Early Warning Services

Principal - AI Technology Risk

Early Warning Services$221K — $276K *
Information Technology
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in computer science, IT, Cyber Security, or related field.
  • 15+ years in information technology/security with various security technologies.
  • 3+ years of hands-on experience in security governance and risk management.
  • Expertise in network and application security design and operational standards.
  • Strong knowledge of security tools and frameworks including ISO, PCI, and NIST.
  • Experience with cloud security standards and solutions.
  • Ability to evaluate processes for compliance with policies.

Responsibilities

  • Create and manage a model to identify and resolve security risks.
  • Lead strategies for the Security Posture Management program.
  • Collaborate with teams to maintain awareness of security posture and improvement opportunities.
  • Establish effective relationships across the enterprise to foster a strong risk culture.
  • Ensure controls meet compliance and business objectives while addressing risk management needs.
  • Review and consult on processes from a controls perspective to design new controls.
  • Develop and present risk reporting frameworks and metrics to monitor control effectiveness.

Benefits

  • Comprehensive healthcare coverage including medical, dental, and vision plans.
  • 401(k) plan with a 100% company match on your first 6% deferral.
  • Flexible time off policy and 11 paid holidays plus a volunteer day.
  • 12 weeks of paid parental leave for new parents.
  • Support for family planning through various stages including fertility and adoption.
Full Job Description
Positions located in Scottsdale, San Francisco, Chicago, or New York follow a hybrid work model to allow for a more collaborative working environment.

Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment Visa sponsorship.

Overall Purpose:

Top technical subject matter expert providing technical and risk management expertise in improving and expanding the observability and reporting on the Security Posture of the Company. This position supports the enterprise-wide Information Security program as a trusted technical advisor by empowering team members to make risk-aware decisions in accordance with Early Warning's compliance, regulatory and departmental policy and procedures. Provides the primary measure of confidence that the security features, practices, procedures, and architecture of the security program accurately mediate and enforce the security policy.

Essential Functions:
  • Create and manage the operating model for identifying and resolving security risks and posture drift.
  • Lead initiatives and strategies in support of the Security Posture Management program.
  • Own ensuring that business goals and risks are adequately addressed; collaborate and consult with enterprise cross-functional teams to maintain continuous awareness of the enterprise's Security Posture and identify improvement opportunities.
  • Establish effective working relationships across the enterprise to foster a strong risk culture by supporting stakeholders in owning and managing their risks and controls.
  • Ensure controls are successfully designed and implemented to meet Compliance requirements and business objectives. Manage relationships cross-functionally to integrate alignment with organizational strategies while addressing risk management needs.
  • Review new processes from a control's perspective. Consult with process owners to design and implement new controls.
  • Improve risk and control environment by providing subject matter technical expertise on enhancing the design and effectiveness of Security's control program while aligning with compliance and technical needs.
  • Develop, execute, and present the risk reporting framework ensure risk mitigation activities are performed timely. Select appropriate metrics (KRI/KPI's) to monitor adequacy and effectiveness of the control environment. Monitor remediation efforts to closure, including review of supporting evidence.
  • Develop and enhance documentation and reporting standards to support oversight of the enterprise's Security Posture and ensure consistent execution and coverage across the enterprise supported through a stakeholder-approved policy-driven governance program.
  • Supports the company's commitment to risk management and protecting the integrity and confidentiality of systems and data.


