Technical consultant addressing information security risks for USAA and guiding strategic security direction. Leading peers in assessing security strategies and educating on best practices.
Responsibilities
Provide technical consultation and guidance to the business for the interpretation and assessment of information security risk for projects, technologies, and environments
Integrate risk management strategies and educate risk owners across the enterprise on information security requirements and best practices
Evaluate, administer, and implement systems, policies and processes which serve to enhance the mitigation, reporting, and analysis of Information Security risk
Stay current on the latest Information Security risks
Leads peers and junior team members in the execution of Information Security domain activities while anticipating efforts that will impact their team
Develops, publishes, maintains and/or interprets complex Information Security governance requirements (e.g. policies and standards)
Designs, develops and optimizes repeatable methods and measurements for Information Security risk management program
Performs security risk assessments of complex projects, new technologies, environments, business partners and third parties
Influences Information Security risk management strategies; educates and consults with risk owners on best practices
Consults across the enterprise (advice, guidance and assistance) on Information Security risk; guides the strategic security direction of USAA technical projects, initiatives and other special projects
Recommends risk treatment options for technical projects, initiatives and other special projects
Responds both verbally and in writing to moderately complex inquiries and periodic exams from both internal control partners (e.g. legal, compliance, audit, risk) and external control partners (e.g. regulators, external auditors, third parties)
Ensures process owners identify, develop and test Information Security controls for risk mitigation effectiveness
Ensures risks associated with business activities are effectively identified, measured, monitored, and controlled in accordance with risk and compliance policies and procedures
Requirements
Bachelor’s degree; OR 4 years of related experience (in addition to the minimum years of experience required) may be substituted in lieu of degree
6 years of work experience in two or more of the eight areas Security and Risk Management, Asset Security, Security Architecture and Engineering, Communication and Network Security, Identity and Access Management (IAM), Security Assessment and Testing, Security Operations, and/or Software Development Security
4 years of related experience in conducting risk assessments, recommending risk treatment options and/or developing program governance (e.g. policies and standards)
Advanced level of business acumen in the areas of business operations, risk management, industry practices and emerging trends
Demonstrated risk management experience in a complex institution and/or highly matrixed environment related to banking, insurance and/or financial services
Knowledge of current IT risks and experience implementing security solutions
Knowledge of a wide range of security technologies, such as network security, database security, tokenization platforms, Data Leakage Prevention, Data Leakage Protection, Database Monitoring, Identity and Access Management systems
Experience with development of enterprise level policies/standards/Controls Experience with IT General Controls, Control Execution, Control Testing, etc. & Process Improvement, including identification of risk and controls
Advanced knowledge of applicable information security frameworks, standards, regulatory requirements, and controls
Advanced knowledge and application of security controls/mechanisms and threat/risk assessment techniques pertaining to complex data, application, and networking environments
Benefits
comprehensive medical, dental and vision plans
401(k)
pension
life insurance
parental benefits
adoption assistance
paid time off program with paid holidays plus 16 paid volunteer hours
Cyber Security Specialist focusing on IT security measures and infrastructure protection for a motivated team. Engaging in both project work and internal security processes.
IT & Cybersecurity Intern assisting with help desk support and IT system maintenance at OBDeleven. Collaborating with teams and improving IT documentation in a fun workplace culture.
Werkstudent supporting information security management and business continuity projects for Syneco's energy operations. Engaging in the development and upkeep of management systems and reporting tools.
Security Consultant providing IT - Security Consulting by leveraging knowledge and skills to assist clients. Involved in diverse projects from analysis to execution and results presentation.
Lead functional safety for product development in PEM electrolyzers at Quest One. Collaborate with teams and support certification processes in the field of green hydrogen technology.
(Senior) Consultant in Automotive - & Product Security at Wavestone, focusing on cyber security solutions for clients in innovative projects. Collaborative work in a vibrant team environment across multiple German cities.
Consultant specializing in Cyber & Product Security for clients in a hybrid role. Focused on implementing security strategies and conducting assessments with a collaborative approach.
Information Security Manager focusing on risk management for Xecuro GmbH. Implementing and optimizing risk management processes within a technological environment in Bonn.
Information Security Expert working on safe digital solutions, ensuring compliance and conducting risk assessments. Join Xecuro GmbH in shaping Germany's digital future with innovative security measures.
Teamlead position for Security Governance & Assurance at Xecuro GmbH in Bonn. Leading team and implementing information security management systems (ISMS).