Member of Information Security (Global)
Anchorage Digital
Mission & Outcomes of the Position
- Assist the Deputy CISO and the Global Information & Security Team in building and maintaining the overall Information Security and IT Risk Management Program
- Maintain enterprise information security and IT risk management program commensurate with national and international standards (e.g. NIST, FFIEC, ISO, SOC 2)
- Execute key team projects from start to finish, including but not limited to risk assessments, cybersecurity assessments, threat models, requirement mapping, and gap analyses
- Develop, implement, and monitor meaningful reporting, metrics, analysis, and controls commensurate with business needs and regulatory expectations
- Assist the Deputy CISO and the Global Information & Security Team to operationalize established security strategy and track initiatives from conception to completion, in concert with external technology providers
- Maintain entity controls and identify, report, and control incidents relevant to the services offered by the business lines and supported jurisdictions
- Drive resolution of IT security internal and external audit issues, including developing and implementing management action plans
- Manage periodic security tests, including internal and external penetration testing and phishing exercises
Job Description
- Expert knowledge and wide-ranging experience with the regulatory and industry frameworks/standards/methodologies/tech: SOC 1/2, ISO 27001, NIST 800-53, NIST Cybersecurity Framework, cloud environments, HSMs, data center controls, change management, and logical security
- Fundamental understanding of business continuity program management at a regulated financial institution
- Ability to quickly grasp new technologies and systems, articulate related risks, and develop appropriate risk mitigating measures
- Comprehension of core information security principles in order to reason and continuously improve the core Anchorage Digital security model
- Deep understanding of the IT threat landscape for the industry and ability to anticipate any impact on the business with the goal to drive a proactive response
- Excellent project management skills to support stability and successful execution in a very fast moving and cross-functional environment
Overview of responsibilities, ownership, and expertise
- Expert knowledge and wide-ranging experience with the regulatory and industry frameworks/standards/methodologies/tech: SOC 1/2, ISO 27001, NIST 800-53, NIST Cybersecurity Framework, cloud environments, HSMs, data center controls, change management, and logical security
- Ability to quickly grasp new technologies and systems, articulate related risks, develop appropriate risk mitigating measures, and “connect the dots” between the company’s service offerings and products to the IT/Information Security environment
- Resolves a wide range of issues in creative ways to ensure regulatory requirements are being met, including managing and tracking findings (from risk assessments, audits, etc.) from identification to remediation
- Comprehension of core cybersecurity principles in order to reason and continuously improve the core Anchorage Digital security model
- Deep understanding of the IT threat landscape for the industry and ability to anticipate any impact on Anchorage Digital with the goal to drive a proactive response
- Excellent project management skills to support stability and successful execution in a very fast moving environment
- Experience conducting Business Impact Analyses and Business Continuity Plans with little oversight
Complexity and Impact of Work
- Assist the Deputy CISO and the Global Information & Security Team in building and maintaining the overall Information Security and IT Risk Management Program
- Execute key team projects from start to finish, including but not limited to risk assessments, cybersecurity assessments, threat models, requirements mapping, and gap analyses
- Develop meaningful reporting, metrics, analysis, and controls commensurate with business needs and regulatory expectations
- Assist the Deputy CISO and the Global Information & Security Team to operationalize established security strategy and track initiatives from conception to completion, in concert with external technology providers
- Maintain enterprise information security and IT risk management program commensurate with national and international standards (e.g. NIST, FFIEC, ISO, SOC 2)
- Maintain entity controls and identify, report, and control incidents relevant to the services offered by the business lines and supported jurisdictions
- Drive resolution of IT security internal and external audit issues, including developing and implementing management action plans
- Can work autonomously, defines priorities under broad direction, and applies problem solving skills to translate regulations and compliance obligations into technical controls, and vice-versa.
- Manage periodic security tests, including internal and external penetration testing and phishing exercises
Organizational Knowledge:
- Understanding of enterprise-level information security programs and the ability to maintain a control set and policy framework which satisfies regulatory requirements in an efficient and elegant manner
- Help build and maintain the Anchorage Digital enterprise-wide information security program commensurate with business needs as well as industry and regulatory standards, in concert with external technology providers
- Understands how the company’s priorities relate to their own area of work, and clearly communicates the ‘why’ behind the work
Communication and Influence
- Communicates proactively, takes ownership in assigned work/projects, and is comfortable asking questions when something is unclear or to further knowledge in a specific area
- Contributes to cross-functional projects, collaborates with their team and adjacent teams working directly with subject matter experts and doing meaningful translation of compliance requirements into actionable processes.
- Consistently expresses clear, thoughtful, analytical and solutions-oriented communications, whether in high-impact slides/decks, written communications in slack or email, or verbal communications.
- Ensure compliance with the changing laws and applicable regulations
- Develop key risk indicators and dashboard metrics suitable for reporting to senior management
You may be a fit for this role if you have:
- Background working on programs and the ability to manage multiple processes and projects at once while building constructive working relationships with stakeholders across the different teams,
- A strong understanding of key cloud architecture principles, cryptography, APIs, as well as appropriate enterprise security practices
- Knowledge and experience of Information Security Risk and Security Governance
- Experience participating in security incident response and coordinating activities
- Familiarity with FFIEC standards and similar regulations
- Experience working with external regulators, e.g. OCC and NYDFS
Although not a requirement, bonus points if:
- Experience working in start-ups tech and/or fin-tech companies
- Experience working as information systems auditor or consultant
- You were emotionally moved by the soundtrack to Hamilton, which chronicles the founding of a new financial system :)