Member of Information Security (Global)
Anchorage Digital
This job is no longer accepting applications
See open jobs at Anchorage Digital.See open jobs similar to "Member of Information Security (Global)" Blockchain Association.Mission & Outcomes of the Position
- Assist the Deputy CISO and the Global Information & Security Team in building and maintaining the overall Information Security and IT Risk Management Program
- Maintain enterprise information security and IT risk management program commensurate with national and international standards (e.g. NIST, FFIEC, ISO, SOC 2)
- Execute key team projects from start to finish, including but not limited to risk assessments, cybersecurity assessments, threat models, requirement mapping, and gap analyses
- Develop, implement, and monitor meaningful reporting, metrics, analysis, and controls commensurate with business needs and regulatory expectations
- Assist the Deputy CISO and the Global Information & Security Team to operationalize established security strategy and track initiatives from conception to completion, in concert with external technology providers
- Maintain entity controls and identify, report, and control incidents relevant to the services offered by the business lines and supported jurisdictions
- Drive resolution of IT security internal and external audit issues, including developing and implementing management action plans
- Manage periodic security tests, including internal and external penetration testing and phishing exercises
Job Description
- Expert knowledge and wide-ranging experience with the regulatory and industry frameworks/standards/methodologies/tech: SOC 1/2, ISO 27001, NIST 800-53, NIST Cybersecurity Framework, cloud environments, HSMs, data center controls, change management, and logical security
- Fundamental understanding of business continuity program management at a regulated financial institution
- Ability to quickly grasp new technologies and systems, articulate related risks, and develop appropriate risk mitigating measures
- Comprehension of core information security principles in order to reason and continuously improve the core Anchorage Digital security model
- Deep understanding of the IT threat landscape for the industry and ability to anticipate any impact on the business with the goal to drive a proactive response
- Excellent project management skills to support stability and successful execution in a very fast moving and cross-functional environment
Overview of responsibilities, ownership, and expertise
- Expert knowledge and wide-ranging experience with the regulatory and industry frameworks/standards/methodologies/tech: SOC 1/2, ISO 27001, NIST 800-53, NIST Cybersecurity Framework, cloud environments, HSMs, data center controls, change management, and logical security
- Ability to quickly grasp new technologies and systems, articulate related risks, develop appropriate risk mitigating measures, and “connect the dots” between the company’s service offerings and products to the IT/Information Security environment
- Resolves a wide range of issues in creative ways to ensure regulatory requirements are being met, including managing and tracking findings (from risk assessments, audits, etc.) from identification to remediation
- Comprehension of core cybersecurity principles in order to reason and continuously improve the core Anchorage Digital security model
- Deep understanding of the IT threat landscape for the industry and ability to anticipate any impact on Anchorage Digital with the goal to drive a proactive response
- Excellent project management skills to support stability and successful execution in a very fast moving environment
- Experience conducting Business Impact Analyses and Business Continuity Plans with little oversight
Complexity and Impact of Work
- Assist the Deputy CISO and the Global Information & Security Team in building and maintaining the overall Information Security and IT Risk Management Program
- Execute key team projects from start to finish, including but not limited to risk assessments, cybersecurity assessments, threat models, requirements mapping, and gap analyses
- Develop meaningful reporting, metrics, analysis, and controls commensurate with business needs and regulatory expectations
- Assist the Deputy CISO and the Global Information & Security Team to operationalize established security strategy and track initiatives from conception to completion, in concert with external technology providers
- Maintain enterprise information security and IT risk management program commensurate with national and international standards (e.g. NIST, FFIEC, ISO, SOC 2)
- Maintain entity controls and identify, report, and control incidents relevant to the services offered by the business lines and supported jurisdictions
- Drive resolution of IT security internal and external audit issues, including developing and implementing management action plans
- Can work autonomously, defines priorities under broad direction, and applies problem solving skills to translate regulations and compliance obligations into technical controls, and vice-versa.
- Manage periodic security tests, including internal and external penetration testing and phishing exercises
Organizational Knowledge:
- Understanding of enterprise-level information security programs and the ability to maintain a control set and policy framework which satisfies regulatory requirements in an efficient and elegant manner
- Help build and maintain the Anchorage Digital enterprise-wide information security program commensurate with business needs as well as industry and regulatory standards, in concert with external technology providers
- Understands how the company’s priorities relate to their own area of work, and clearly communicates the ‘why’ behind the work
Communication and Influence
- Communicates proactively, takes ownership in assigned work/projects, and is comfortable asking questions when something is unclear or to further knowledge in a specific area
- Contributes to cross-functional projects, collaborates with their team and adjacent teams working directly with subject matter experts and doing meaningful translation of compliance requirements into actionable processes.
- Consistently expresses clear, thoughtful, analytical and solutions-oriented communications, whether in high-impact slides/decks, written communications in slack or email, or verbal communications.
- Ensure compliance with the changing laws and applicable regulations
- Develop key risk indicators and dashboard metrics suitable for reporting to senior management
You may be a fit for this role if you have:
- Background working on programs and the ability to manage multiple processes and projects at once while building constructive working relationships with stakeholders across the different teams,
- A strong understanding of key cloud architecture principles, cryptography, APIs, as well as appropriate enterprise security practices
- Knowledge and experience of Information Security Risk and Security Governance
- Experience participating in security incident response and coordinating activities
- Familiarity with FFIEC standards and similar regulations
- Experience working with external regulators, e.g. OCC and NYDFS
Although not a requirement, bonus points if:
- Experience working in start-ups tech and/or fin-tech companies
- Experience working as information systems auditor or consultant
- You were emotionally moved by the soundtrack to Hamilton, which chronicles the founding of a new financial system :)
This job is no longer accepting applications
See open jobs at Anchorage Digital.See open jobs similar to "Member of Information Security (Global)" Blockchain Association.