Jobs · Education · North Carolina

Principal, Cybersecurity Risk

Fidelity Investments · Durham, NC · 1 wk ago
On-siteEducationFull-time

Fidelity will not provide immigration sponsorship for this position.

About the Role

The Enterprise Cybersecurity Risk (ECS Cyber Risk) team is seeking an experienced Principal-level risk professional to lead in the creation of cyber risk analysis pertaining to ECS. The candidate will understand current and emerging cybersecurity risks and determine key risk scenarios for the ECS Product Areas. The candidate will participate in risk/threat modeling sessions to prioritize top risks, advise on both exceptions and audit finding risk levels to drive down the number of exceptions, and accurately risk rate audit findings. The candidate will quantify cyber risk and present analyses at the technical and executive level that will allow senior management to make informed decisions based on resulting risk data.

Responsibilities

  • Quantify cyber risk scenarios and present data in a meaningful and insightful way to senior leaders.
  • Manage projects end-to-end, from acquiring data from multiple sources and subject matter experts to tracking, maintenance, and closure, integrating data into risk analysis tools.
  • Use governance, risk, and compliance tools to evaluate risks and communicate progress effectively across multiple lines and levels.
  • Deep dive into metrics to quantify both the work being done and improvements in the cyber risk position.
  • Apply critical thinking to uncover discrepancies and gaps in risk assessments.
  • Work across business lines to influence change and help mitigate cyber risk.
  • Determine appropriate controls for cybersecurity risks.
  • Evaluate asset inventory and asset management practices.
  • Analyze multiple sources, reports, and industry trends to compare risk-related findings to existing ECS policies and identify gaps or opportunities for process improvement.
  • Determine necessary changes to close gaps, working with appropriate contacts to draft policy enhancements.

Requirements

  • Minimum 3-5 years of risk experience quantifying cyber risk scenarios.
  • Demonstrated experience in cybersecurity risk management, assessment frameworks, and metrics reporting.
  • Advanced understanding of NIST 800-53 Cybersecurity Framework, Cybersecurity Risk Institute (CRI), and FAIR.
  • Intermediate understanding of risks pertaining to: cloud security, access controls, encryption, vendor security, data exfiltration, application security, perimeter security, customer protection, privileged access, denial of service, unpatched vulnerabilities, and end-of-life software.
  • Ability to operate in a fast-paced environment, completing analyses quickly and accurately while integrating new cybersecurity data into risk models.
  • Investigator mindset to deep dive into metrics and communicate actionable risk to business and technology groups.

Qualifications

  • CRISC, CISSP, or CISM certifications are preferred.
  • Effective communication and excellent presentation skills for senior leaders.

About the Team

ECS Cyber Risk provides cybersecurity risk analyses pertaining to existing and emerging risk scenarios and communicates these risks to appropriate ECS technical teams and senior leadership. This team focuses on identifying, measuring, prioritizing, and reporting on cyber risk scenarios and works both independently and across business units and technology teams to assist senior management with informed decisions and strategic direction.

Schedule

Fidelity is transitioning to a full-time onsite working model through a phased rollout across regions and roles. Currently, some roles and locations require 100% onsite presence, while others require less. Onsite expectations are likely to evolve as the rollout continues. This transition does not apply to fully remote roles.

Similar jobs

Cyber Security Principal

Federal Express CorporationMemphis, TN· 1 wk ago
Education$9k–$17k/moapply on careers.fedex.com