SoFi
Staff Cybersecurity Controls Specialist
New York City · Staff+
Sponsorship not specifiedDetected 6 days ago
CybersecurityAuditingCommunicationCollaborationProblem SolvingInternal Audit
About the role
- The Staff Cybersecurity Controls Specialist is responsible for working with information security partners to document, manage, and monitor progress toward achieving risk mitigation.
- This position is within the first line-of-defense (1LOD) and requires coordination with second line-of-defense (2LOD) partners and auditors in support of their activities.
- Additionally, this role will promote and support security risk awareness activities.
Responsibilities
- Partner with security leaders and staff to identify and document risks related to information security objectives
- Drive accountability with process owners to ensure timely identification and remediation of security-related control issues
- Maintain a comprehensive understanding of existing and emerging regulatory requirements, operational processes, inherent risks, and internal policies & practices to provide advice to stakeholders.
Requirements
- Minimum 7 years of experience in cybersecurity risk management in a financial services and/or banking operating environment
- Experience with interacting and solutioning with information security teams to document and measure control effectiveness
- Experience collaborating across multiple teams and enterprise-wide
- Strong ability to promote a culture of ownership, accountability, and collaboration
- Strong understanding of risk management frameworks and best practices
- Ability to balance multiple critical priorities simultaneously
- Experience in highly-matrixed, fast paced environments
- A Bachelor's Degree or 4 years of relevant experience in lieu of a degree
Compensation
- The base pay range for this role is listed below.
- Final base pay offer will be determined based on individual factors such as the candidate's experience, skills, and location.
Benefits
- To view all of our comprehensive and competitive benefits, visit our Benefits at SoFi page!
Company info
- Shape a brighter financial future with us.
- Together with our members, we're changing the way people think about and interact with personal finance.
- We're a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals.
- The industry is going through an unprecedented transformation, and we're at the forefront.
- We're proud to come to work every day knowing that what we do has a direct impact on people's lives, with our core values guiding us every step of the way.
- Join us to invest in yourself, your career, and the financial world.
- Management and oversight of risks and controls for information security objectives across the enterprise
- Execute formal Risk and Control Self-Assessment (RCSA) activities in coordination with security risk owners
- Work with 2LOD and audit teams to coordinate monitoring activities and objectives
- Prepare committee materials, briefings, summary reports, and other documentation for executive-level audiences
- Assist with preparation of training materials related to information security risks
- Exceed timeliness goals and meet deadlines for mitigating issues
- Provide input and subject matter guidance on information security policies and standards
- Adhere to risk and compliance policies.
- Communicate information security risk posture to senior management and stakeholders
- What you'll need:
- Minimum 7 years of experience in cybersecurity risk management in a financial services and/or banking operating environment; specifically managing first or second line of defense risk and controls activity
- External audit, internal audit, or 2LOD information security risk experience
- Strong verbal and written communication skills
This listing is sourced directly from SoFi's careers page and normalized into a canonical job model.