What you'll do- Develop and maintain the information security policy and standards library, aligning it with business priorities, regulatory expectations, and control objectives
- Lead independent assessments of the information security program, including regulatory examinations and third-party evaluations
- Identify technology risks across a complex business environment and drive mitigation aligned with our firm's standards and control expectations
- Investigate data privacy inquiries and privacy-related events, assess business impact, and coordinate timely response activities
- Partner with technology, legal, compliance, and business stakeholders to translate risk findings into practical remediation plans
- Advise control owners on policy interpretation, risk treatment, and evidence expectations for assessments and examinations
- Prepare clear reports for management on team activity, emerging risks, remediation progress, and key decisions
- Maintain accurate risk, policy, privacy, and assessment documentation to support transparency, accountability, and examination readiness
- Strengthen governance processes by identifying recurring issues and recommending improvements that reduce risk and improve readiness
What's required- 8-10 years of experience in information security governance, risk, and compliance or related fields
- Bachelor's degree in information security, information systems, information technology, or another relevant discipline
- Extensive experience managing and responding to regulatory examinations and third-party evaluations
- Hands-on experience working with vendor assessment tools, such as SIG, OneTrust, and KY3P
- Proven track record writing and implementing information security policies and standards
- In-depth knowledge of global data privacy laws and regulations, including the California Consumer Privacy Act and General Data Protection Regulation
- Experience managing technology risks in a complex business environment
- Exceptional written and verbal communication skills, with the ability to present risk concepts clearly to management and cross-functional stakeholders
- Commitment to the highest ethical standards
We take care of our peopleWe invest in our people, their careers, their health, and their well-being. When you work here, we provide:
- Fully-paid health care benefits
- Generous parental and family leave policies
- Mental and physical wellness programs
- Volunteer opportunities
- Non-profit matching gift program
- Support for employee-led affinity groups representing women, minorities and the LGBT+ community
- Tuition assistance
- A 401(k) savings program with an employer match and more
The annual base salary range for this role is $175,000-$275,000 (USD), which does not include discretionary bonus compensation or our comprehensive benefits package. Actual compensation offered to the successful candidate may vary from posted hiring range based upon geographic location, work experience, education, and/or skill level, among other things.