Job DescriptionThe impact you will have in this role: Within the Cybersecurity Business Office, our role is to serve as trusted advisors to the business, shaping and guiding cyber risk-informed decision-making across the enterprise. We ensure security investments are aligned to the threat landscape and risk appetite, effectively funded, and focused on delivering measurable risk reduction, strengthening resilience, protecting critical assets, and enabling sustainable, secure business growth.
Primary Responsibilities: - Define and drive the enterprise Cybersecurity strategy aligned to business objectives, regulatory requirements, and evolving threat landscape
- Translate cybersecurity risk insights (threat intelligence, assessment results, and issues / control gaps) and strategic priorities into a structured, multi-year cybersecurity roadmap in alignment with Business, IT, and Cybersecurity objectives
- Understand and contextualize how the achievement of Cybersecurity strategic objectives will continue to mature the Cybersecurity program against the core Cyber Risk Institute Profile (CRI Profile) principles and tenets
- Develop and manage a portfolio of cybersecurity initiatives spanning vulnerability management, threat intelligence and detection, identity access management, data protection, as well as cybersecurity architecture and resilience
- Structure the cybersecurity roadmap into programs and projects mapped to key risk domains and control frameworks (e.g., CRI Profile)
- Prioritize initiatives based on alignment to strategic objectives, risk reduction, business impact, and regulatory exposure
- For each identified cybersecurity initiative, assist in the definition of milestones and success criteria tied to tangible security outcomes (e.g., reduced attack surface, improved patching, expand Role-Based Access)
- Oversee the execution against milestones with a focus on risk reduction progress, not just delivery completion
- Assist in developing and presenting executive reporting on cyber posture improvement, emerging risks, and program effectiveness
- Design and manage the cybersecurity program budget, including:
- Operational security capabilities (SOC, vulnerability management, IAM)
- Capital investments in security tooling and infrastructure
- Specialized cyber professional services (incident response, advisory, assessments)
- Monitor and forecast cybersecurity spending against budget, ensuring efficient allocation of resources across risk domains
- Evaluate cost vs. risk reduction value for tools, services, and programs to optimize investment decisions
- Lead the development of bi-monthly cybersecurity board reporting, translating complex cyber risks, threats, and control performance into clear, executive-level insights
- Synthesize inputs across vulnerability management, IAM, threat intelligence, incident response, and control effectiveness into concise, decision-oriented updates
- Provide a risk-informed narrative on the organization's cyber posture, highlighting emerging threats and critical issues (including high-risk vulnerabilities, control gaps, and delayed remediations, with recommended actions)
- Define and drive the enterprise cybersecurity strategy, translating cyber risk, threat intelligence, and regulatory requirements into a prioritized multi-year roadmap and book of work
- Establish and manage the cybersecurity portfolio, structuring initiatives across key domains (e.g., vulnerability management, IAM, threat detection) and prioritizing based on risk, business impact, and control gaps
- Oversee program execution and milestone delivery, ensuring initiatives are clearly defined, tracked against timelines, and delivering measurable risk reduction and resilience outcomes
- Design and manage the cybersecurity financial strategy and budget, including operational, capital, and professional services spend, with a focus on aligning investments to highest-risk areas
- Develop and deliver executive and board-level reporting, providing bi-monthly, risk-informed insights on cyber posture, key metrics, program progress, and emerging threats
- Analyze interdependencies across Cybersecurity projects, including financial benefits, resource constraints, risk mitigation, client satisfaction, and strategic alignment.
- Partner closely with Cybersecurity senior leadership and Finance management to drive informed decision-making.
Qualifications - Minimum of 8 years of related experience
- Bachelor's degree preferred or equivalent experience.
Talents Needed For Success - Management consulting experience preferred, with the ability to assess complex cybersecurity challenges, provide structured recommendations, and effectively communicate solutions to leadership.
- Create effective working relationships with senior business, cybersecurity, technology, and risk / control leadership.
- Ability to synthesize large amounts of information inclusive of project progress, risks, and issues into board-ready deliverables illustrating critical information to drive risk-based decisions.
- Strong cybersecurity acumen with technical expertise across Identity Access Management, Vulnerability and Threat Intelligence, and Data Protection capabilities.
- Effective collaboration, expectations management and partnership with multiple internal and external stakeholders.
- Participate as a cybersecurity leader in helping to move the entire organization towards our objectives
- Demonstrates strong critical thinking skills with the ability to identify interdependencies across cybersecurity processes, tools, and stakeholders to proactively mitigate risks and drive effective decision-making
- Translating multiple data elements (both financial and cyber-orientated) into a tangible product which can drive insights and decision making
- Experience with cybersecurity strategy development and portfolio governance
- Knowledge of Cybersecurity Financial Management, specifically related to operational, capital, and professional service expenses
The salary range is indicative for roles at the same level within DTCC across all US locations. Actual salary is determined based on the role, location, individual experience, skills, and other considerations.
Learn more about Clearance and Settlement by clicking here.
About the TeamServes as a dedicated technology resource for advancing DTCC's business opportunities and providing industry thought leadership for leveraging new technology. The goal of this new department is to partner internally with IT, our business and regulatory divisions and externally with clients, regulators, and fintech vendors, to help build new platforms and business models to advance DTCC's mission to support the financial markets.