Third Party Cyber Resilience-Director

Found in: Talent US C2 - 2 weeks ago


New York, United States SMBC Group Full time

The anticipated salary range for this role is between $194,000.00 and $224,000.00. The specific salary offered to an applicant will be based on their individual qualifications, experiences, and an analysis of the current compensation paid in their geography and the market for similar roles at the time of hire. The role may also be eligible for an annual discretionary incentive award. In addition to cash compensation, SMBC offers a competitive portfolio of benefits to its employees.

Role Description

• Responsible for building a Third-Party Cyber Resilience program designed to increase planning and crisis response capabilities supporting third party risk management, vendor management, information technology, data management, cybersecurity, cyber resilience, and operational resilience management across various businesses, group companies, and functions of the bank and reporting to executive leadership, as necessary.
• Design and participate in cybersecurity exercising involving 3rd party incident and crisis response engagement. 
• Identify and implement cyber incident readiness and third-party cyber resilience related improvements in alignment with regulatory expectations.
• The Cyber Resilience department is a 1st Line of Defense (LOD) in its role of monitoring and assessing business practices, security, and technology as it related to Resilience. The Information Security Group implements a framework designed to protect data and information assets from a wide range of threats to ensure resilience, business continuity, minimize disruption, and to maximize returns on investments and business opportunities.
• Reporting to the Director of Cyber Resilience Governance, the Director supports the 1st LOD Information Security Group Department Americas Division’s (GPDAD) managing activities related to Cyber Incident Readiness focusing on Third-Party Resilience for the Combined U.S. Operations (CUSO) in accordance with US Regulations, Head Office policies and industry practices for Information Security and Operational Resilience

Role Objectives

• Maintain approved annual budgetary amount for the approved cyber incident readiness and third-party cyber resilience related projects.
• Maintain interfaces /relationships with Business, Technology, Operational Resilience including Business Continuity, other SMBC AD entities and other SMBC regions’ key stakeholders
• Develop, enhance, and implement cyber incident readiness and third-party resilience processes, policies, standards, and controls aligning with and complementing the existing business and technology incident response processes and plans.
• Lead cyber incident readiness maturity related projects to achieve organizational objectives.
• Actively participate in Cyber Incident Response Team in managing third-party incidents to provide resilience guidance and management through resolution including post analysis review of vendor and remediation activities. 
• Review vendor (third-party) contracts and recommend changes to improve third-party cyber resilience capabilities, incident response communication, and increased visibility with third parties.
• Support communication with third parties during cyber incident, zero-day threat or high vulnerability environment event. Obtain third-party situational awareness and status on threat mitigation instructions. 
• Design and participate in cybersecurity exercising involving third-party incident and crisis response engagement. Coordinate continuous improvement of third-party incident response coordination.
• Support group companies and Incident Response SOC in the creation of scenario-based workarounds, communications, and cyber playbooks for critical vendors and important business services.
• Partner with Third Party Risk Management, Vendor Management and Threat & Vulnerability Management to create resilience alignment to include information sharing, controls aggregation, risk management, data management, creation of real time data analysis and threat statistic to the Information Security Group and Operational Resilience functions. 
• Support coordination of cyber resilience related diagnostic statements during the annual Cyber Risk Institute (CRI) profile validation effort including reporting status, maturity determination, evidence gathering from internal stakeholders and identifying improvement recommendations/new projects.
• Develop cyber incident readiness and third-party cyber resilience readiness related reporting to support cyber resilience governance executive reporting.
• Plan and deliver cyber incident readiness and third-party resilience related education to the cross-functional and cross-entity stakeholders.
• Understand the impact of third-party risk as it relates to both firm and industry wide impacts to technical and security dependencies and single points of failure. 
• Understand changes related to regulatory, new product/initiative, processes, controls, events, issues, etc., in the IT, data management, cybersecurity, third party, and operational resiliency domains that may impact the operational risk profile of the bank.
• Develop increased awareness of third-party resilience working with business, functional and SMBC AD entity stakeholders. 

