SoFi

SoFi

Staff Cybersecurity Controls Specialist

New York City · Staff+

Sponsorship not specifiedDetected 6 days ago
CybersecurityAuditingCommunicationCollaborationProblem SolvingInternal Audit

About the role

  • The Staff Cybersecurity Controls Specialist is responsible for working with information security partners to document, manage, and monitor progress toward achieving risk mitigation.
  • This position is within the first line-of-defense (1LOD) and requires coordination with second line-of-defense (2LOD) partners and auditors in support of their activities.
  • Additionally, this role will promote and support security risk awareness activities.

Responsibilities

  • Partner with security leaders and staff to identify and document risks related to information security objectives
  • Drive accountability with process owners to ensure timely identification and remediation of security-related control issues
  • Maintain a comprehensive understanding of existing and emerging regulatory requirements, operational processes, inherent risks, and internal policies & practices to provide advice to stakeholders.

Requirements

  • Minimum 7 years of experience in cybersecurity risk management in a financial services and/or banking operating environment
  • Experience with interacting and solutioning with information security teams to document and measure control effectiveness
  • Experience collaborating across multiple teams and enterprise-wide
  • Strong ability to promote a culture of ownership, accountability, and collaboration
  • Strong understanding of risk management frameworks and best practices
  • Ability to balance multiple critical priorities simultaneously
  • Experience in highly-matrixed, fast paced environments
  • A Bachelor's Degree or 4 years of relevant experience in lieu of a degree

Compensation

  • The base pay range for this role is listed below.
  • Final base pay offer will be determined based on individual factors such as the candidate's experience, skills, and location.

Benefits

  • To view all of our comprehensive and competitive benefits, visit our Benefits at SoFi page!

Company info

  • Shape a brighter financial future with us.
  • Together with our members, we're changing the way people think about and interact with personal finance.
  • We're a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals.
  • The industry is going through an unprecedented transformation, and we're at the forefront.
  • We're proud to come to work every day knowing that what we do has a direct impact on people's lives, with our core values guiding us every step of the way.
  • Join us to invest in yourself, your career, and the financial world.
  • Management and oversight of risks and controls for information security objectives across the enterprise
  • Execute formal Risk and Control Self-Assessment (RCSA) activities in coordination with security risk owners
  • Work with 2LOD and audit teams to coordinate monitoring activities and objectives
  • Prepare committee materials, briefings, summary reports, and other documentation for executive-level audiences
  • Assist with preparation of training materials related to information security risks
  • Exceed timeliness goals and meet deadlines for mitigating issues
  • Provide input and subject matter guidance on information security policies and standards
  • Adhere to risk and compliance policies.
  • Communicate information security risk posture to senior management and stakeholders
  • What you'll need:
  • Minimum 7 years of experience in cybersecurity risk management in a financial services and/or banking operating environment; specifically managing first or second line of defense risk and controls activity
  • External audit, internal audit, or 2LOD information security risk experience
  • Strong verbal and written communication skills

This listing is sourced directly from SoFi's careers page and normalized into a canonical job model.