Principal, Cybersecurity Risk
Indexed description
The Expertise And Skills You Bring
- Minimum 3-5 years of risk experience quantifying cyber risk scenarios and presenting data in a meaningful and insightful way to senior leaders.
- Demonstrated experience in cybersecurity risk management, assessment frameworks, and metrics reporting.
- Experience managing projects end-to-end, from initial stages of acquiring data from multiple sources and subject matter experts to the tracking, maintenance, and closure of a project, with proven ability to integrate data into risk analysis tools and communicate progress effectively across multiple lines and levels.
- Use and understanding of governance, risk, and compliance tools.
- Advanced understanding of NIST 800-53 Cybersecurity Framework, Cybersecurity Risk Institute (CRI), and FAIR
- CRISC, CISSP, or CISM certifications are preferred.
- You have effective communication and excellent presentation skills to senior leaders.
- You can deep dive into metrics that will both (1) quantify the work being done and (2) quantify how cyber risk position has improved.
- Critical thinking skills to ask detailed questions and fully vet answers to uncover discrepancies and gaps others may not have found is a must.
- You can work across business lines to influence change and help mitigate cyber risk.
- You have an intermediate understanding of risks pertaining to the following: cloud security, access controls, encryption, vendor security, data exfiltration, application security, perimeter security, customer protection, privileged access, denial of service, unpatched vulnerabilities, and end of life software.
- You operate in a fast-paced environment and can complete analyses quickly and accurately integrating new cybersecurity data into risk models as it emerges.
- You bring an investigator mindset to deep dive into metrics to understand and communicate actionable risk to business and technology groups.
- Determining the appropriate controls for cybersecurity risks
- Working with asset inventory and asset management
- Evaluating multiple sources, reports, industry trends to compare risk related findings to existing ECS policies and uncover gaps and opportunities for process improvement.
- Determining what, who, and where changes are warranted to close gaps, working with appropriate contacts to draft policy enhancement ensuring continued progress.
Fidelity’s Onsite Working Model
Fidelity is transitioning to a full-time onsite working model through a phased rollout across regions and roles. Currently, some roles and locations require 100% onsite presence, while others require less. Onsite expectations are likely to evolve as the rollout continues. This transition does not apply to fully remote roles.
Certifications
Category:
Information Technology
Please be advised that Fidelity’s business is governed by the provisions of the Securities Exchange Act of 1934, the Investment Advisers Act of 1940, the Investment Company Act of 1940, ERISA, numerous state laws governing securities, investment and retirement-related financial activities and the rules and regulations of numerous self-regulatory organizations, including FINRA, among others. Those laws and regulations may restrict Fidelity from hiring and/or associating with individuals with certain Criminal Histories.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search