> Markdown version of [/jobs/ext/588935-senior-information-security-risk-manager](https://www.wearedevelopers.com/jobs/ext/588935-senior-information-security-risk-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information Security & Risk Manager - **Company:** National Futures Association - **Location:** Chicago, IL, United States - **Experience:** Expert - **Salary:** $152,950.0 - $272,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems - **Published:** June 21, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=c5129ffb3b174dff ## About the Role Do you have experience in Stakeholder engagement?, Do you have a Bachelor's degree?, We're seeking a collaborative and intellectually curios professional who combines strong compliance expertise with business judgement. The successful candidate will be comfortable working independently and communicating with both technical and non-technical stakeholders. A commitment to continuous learning, attention to detail, and the ability to translate complex regulatory requirements into practical solutions will be critical to success in this role. Additional requirements and experience include: Bachelor's degree in Information Security, Cybersecurity, Risk Management, or related field. A minimum of 7 years of experience in information security, cybersecurity compliance, IT risk management, or related discipline. SME in NIST CSF, NIST SP 800-53, FISMA, and information security governance. Experience supporting regulatory examinations, audits, control assessments, or compliance reviews. Expertise in information security risk management methodologies and control frameworks. Knowledge and interest in emerging cybersecurity concepts, as well as AI governance considerations. Strong analytical, organizational, problem solving, and communication skills. Ability to collaborate and work with departments across multifaceted organizations. Skilled in developing executive reports and presentations that convey complex information security and risk concepts to both technical and non-technical audiences. Relevant certifications such as CISSP, CISM, CRISC, CGRC, or similar certifications are preferred. ## Description When you join NFA as a Senior Information Security & Risk Manager, you will play a critical role in supporting our mission by strengthening NFA's information security compliance program and ensuring alignment with regulatory requirements, industry frameworks, and evolving cybersecurity best practices. As a subject matter expert you will ensure policy alignment with NIST CSF, NIST SP 800-53r5, and FISMA requirements. Bring your analytical mindset and security expertise to solve complex challenges, evaluate risk, and identify opportunities for continuous improvement. Beginning your first day and throughout your career at NFA, you will collaborate with Information Systems, Security Operations, and business stakeholders to assess compliance requirements, evaluate security controls, and support ongoing compliance initiatives. You will quickly become a trusted resource on security frameworks while helping NFA navigate an increasingly complex cybersecurity and technology landscape, including adoption of artificial intelligence. What you'll do: As a key contributor and SME, you will support the development and maturity of the information security compliance program while partnering with stakeholders across the organization to strengthen governance, manage risk, and ensure regulatory compliance. In addition, you will: Support the development, implementation, maintenance, and improvement of NFA's information security compliance program. Assess and monitor the effectiveness of information security controls, compliance activity, risk mitigation efforts to ensure alignment with regulatory, industry, and organizational requirements. Develop and enhance information security policy standards, procedures and related governance documentation. Collaborate with various departments and stakeholders to identify compliance gaps, evaluate risk, and support remediation activities. Help lead internal and external audits and prepare compliance materials for regulatory reporting and information requests, including those related to CFTC submissions. Monitor changes to applicable laws, regulations, frameworks and industry best practices to recommend appropriate updates to NFA's compliance program. Prepare compliance documentation, risk assessments, metrics, and reports for management, regulatory agencies, and other stakeholders. Assess governance, risk, compliance, and control considerations associated with emerging technologies, including artificial intelligence and support the development of appropriate policies, and oversight practices. Maintain professional knowledge through continuous education, industry engagement, and awareness of evolving cybersecurity, compliance, privacy, and AI governance practices. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Giving AI eyes: How to build a dashboard you can't see](https://www.wearedevelopers.com/videos/100193-giving-ai-eyes-how-to-build-a-dashboard-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)