In this role you will serve as a trusted advisor to business and technology partners across the organization, embedding security expertise into decision-making from strategy through delivery. You will provide advisory services for risk decisions, secure-by-design guidance, and regulatory mapping, and deliver security input into strategic programs, mergers and acquisitions, and vendor due diligence to ensure risk-informed, business-aligned outcomes.
Key ResponsibilitiesTrusted Advisory & Stakeholder Partnership- Act as the primary security advisor to business, product, and technology leadership.
- Build trusted relationships that position security as an enabler of business objectives.
- Translate complex security concepts into clear, actionable guidance for technical and non-technical stakeholders.
Risk Advisory Services & Secure-by-Design Guidance- Provide advisory services on risk considerations for new initiatives, products, and architectural decisions.
- Embed secure-by-design principles across solution design and development lifecycles.
- Advise teams on control selection, residual risk, risk acceptance, and treatment options.
Security Assessment- Lead security assessments and design reviews across applications, platforms, and infrastructure.
- Identify and prioritize security weaknesses, control gaps, and design risks.
- Recommend proportionate, risk-based mitigations aligned to the organization's risk appetite.
Regulatory Mapping & Compliance Alignment- Map regulatory and compliance requirements to security controls and business processes.
- Advise on the security implications of evolving regulatory obligations.
- Partner with risk, legal, compliance, and audit teams to support examinations and assessments.
Strategic Programs, M&A & Vendor Due Diligence- Provide security input into strategic programs and enterprise-wide initiatives.
- Lead security due diligence for mergers, acquisitions, and divestitures.
- Assess third-party and vendor security posture and advise on risk-based onboarding decisions.
- Build and maintain ongoing security partnerships with key third parties and vendors to strengthen the extended risk posture.
Leadership & Collaboration- Lead and develop a high-performing security advisory services practice.
- Partner closely with security engineering and operations teams to align guidance with execution.
- Champion a culture of security awareness and shared accountability across the enterprise.
Required Qualifications- Extensive experience in security advisory services or risk leadership within financial services.
- Deep expertise in threat modeling, secure architecture, and risk assessment methodologies.
- Strong knowledge of regulatory and compliance frameworks and their application to security.
- Proven experience advising on M&A activities, strategic programs, and third-party/vendor risk.
- Exceptional stakeholder engagement, communication, and influencing skills.
LocationHybrid position in NYC/NJ.
The expected base salary ranges from $150k-$215k. Salary offers are based on a wide range of factors including relevant skills, training, experience, education, and, where applicable, certifications and licenses obtained. Market and organizational factors are also considered. In addition to salary and a generous employee benefits package, successful candidates are eligible to receive a discretionary bonus.
#LI-Hybrid
Other requirementsMizuho has in place a hybrid working program, with varying opportunities for remote work depending on the nature of the role, needs of your department, as well as local laws and regulatory obligations. Roles in some of our departments have greater in-office requirements that will be communicated to you as part of the recruitment process