InfoSec Risk Assessment Advisor Senior
San Antonio Home Office I, United States
USAA
USAA offers competitive auto rates, no-monthly service fee banking and retirement options to all branches of the military and their family. Join now and let us serve you.Why USAA?
At USAA, our mission is to empower our members to achieve financial security through highly competitive products, exceptional service and trusted advice. We seek to be the #1 choice for the military community and their families.
Embrace a fulfilling career at USAA, where our core values – honesty, integrity, loyalty and service – define how we treat each other and our members. Be part of what truly makes us special and impactful.
The Opportunity
As a dedicated InfoSec Risk Assessment Advisor Senior, you will provide information assurance capabilities through technical consultation and guidance to the business for the interpretation and assessment of information security risk for projects, technologies, and environments. You will aim to identify and manage existing and emerging risks and integrate risk management strategies and educate risk owners across the enterprise on information security requirements and best practices. You will also ensure risks associated with business activities are effectively identified, measured, monitored and controlled and administers, and implements systems, policies and processes which serve to enhance the mitigation, reporting, and analysis of Information Security risk.
We offer a flexible work environment that requires an individual to be in the office 4 days per week. This position can be based in one of the following locations: San Antonio, TX, Plano, TX, Phoenix, AZ, Colorado Springs, CO, Charlotte, NC, Chesapeake, VA or Tampa, FL. Relocation assistance is available for this position.
What you'll do:
- Leads peers and junior team members in the execution of Information Security domain activities while anticipating efforts that will impact their team.
- Develops, publishes, maintains and/or interprets complex Information Security governance requirements (e.g. policies and standards).
- Designs, develops and optimizes repeatable methods and measurements for Information Security risk management program.
- Performs security risk assessments of complex projects, new technologies, environments, business partners and third parties.
- Influences Information Security risk management strategies; educates and consults with risk owners on best practices.
- Consults across the enterprise (advice, guidance and assistance) on Information Security risk; guides the strategic security direction of USAA technical projects, initiatives and other special projects.
- Recommends risk treatment options for technical projects, initiatives and other special projects.
- Responds both verbally and in writing to moderately complex inquiries and periodic exams from both internal control partners (e.g. legal, compliance, audit, risk) and external control partners (e.g. regulators, external auditors, third parties).
- Ensures process owners identify, develop and test Information Security controls for risk mitigation effectiveness.
- Ensures risks associated with business activities are effectively identified, measured, monitored, and controlled in accordance with risk and compliance policies and procedures.
What you have:
- Bachelor’s degree; OR 4 years of related experience (in addition to the minimum years of experience required) may be substituted in lieu of degree.
- 6 years of work experience in two or more of the eight areas Security and Risk Management, Asset Security, Security Architecture and Engineering, Communication and Network Security, Identity and Access Management (IAM), Security Assessment and Testing, Security Operations, and/or Software Development Security.
- 4 years of related experience in conducting risk assessments, recommending risk treatment options and/or developing program governance (e.g. policies and standards).
- Advanced level of business acumen in the areas of business operations, risk management, industry practices and emerging trends.
- Demonstrated risk management experience in a complex institution and/or highly matrixed environment related to banking, insurance and/or financial services.
- Knowledge of current IT risks and experience implementing security solutions.
- Knowledge of a wide range of security technologies, such as network security, database security, tokenization platforms, Data Leakage Prevention, Data Leakage Protection, Database Monitoring, Identity and Access Management systems.
- Experience with development of enterprise level policies/standards/Controls
- Experience with IT General Controls, Control Execution, Control Testing, etc. & Process Improvement, including identification of risk and controls.
- Advanced knowledge of applicable information security frameworks, standards, regulatory requirements, and controls.
- Advanced knowledge and application of security controls/mechanisms and threat/risk assessment techniques pertaining to complex data, application, and networking environments.
What sets you apart:
- Experience managing InfoSec risk management processes and procedures at a financial services company like USAA, including Program cyber risk assessments, RCSAs, application risk assessments and ratings, third party risks assessment, and issues management
- Experience collaborating with Second and Third Line teams risk management to build and operate a "risk engine" that assesses, aggregates, prioritizes and tracks remediation of InfoSec Program risks using a framework that align with USAA enterprise risk management policies and industry best practices
- Solid understanding of emerging InfoSec risks and mitigations
- Solid understanding of risk and issue lifecycle management, mitigation and acceptance strategies, and risk "burndown" reporting
- Excellent written and verbal communication skills, as well as experience producing and presenting risk reporting to management
- US military experience through military service or a military spouse/domestic partner
Compensation range: The salary range for this position is: $127,310 - $243,340.
USAA does not provide visa sponsorship for this role. Please do not apply for this role if at any time (now or in the future) you will need immigration support (i.e., H-1B, TN, STEM OPT Training Plans, etc.).
Compensation: USAA has an effective process for assessing market data and establishing ranges to ensure we remain competitive. You are paid within the salary range based on your experience and market data of the position. The actual salary for this role may vary by location.
Employees may be eligible for pay incentives based on overall corporate and individual performance and at the discretion of the USAA Board of Directors.
The above description reflects the details considered necessary to describe the principal functions of the job and should not be construed as a detailed description of all the work requirements that may be performed in the job.
Benefits: At USAA our employees enjoy best-in-class benefits to support their physical, financial, and emotional wellness. These benefits include comprehensive medical, dental and vision plans, 401(k), pension, life insurance, parental benefits, adoption assistance, paid time off program with paid holidays plus 16 paid volunteer hours, and various wellness programs. Additionally, our career path planning and continuing education assists employees with their professional goals.
For more details on our outstanding benefits, visit our benefits page on USAAjobs.com.
Applications for this position are accepted on an ongoing basis, this posting will remain open until the position is filled. Thus, interested candidates are encouraged to apply the same day they view this posting.
USAA is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Tags: Banking Compliance Governance IAM Monitoring Network security Risk assessment Risk management Security assessment STEM
Perks/benefits: Career development Competitive pay Flex hours Flex vacation Health care Insurance Relocation support Wellness
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.