- Company Name
- Investigo Government Solutions (IGS)
- Job Title
- Information Security Risk Management Lead
- Job Description
-
**Job Title:** Information Security Risk Management Lead
**Role Summary:**
Lead the design, implementation, and ongoing management of enterprise and operational information security risk frameworks. Act as a trusted advisor and independent reviewer of security processes, ensuring effective identification, measurement, monitoring, and mitigation of security risks across a global, high‑volume, regulated organization.
**Expectations:**
- Provide strategic direction for security risk posture in a dynamic, matrixed environment.
- Deliver credible challenge and independent validation of security controls and governance.
- Maintain alignment with Basel, industry best practices, and evolving threat landscapes.
**Key Responsibilities:**
- Develop, implement, and maintain Operational Risk Management frameworks in line with Basel and industry standards.
- Lead risk assessments, threat modeling, and gap analyses for cyber resilience, cloud security, incident response, and related domains.
- Review and challenge information security policies, processes, and controls; recommend improvements.
- Advise senior leadership on risk exposure and mitigation strategies.
- Coordinate with cross‑functional teams and external auditors to ensure compliance with NIST CSF, ISO 27001, and other frameworks.
- Manage and report on risk metrics using GRC tools (e.g., Archer) and MS Office (PowerPoint, Excel, Visio, Project).
**Required Skills:**
- 10+ years in information security governance, operations, and risk management.
- Proven experience in regulated, high‑transaction environments with continuous availability requirements.
- Strong leadership and influencing skills within matrixed, global organizations.
- Deep knowledge of cyber resilience, cloud security, threat management, and incident response.
- Proficiency with NIST CSF, ISO 27001, Basel operational risk frameworks.
- Advanced MS PowerPoint and Excel; familiarity with Visio, Project, and GRC platforms (Archer).
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Cybersecurity, Information Management, or related field.
- Professional certifications preferred: CISSP, CISM, CISA, CRISC.