality as it carries out its mission of safeguarding the markets and protecting investors. Therefore, NFA employees have a responsibility to conduct themselves according to high ethical standards, and must abide by NFA’s Code of Professional Conduct. Learn more about the Code of Professional Conduct.

About the company

NFA is purpose-driven. We safeguard the integrity of the derivatives markets, protect investors and ensure that our Members meet their regulatory obligations. We take pride in our work; maintain a conviction to do the right thing; empower each other; and support our community. Envision your career in a place where performing critical regulatory work within the financial industry is as significant as the passionate and talented individuals with whom you work.

NFA is purpose-driven. We safeguard the integrity of the derivatives markets, protect investors and ensure that our Members meet their regulatory obligations. We take pride in our work; maintain a conviction to do the right thing; empower each other; and support our community. Envision your career in a place where performing critical regulatory work within the financial industry is as significant as the passionate and talented individuals with whom you work.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:44 min

Background and career journey in regulated software systems

Martin Hynie · Coffee With Developers

2:28 min

Preventing sensitive information disclosure in RAG systems

Deepu Deepu · World Congress 2025

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all