Head of Cybersecurity Risk Management and Incident Response
St. Louis, MO / New York, NY
Full Time Executive-level / Director USD 220K - 230K
Focus Financial Partners
Primary Responsibilities
- Develop and lead the enterprise cybersecurity risk management framework, including risk assessments, controls, and reporting.
- Identify, analyze, and assess cybersecurity threats, vulnerabilities, and risks across infrastructure, applications, and third-party vendors.
- Partner and collaborate with IT, Legal, Compliance, and ERM teams to maintain a robust cyber risk posture.
- Establish key risk indicators (KRIs), control standards, and risk mitigation plans; ensure timely remediation of findings.
- Lead cyber risk governance initiatives, including executive and board-level reporting, risk registers, and audit support.
- Evaluate and implement cyber risk tools and platforms for threat intelligence, risk scoring, and control tracking.
- Establish and Implement vulnerability management program.
- Oversee third-party risk assessments related to cybersecurity, including cloud providers, SaaS vendors, and managed services.
- Stay informed on current and emerging cybersecurity threats, regulatory changes (e.g., NIST, ISO 27001, NYDFS, GDPR), and best practices.
- Drive incident response readiness and response, conduct tabletop exercises focused on cyber risk impacts.
- Build and lead a team of cyber risk professionals; foster a culture of risk awareness across the organization.
Qualifications
- 10+ years of experience in cybersecurity, with at least 5 years in cyber risk management within a financial services setting (e.g., banking, asset management, fintech, insurance).
- In-depth understanding of financial regulatory requirements impacting cybersecurity (e.g., NYDFS Part 500, GLBA, SOX, FFIEC, GDPR)
- Proven track record of building and managing cyber risk programs in a regulated environment.
- Familiarity with GRC platforms used in finance (e.g., Drata, Archer, OneTrust).
- Exceptional communication skills with the ability to translate technical risk into business impact for executive and board-level audiences.
- Relevant certifications such as CISSP, CRISC, CISM, or CISA strongly preferred.
- Bachelor's or Master’s degree in Information Security, Risk Management, Computer Science, or a related field.
#LI-CH1
Tags: Banking CISA CISM CISSP Cloud Compliance Computer Science CRISC FFIEC Finance FinTech GDPR GLBA Governance Incident response ISO 27001 NIST Risk assessment Risk management RMF SaaS SOX Strategy Threat intelligence Vulnerabilities Vulnerability management
Perks/benefits: Salary bonus
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.