Under the leadership of the Chief Information Security Officer (CISO), the Information Security Manager plays a critical role in developing and implementing risk management processes. This role involves analyzing company databases to identify and address potential security risks, ensuring the organization’s data and systems are protected from threats. The Information Security Manager collaborates strategically with internal teams and external stakeholders to design, adopt, and integrate appropriate security controls. They are responsible for delivering consistent processes and solutions, as well as promoting control automation to enhance efficiency and effectiveness. Essential Duties & Responsibilities: Manage the operational, technological, and legal risks associated with the business Establish proper governance to control and proactively spot problems and changes in the underlying systems’ risk profile Help application, product, and information owners understand the overall risk profile so that the proper controls may be introduced Ensure technology solutions adhere to firm-wide risk and regulatory standards by cultivating a strong risk and control environment Collaborate with other control roles, such as software developers, business control managers, compliance, internal audit, and external regulators Proactively identify, assess, and manage inherent risks in our system and promote a risk-mitigating culture Oversee regulatory and firm policy requirements for a wide range of technologies Drive control optimization, education, process efficiency, and better client experience to foster innovation and develop the environment for technology control Identify threats, risks, and relevant mitigation methods to support risk decisions and carry out security risk assessment operations Create a framework for integrated technology control that keeps the right balance between business and product development, risk reduction, and financial gains Drive transparent, quantifiable, and long-lasting control improvements by working together with the audit, compliance, business control management, and technology teams Provide clear direction to business, product, and technology stakeholders so they can manage their risks effectively Contribute to the creation of a culture of risk and control that is centered on proactive awareness of and enhancement of the control environments
Requirements
5+ years of experience in technology or IT risk management Bachelor’s degree in computer science, information security or a related field Proven track record in risk management, preferably in the audit or compliance activities, technology, or other pertinent control functions Proficient in architectural design principles, cyber threat assessments, and the software development life cycle Proficient with firewalls, endpoint security, mobility management, and vulnerability scanning Demonstrated expertise in the management of technology and application risks and controls Understanding of different control structures (e.g., FFIEC, COBIT, NEST) Ability to build effective working relationships with teammates, coworkers, and external organizations who are spread out geographically and from different cultural backgrounds Demonstrated aptitude for analysis and problem-solving Excellent communication skills in writing, speaking, and presenting Outstanding interpersonal, negotiation, and persuasive abilities Strong organizational skills and the capacity to multitask successfully Preferred: Experience building or maintaining infrastructure and apps Certifications like CISSP, CRISC, CISA, CISM, and CCSP
Benefits
ELLKAY offers a comprehensive and competitive benefit package that starts day one! Including: Medical, Dental, and Vision benefits Employer-paid Life and LTD 401k w/ matching – once eligibility is met Work/life balance Paid Volunteer Program Flexible working hours Unlimited PTO Remote work options Employee Discounts Parental Leave Our awesome culture includes: Working with talented, collaborative, and friendly people who love what they do Professional growth within Innovation environment On site in HQ Free daily lunches
Segment Risk Manager supporting the Cybersecurity segment with risk management and governance. Collaborating on risk assessments and providing advisory on standards and practices.
Penetration Testing Coordination Leader managing pre - testing activities and pipelines. Mentoring teams and ensuring timely execution of penetration tests in financial services context.
Sales Representative responsible for B2B IT - Security Consulting services. Focused on active sales, relationship management, and new business opportunities in cybersecurity.
Leading Cybersecurity Consulting initiatives and teams to drive client security strategies at Schönbrunn TASC GmbH. Ensuring the development of secure digital solutions and fostering client relationships.
Security Engineer focusing on detection and response and collaborating with teams to secure infrastructure at Semperis. Building security monitoring solutions and contributing to risk management.
IT Engineer managing network and security infrastructures for industrial clients. Focused on proactive development and troubleshooting in a collaborative team environment.
Cyber Security Management Consultant supporting clients with ISMS implementation and transitional audit preparation. Focused on secure implementation of information security management systems and client relationship management in cyber security.
Information Security Officer ensuring effective ISMS for aedifion's energy - efficient building solutions. Focusing on continuous development, employee safety, and security controls in a tech - driven environment.