Qualifications and Skills

• Well-versed in Third Party Resilience to include technology, incident response and cyber risk practices with the ability to connect and align with the firm’s operational resilience processes and framework.
• Significant direct work experience within the financial services industry with focus on incident management, risk management, regulatory, information technology, data management, cybersecurity, operational resilience, compliance, or audit experience.
• Foundational knowledge of enterprise risk management industry practices
• Working knowledge of Third Party/ Vendor/Supplier related technology and cyber risk management process and controls, industry practices, and frameworks (e.g., NIST, ISO).
• Detail oriented, with proven ability to question the status quo and apply resilience activities to enhance capabilities, as appropriate
• Strong organizational skills, with proven ability to successfully manage multiple, concurrent priorities and team members as the program is built out.
• Demonstrated ability to influence a group of diverse stakeholders
• Ability to communicate and work effectively in a matrixed environment and across various organizational levels, where flexibility, collaboration, and adaptability are important
• Ability to work independently and attention to detail
• Foundational knowledge of banking laws and regulations (FFIEC, BCBS, FCA, PRA, BoE, etc.)
• Maintain a cyber threat mindset to understand underlying risks and weaknesses to properly assist in mitigating and enhancement activities
Education & Qualifications
• Bachelor’s/University degree
• Professional certifications such as Certified Cloud Security Professional (CCSP), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC), AWS Certified Practitioner, Microsoft Certified Azure Fundamentals etc. are preferred 



  • New York, United States QBE Full time

    Primary Details Time Type: Full time Worker Type: Employee The Opportunity Build QBE’s Global Cyber Services strategy including in-house and vendor capabilities with a goal of supporting growth and profitability across the global cyber portfolio. Primary Responsibilities - Build QBE’s global Cyber services strategy taking into consideration the...

  • Compliance and Legal, Third Party Risk Management, Associate

    Found in: Careerbuilder One Red US C2 - 2 weeks ago


    New York, NY, United States Goldman Sachs Full time

    Global Compliance Our division prevents, detects and mitigates compliance, regulatory and reputational risk across the firm and helps to strengthen the firm's culture of complianceCompliance accomplishes these through the firm's enterprise-wide compliance risk management programAs an independent control function and part of the firm's second line of...


  • New York, United States Pierce Technology Corp Full time

    Job DescriptionJob DescriptionAssume management of the security risk management process.Lead a team focused on collaborating and helping business units identify their security related risks.Ensure alignment of security policy, standards, and controls with the enterprise security risk management framework to produce scalability and flexibility.Working across...


  • New York, United States Pierce Technology Corp Full time

    Job DescriptionJob DescriptionAssume management of the security risk management process.Lead a team focused on collaborating and helping business units identify their security related risks.Ensure alignment of security policy, standards, and controls with the enterprise security risk management framework to produce scalability and flexibility.Working across...

  • Cyber Risk Management Lead

    Found in: Appcast Linkedin GBL C2 - 2 weeks ago


    New York, United States Pierce Full time

    Assume management of the security risk management processLead a team focused on collaborating and helping business units identify their security related risksEnsure alignment of security policy, standards, and controls with the enterprise security risk management framework to produce scalability and flexibilityWorking across the security teams, and...

  • Third Party Follow-Up Representative

    Found in: Resume Library US A2 - 1 day ago


    Hackensack, New Jersey, United States Hackensack Meridian Health Full time

    Overview: Our team members are the heart of what makes us better.   At Hackensack Meridian Health we help our patients live better, healthier lives — and we help one another to succeed. With a culture rooted in connection and collaboration, our employees are team members. Here, competitive benefits are just the beginning. It’s also about how we...

  • Third Party Follow-Up Representative

    Found in: Resume Library US A2 - 1 week ago


    Eatontown, New Jersey, United States Hackensack Meridian Health Full time

    Overview: Our team members are the heart of what makes us better.   At Hackensack Meridian Health we help our patients live better, healthier lives — and we help one another to succeed. With a culture rooted in connection and collaboration, our employees are team members. Here, competitive benefits are just the beginning. It’s also about how we...

  • Cyber Risk Management Lead

    Found in: Resume Library US A2 - 2 weeks ago


    New York County, New York, United States Pierce Technology Corp Full time

    Assume management of the security risk management process. Lead a team focused on collaborating and helping business units identify their security related risks. Ensure alignment of security policy, standards, and controls with the enterprise security risk management framework to produce scalability and flexibility. Working across the security teams,...


