OneMain Financial

Cybersecurity Governance Manager

OneMain Financial$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree in Cybersecurity, Information Technology, or equivalent experience.
  • 5-7 years of experience in technology and cybersecurity governance in regulated industries.
  • 3-5 years in a leadership role with proven influence across functional teams.
  • Deep knowledge of cybersecurity frameworks like NIST, SOC2, and CIS.
  • Familiarity with cybersecurity laws and regulations including GLBA, NYDFS, and PCI.
  • Strong verbal and written communication skills for complex data presentations.
  • Excellent organizational and program management skills.

Responsibilities

  • Establish and maintain a NIST-based security governance framework.
  • Oversee the cybersecurity policy program, including drafting and enforcement.
  • Maintain cybersecurity risk and controls matrix aligned with multiple frameworks.
  • Lead the annual enterprise risk assessment related to technology and cybersecurity.
  • Create and implement an automated GRC program for ongoing risk monitoring.
  • Facilitate the annual NYDFS Part 500 Cybersecurity self-assessment.
  • Manage the SOC2 audit and relevant exams from regulators.

Benefits

  • Collaborative team environment with motivated colleagues.
  • Opportunity to lead change and drive innovation in cybersecurity practices.
  • Engagement with key business partners across the organization.
  • Exposure to various cybersecurity frameworks and regulatory standards.
  • Possibility of influencing enterprise-wide cybersecurity strategies.
Full Job Description

We are seeking aManagerof Cybersecurity Governance to join our dynamic teamreporting to theDirectorof Cybersecurity Governance and Risk.This rolewillleadthedevelopmentof a comprehensive technology and cybersecuritygovernanceframework tailored to ouron-premiseandcloudenvironments. This role is critical in ensuring that our company'stechnology and cybersecuritypractices are compliant with regulatory requirements and industry standards, while alsoeffectivelyidentifyingrisks.

Members of the Cybersecurity Governance team are motivated, detail-oriented, and thrive in a collaborative environment where they will add value to key business partners. This position will require you to be adaptive, willing to drive change and innovation, and work in a fast-paced environment requiring collaboration and the ability to organize and prioritize assignments.

Responsibilities:

  • Establish andmaintainasecurity governance frameworkbased on the National Institute of Standards and Technology (NIST) Cybersecurity Frameworkto ensure effective oversight and accountability.

  • Oversee thetechnology and cybersecurity policy program, which includes policyand controldrafting,facilitatingcross-functional input,and enforcement of policies, procedures, and controls.

  • Maintain the companys technology and cybersecurity riskandcontrolsmatrix in alignment with multiple frameworks, including SOC2,CIS,PCI, NIST CSF,NIST 800-53, and NYDFS Part 500.

  • Leadtheannualenterprisetechnology and cybersecurity riskassessment.

  • Establish an automatedtechnology and cybergovernance risk and compliance (GRC) program to continuouslymonitorand report on technology and cyber risk and control effectiveness.

  • Lead the companys annual NYDFS Part 500 Cybersecurity self-assessment.

  • Oversee andfacilitatethe annual SOC2 audit and any exams and assessments focused on technology and cybersecurity controlsfrom state examiners, regulators, and OneMain partners.

  • Educate,influenceandprovide clear directives for technology projects, either directly or through committees, to ensure the consistent application of policies,standardsand controlsacross all technology projects,systemsand services.

  • Partnerand coordinatewith the enterprise risk management team, internal audit, and otherfunctions withinthe cyber risk team to ensureappropriateoversightand management of cyber risks and controls in-line with OneMains enterprise riskmanagementframework.

  • Partner with cybersecurity architects, engineers, andtechnologyoperations teams to ensuregovernance programsforaccess privileges,applications, cloud environments, asset management, artificial intelligence, and other technology functionsareimplementedandmaintainedaccording tocybersecuritystandardsand guidelines.

  • Lead a metrics and reporting program to measure the efficiency and effectiveness of the cybersecurity program for senior management providing insights,trendsand recommendations.

Qualifications:

  • Bachelor's Degree with a focus in Cybersecurity, Information Technology disciplines or equivalent experience.

  • Minimum of 5 - 7 yearsofexperience inplanning, designing,implementingand managingtechnology and cybersecurity governanceandcontrolsframeworkin the financial industry or other regulated industry.

  • Minimum 3 - 5 years in a leadership rolewith a strong ability to influence peers,leadersand team members at all levels and across functional lines.

  • In-depth knowledge of cybersecurity frameworks, such as NIST, SOC2,andCIS.

  • In-depth knowledge of cybersecurity laws and regulations, industry standards and best practicesincludingGLBA 501(b),NYDFSand PCI.

  • Excellent verbal and written communication and presentation skillswith the ability to prepare and deliver complex data in a way that is concise/understandable.

  • Strong organizational and program management skills. Ability to effectively respond to shifting priorities and assignments.

  • Sound analytical, problem solving andresearchskills.

  • Proficient incomputerskills in Microsoft Office suite - Word, Excel, and PowerPoint.

  • Familiarity withGRC, metrics, and reporting tools likeArcher,Anecdotes,Power BI, or equivalent software a plus.

  • Self-motivation with proven ability to be adaptable to a dynamic, fast-pacedwork environment with multiple priorities and strict timelines.

About OneMain Financial

OneMain Financial is a consumer finance company that provides personal loans and other financial services. The company was founded in 1912 and is headquartered in Evansville, Indiana. OneMain Financial offers loans for a variety of purposes, including debt consolidation, home improvement, and auto financing. The company operates more than 1,500 branches across the United States. OneMain Financial is a subsidiary of Springleaf Holdings, Inc.
Learn more about OneMain Financial
Size
8,800 employees
Market Cap
$4 billion
Industry
Net Income
$730 million
Founded
1912
5 Year Trend
+5%
Revenue
$4.9 billion
NASDAQ

Similar Jobs

More Jobs at OneMain Financial

More Information Technology Jobs

Find similar Cybersecurity Governance Manager jobs: