Manager of Cybersecurity Strategy and Governance
This position is an onsite role available at any Huntington Corporate office location: Birmingham, AL; Tupelo, MS; Atlanta, GA; Houston, TX; Dallas/Houston, TX; Minnetonka, MN; or Detroit, MI.
About the Role
The Manager of Cybersecurity Strategy and Governance supports the execution of strategic cybersecurity initiatives, maintains governance processes, and collaborates with Cybersecurity teams to enhance the organization's security posture. Reporting to the Director of Cybersecurity Strategy, Innovation, and Governance (DCSIG), this role translates strategic direction into actionable workstreams, partners across cybersecurity and business units, and promotes governance discipline, control maturity, and innovation enablement.
Responsibilities
- Support the design and execution of a comprehensive cybersecurity strategy aligned with business objectives, risk management goals, regulatory guidance, and long-term growth.
- Operationalize components of the cybersecurity Strategy, Governance, and Innovation roadmap in partnership with the DCSIG and Cybersecurity Leadership team.
- Track progress against defined maturity goals and report key milestones, risks, and dependencies to leadership.
- Continuously assess and refine the strategy to address emerging threats, technological advancements, banking trends, and evolving regulatory requirements.
- Support the lifecycle of cybersecurity policies and standards, including drafting, reviews, socialization, and updates, aligned with regulations and industry standards (e.g., FFIEC, NIST, GLBA, SOX, PCI DSS, CRI, ISO 27001).
- Implement governance processes to ensure alignment with regulatory requirements and internal risk frameworks.
- Coordinate inputs to governance forums, including meeting materials, charters, and action item follow-ups.
- Maintain and update the cybersecurity risk and control matrix (RCM) to reflect the current-state control environment and ownership.
- Partner with internal stakeholders to collect and validate cybersecurity-related inputs into enterprise risk assessments, RCSAs, and self-assessments.
- Track and support closure of cybersecurity audit issues, regulatory findings, and control remediation items.
- Collaborate with cyber operations, engineering, and architecture teams to pilot and integrate innovative capabilities.
- Participate in process improvement efforts, including current state mapping, metric tracking, and performance analysis.
- Develop, maintain, and operationalize cybersecurity metrics and dashboards for executive and risk committee reporting.
- Ensure data accuracy and alignment of metrics with business outcomes and program maturity goals.
- Automate and streamline reporting processes to reduce manual data collection efforts.
- Coordinate working groups, task forces, and project teams related to cybersecurity governance and strategy implementation.
- Facilitate collaboration across Legal, Compliance, Risk, and Technology functions to ensure cohesive program execution.
- Serve as a resource for teams seeking clarification or support related to cybersecurity policies, controls, or governance processes.
Requirements
- Bachelor’s degree in Cybersecurity, Risk Management, Information Systems, or a related field, or 4+ additional years of equivalent experience.
- 5+ years of experience in cybersecurity, risk, compliance, or governance functions.
- 3+ years of experience utilizing cybersecurity frameworks (e.g., NIST CSF, FFIEC CAT, ISO 27001, CRI).
- 3+ years of experience with regulatory and risk management practices, particularly in financial services or regulated industries.
Preferred Qualifications
- Proven experience managing cross-functional projects and delivering results in matrixed environments.
- Strong communication and interpersonal skills, with the ability to translate technical concepts into business terms.
- Proficiency in GRC platforms, data visualization tools, and metrics reporting.
- Detail-oriented with strong organizational and execution skills.
- Ability to thrive in a fast-paced environment with shifting priorities and multiple workstreams.
Workplace Type
This is an office-based role. Huntington offers a hybrid work approach for eligible positions, combining in-office and remote work. Remote roles may have opportunities to gather in offices for key moments.
Pay
The compensation range for this position is $102,000 - $208,000 annual salary. Actual compensation varies based on factors such as location, experience, and education. Eligible colleagues may also participate in an applicable incentive compensation plan.
Benefits
- Health insurance coverage
- Wellness program
- Life and disability insurance
- Retirement savings plan
- Paid leave programs
- Paid holidays and paid time off (PTO)