Minimum Qualifications:
  • Education and experience typically obtained through completion of a bachelor's degree in computer science, Information Technology, Cyber Security, or related field.
  • Typically 15 or more years of progressive related information technology or information security work experience with various types of information security-related technologies. including firewalls, IDS, vulnerability management, anti-virus, data loss prevention, two factor authentication, and VPN.
  • 3 or more years of experience with the security, regulatory, and privacy controls environment, and security governance, regulatory landscape, risk assessment, and risk management principles and techniques.
  • Demonstrated advanced level experience with network security design and protection, application development, application security issues, operating system security, hardening standards and protection mechanisms.
  • Strong technical knowledge in the area of security tools, application security design and architecture; secure network design and architecture, server security, and workstation security.
  • Ability to articulate the practical and technical application of the following standards: (ISO, PCI and NIST/FISMA)
  • Strong understanding and experience with Information technology systems and processes, network infrastructure, data architecture, data processes, protocols, and auditing and monitoring processes.
  • Strong understanding and experience with Cyber and cloud security standard frameworks, architecture, design, operations, controls, technology, solutions, and service orchestration.
  • Experience evaluating process and configurations for compliance with policies and regulations.
  • Respected subject matter expert with high level of integrity, effective interpersonal and communication skills, and executive presence.
  • Strong experience developing and tracking information security related KPIs and KRIs.
  • Background and drug screen.


The above job description is not intended to be an all-inclusive list of duties and standards of the position. Incumbents will follow instructions and perform other related duties as assigned by their supervisor.

Preferred Qualifications:
  • Expertise in ISO 27002, PCI DSS 3.2 or current, NIST 800-53a, SIG, FFIEC handbooks, SOC2 Type II, GLBA, FCRA, NYDFS, data privacy.
  • Certification in one of CISA, CISM, CISSP, CCSP, CRISC, GSNA, CGIH, or equivalent
  • Project or Process management experience.


Working conditions consist of a normal office environment. Work is primarily sedentary and requires extensive use of a computer and involves sitting for periods of approximately four hours. Work may require occasional standing, walking, kneeling, and reaching. Must be able to lift 10 pounds occasionally and/or negligible amount of force frequently. Requires visual acuity and dexterity to view, prepare, and manipulate documents and office equipment including personal computers. Requires the ability to communicate with internal and/or external customers.

Employee must be able to perform essential functions and physical requirements of position with or without reasonable accommodation.

The base pay scale for this position in:
New York, NY/ San Francisco, CA in USD per hour is: $221,000 - $276,000.
Additionally, candidates are eligible for a discretionary incentive plan and benefits.

This pay scale is subject to change and is not necessarily reflective of actual compensation that may be earned, nor a promise of any specific pay for any specific candidate, which is always dependent on legitimate factors considered at the time of job offer. Early Warning Services takes into consideration a variety of factors when determining a competitive salary offer, including, but not limited to, the job scope, market rates and geographic location of a position, candidate's education, experience, training, and specialized skills or certification(s) in relation to the job requirements and compared with internal equity (peers). The business actively supports and reviews wage equity to ensure that pay decisions are not based on gender, race, national origin, or any other protected classes.

Some of the Ways We Prioritize Your Health and Happiness

  • Healthcare Coverage - Competitive medical (PPO/HDHP), dental, and vision plans as well as company contributions to your Health Savings Account (HSA) or pre-tax savings through flexible spending accounts (FSA) for commuting, health & dependent care expenses.
  • 401(k) Retirement Plan - Featuring a 100% Company Safe Harbor Match on your first 6% deferral immediately upon eligibility.
  • Paid Time Off - Flexible Time Off for Exempt (salaried) employees, as well as generous PTO for Non-Exempt (hourly) employees, plus 11 paid company holidays and a paid volunteer day.
  • 12 weeks of Paid Parental Leave
  • Maven Family Planning - provides support through your Parenting journey including egg freezing, fertility, adoption, surrogacy, pregnancy, postpartum, early pediatrics, and returning to work.


And SO much more! We continue to enhance our program, so be sure to check our Benefits page here for the latest. Our team can share more during the interview process!

Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

About Early Warning Services

Early Warning Services is a financial services company that provides fraud prevention and risk management solutions to banks, credit unions, and other financial institutions. The company was founded in 1990 and is headquartered in Scottsdale, Arizona. Early Warning Services offers a variety of products and services, including identity verification, account verification, and payment authentication. The company's solutions are designed to help financial institutions reduce fraud and improve the customer experience.
Learn more about Early Warning Services
Size
1,000 employees
Industry

Similar Jobs

More Jobs at Early Warning Services

More Information Technology Jobs

Find similar Principal - AI Technology Risk jobs: