> Markdown version of [/jobs/ext/938514-information-security-risk-oversight-professional](https://www.wearedevelopers.com/jobs/ext/938514-information-security-risk-oversight-professional). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Risk Oversight Professional - **Company:** U.S. Bank - **Location:** Minneapolis, MN, United States - **Experience:** Expert - **Salary:** $111,605.0 - $131,300.0 - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, Cyber Security, Identity and Access Management, Information Security Management, Software Vulnerability Management, Software Security - **Published:** June 3, 2026 - **Apply:** https://dejobs.org/x/x/EE2E79F57A3B475FB06CF7E95B86D8A2/job/ ## About the Role * Bachelor's degree, or equivalent work experience * Typically more than eight years of applicable experience Preferred Skills/Experience * Strong foundational understanding of information security domains (e.g., vulnerability management, identity and access management, application security, cloud security, security governance, incident management). * Demonstrated ability to perform risk assessments and oversight activities with depth, critical thinking, and professional skepticism. * Experience operating in or with a Second Line of Defense, audit, or regulatory environment is strongly preferred. * Proven ability to work independently and autonomously, managing priorities and delivering high-quality work with limited direction. * Strong written and verbal communication skills, including the ability to translate technical risk into clear, executive-ready insights. * Ability to engage confidently with senior stakeholders while maintaining independence, objectivity, and professionalism. * Relevant certifications (e.g., CISSP, CISA, CRISC, CISM) are preferred but not required. ## Description The Information Security Risk Oversight Professional serves as a key member of the Cybersecurity Risk Oversight team within the Second Line of Defense (2LoD). This role is accountable for providing independent oversight and credible challenge of the First Line Information Security program to ensure risks are appropriately identified, assessed, managed, monitored, and reported in alignment with regulatory requirements, industry standards, and internal risk appetite. This position is intentionally designed for a senior, autonomous professional who can manage their own oversight portfolio, prioritize work based on material risk, and engage effectively with Information Security Services, Technology teams, and senior leadership., * Provide independent oversight and credible challenge of the Information Security program across multiple security pillars, including governance, risk assessments, controls, metrics, and issue management. * Perform risk-based assessments of first line security practices, identifying gaps, weaknesses, thematic concerns, emerging risks, and control deficiencies. * Develop and articulate independent risk opinions supported by sound analysis, evidence, and professional judgment. * Evaluate alignment of first line activities with applicable laws, regulations, regulatory guidance, industry standards (e.g., NIST 800-53, FFIEC, PCI, NIST CSF 2.0, etc), and internal policies. * Monitor key risk indicators, security metrics, assessment results, and issue trends to identify systemic risks or areas requiring escalation. * Escalate material risks, control weaknesses, or ineffective risk management practices through appropriate governance and reporting channels. * Act as a subject matter expert on information security risk, providing insights and guidance to stakeholders while maintaining 2LoD independence. * Build and maintain strong, professional relationships with first line stakeholders while confidently challenging assumptions, conclusions, and risk positions when necessary. * Contribute to executive-level risk reporting by clearly summarizing risk posture, trends, and areas of concern in a concise and defensible manner. * Stay current on evolving cybersecurity threats, regulatory expectations, and industry best practices to continuously strengthen oversight effectiveness. ## Related Videos - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [A Computer Is All You Need](https://www.wearedevelopers.com/videos/100142-a-computer-is-all-you-need) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know)