  • New York, United States Sumitomo Mitsui Banking Corporation Full time

    SMBC Group is a top-tier global financial group. Headquartered in Tokyo and with a 400-year history, SMBC Group offers a diverse range of financial services, including banking, leasing, securities, credit cards, and consumer finance. The Group has more than 130 offices and 80,000 employees worldwide in nearly 40 countries. Sumitomo Mitsui Financial Group,...

  • Internal Auditor

    Found in: Talent US C2 - 1 week ago


    New York, United States CyberSearch Full time

    Sr. Internal AuditorLocation: REMOTELength: 3-6 monthsStart: ASAPInterview: VideoThird party security risk auditor with experience performing cyber security reviews as part of the oversight of third partiesExecution of internal audit engagements and projects for a financial services client. Work under the supervision of an audit manager to execute internal...

  • Supervisor, Third Party Follow-Up

    Found in: Resume Library US A2 - 1 week ago


    Hackensack, New Jersey, United States Hackensack Meridian Health Full time

    Overview: Our team members are the heart of what makes us better.  At Hackensack Meridian Health we help our patients live better, healthier lives — and we help one another to succeed. With a culture rooted in connection and collaboration, our employees are team members. Here, competitive benefits are just the beginning. It’s also about how we support...


  • New York, United States Federal Reserve Bank of New York Full time

    Company Federal Reserve Bank of New York Working at the Federal Reserve Bank of New York positions you at the center of the financial world with a unique perspective on national and international markets and economies. You will work in an environment with a diverse group of experienced professionals to foster and support the safety, soundness, and vitality...


  • New York, United States CFSB Full time

    **JOB SUMMARY**: CFSB is seeking an experienced Director of Compliance Data Governance and Reporting. The individual is responsible for establishing and maintaining a robust data governance framework and ensuring accurate and timely compliance reporting, with a specific focus on managing compliance data from third parties. This position plays a critical role...


  • New York, United States Citi Full time

    The Cyber Investigations & Digital Forensics Group Manager is a Director level senior manager leading and directing many of the investigations posing the greatest reputational and regulatory risk to Citi. This role will lead four (4) managers and oversee the operation of ~25 investigators and digital forensic examiners conducting professional and...

  • Assurance Intern, Third Party Attestation

    Found in: Talent US C2 - 2 weeks ago


    New York, United States DemandGen Internationa Full time

    Job Summary: BDO is a place for energetic self-starters who can think and act like entrepreneurs. As an Intern in our Third Party Attestation practice, you will begin to utilize your educational background as well as your organizational skills as you serve the firm’s dynamic client base. You will assist in problem solving and fact-finding, working...

  • Director, Head of IT

    Found in: beBee jobs US - 2 weeks ago


    New York, New York, United States Kallyope Full time

    JOB SUMMARYReporting to the CFO, the Head of IT will partner across the business to drive and optimize the development, implementation, and maintenance of Kallyope's information systems to meet the Company's strategic business imperatives. This includes business applications, data strategy, network infrastructure, servers, cloud computing and storage,...


  • New York, United States jcw llc Full time

    JCW is currently working on behalf of a growing specialty insurance looking for a Director of Actuarial Reserving for their US team. In this newly created role, you will be reporting directly to the Chief Actuary and Chief Risk office and oversee the identification, measurement, monitoring, and reporting of our total reserve profile, with a particular focus...


  • New York, United States My Cooking Party Full time

    **Sales Manager, Culinary Experiential** **Location**: NYC adjacent (Remote), minimum of 5-10 years of boots on the ground NYC living **Salary**: $65-80K + health insurance stipend Are you passionate about creating unforgettable moments of fun and connection? Join My Cooking Party as our Cooking Party Sales Manager, where you'll blend your sales prowess...

  • Director, Strategy

    Found in: Resume Library US A2 - 7 days ago


    New York County, New York, United States PDX Full time

    Job Description We are looking for a Strategy Director with strong experience in CRM, Creative Strategy and program performance management. The ideal candidate should have diverse marketing strategy experience that 1) Helps provide data driven insights and leadership for client’s customer acquisition, loyalty and retention efforts 2) Collaborate with the...


  • New York, United States Columbia University School of Professional Studies Full time

    Company DescriptionColumbia University's Pre-College Programs offer high-achieving high school students the opportunity to engage in exploratory coursework at the college level, studying alongside peers from around the world. This highly selective program is open to students entering grades 9-12 and freshman year of college.Job DescriptionColumbia...