INFORMATION RISK MANAGEMENT LEAD

6 hours ago


Dallas, United States Lamoreaux Search Full time

INFORMATION RISK MANAGEMENT LEAD


Our global marketing communications client has a rich 100+ year history of excellence in service and growth predominantly through acquisition. Their portfolio of companies reaches over 1,500 agencies in over 100 countries connected by a parent company dedicated to leveraging their collective and individual offerings.


Role Overview:

Reporting to the Global Managing Director of Governance, Risk and Compliance, the Information Risk Management Lead is responsible for planning, strategy development and execution of Risk Management programs to measure and maintain the effectiveness of the organization’s cybersecurity, business resilience and Third-Party Risk. Key to this role is partnering throughout the organization and coordinating with all risk functions (Security, Internal Audit, Privacy, Compliance, Controls) to support the successful achievement of the organization’s risk management activities and optimizing operational performance.


The Information Risk Management Lead will evaluate the maturity of the organization’s security program and benchmark against leading practices to ensure industry leading approaches, policies, processes, and tools are implemented to mitigate and counter risks and potential threats. This role will advise on cybersecurity, business resilience and Third-Party Risk Management reference architecture leading practices, and test/ensure the effectiveness of controls, as well as assist the global family of agencies, networks, and practice groups in complying with the relevant regulations.


Performing continuous assessment of the organization’s global threat landscape, to enhance or implement control processes and tools to ensure more effective risk management. The Information Risk Management Lead will provide management and oversight of a team charged with executing daily functions and strategic initiatives, as necessary.


Key Focus Areas:

• Cyber Risk Management is a key area of focus.

• Supported by a Business Resilience Lead and a Third-Party Risk Management Lead oversee the operational day to day management and contribute to strategic implementations.

• Recruit, retain, and maintain a qualified team of security risk management professionals to protect company assets and support security risk initiatives.

• Apply a deep understanding of general security concepts and methods, including cyber strategy and transformation, cyber risk management, cybersecurity architecture, operations and monitoring, infrastructure and application security, cyber threat management, cloud security, emerging technologies security, cyber regulatory compliance and controls, cyber resiliency and business resilience, incident response and crisis management, data protection and privacy, and third-party risk management.

• Work with leaders of the Governance, Risk and Compliance team to define, publish, and maintain global information security policies and standards, taking into consideration industry standards and frameworks, such as ISO 27001, CobiT, NIST, and others.

• Identify, maintain, and refresh the organization’s top risks, and articulate their likelihood, severity and impact using specific purpose Risk Registers.

• Align information security processes with Cyber Security frameworks such as ISO27001, PCI and NIST 800-53 to ensure compliance with stated metrics and documented controls.

• Develop and maintain an operational Cyber Security Risk Framework.

• Support efforts to perform at least annually, risk assessments, and establish a robust risk and compliance program that includes the tracking of risks and findings, creation and implementation of remediation plans, mechanisms for risk acceptance, and escalation procedures.

• Measure compliance with policies and standards as part of assessing the overall cyber risk management capability of the enterprise and develop strategic plans as required.

• Provide active risk data contributions to the Information Risk Management Committee (IRMC) and Risk Sub-committee, which consists of key IT, security, and business stakeholders, to provide strategic direction for the enterprise risk governance.

• Develop risk transparency reporting and communications, with accompanying mitigation plans.

• Investigate, recommend, and follow up appropriate corrective actions for identified security deficiencies and policy exceptions.

• Provide guidance on security controls involving password and access management, segregation of duties, logging and monitoring, data encryption, data backup and recovery, disaster recovery, business continuity management, etc.

• Ensure the information security risk register is properly maintained and ensure that risk issues and other variances including risk acceptance are resolved in a timely manner.

• Oversee entitlement reviews of critical systems to protect the organization’s information assets from internal and external threats.

• Provide periodic reporting on information security issues and gaps for compliance with the enterprise information security policies, standards, and procedures among employees, contractors, alliances, and other third parties.

• Coordinate the execution of security governance and assessment control initiatives. Work with Governance, Risk and Compliance leadership while supporting IT and the business regarding efforts to implement and maintain a business continuity and disaster recovery plan for all practice groups and networks across the enterprise.


Qualifications/Experience:

• Subject Matter Expertise in IT Risk and Cyber Security Governance required.

• Subject Matter Expertise in Business Resilience and Third-Party Risk Management is preferred.

• Bachelor's degree required, preferably in computer science, information systems, engineering, business administration, or related field.

• 6+ years of defining Information Security Governance documentation, technical experience in the security aspects of multiple platforms, operating systems, software, communications and network protocols or an equivalent combination of education and work experience.

• Minimum of 5 years of Risk Management, Information Security, IT Auditing, or equivalent experience.

• Demonstrate a strong understanding of the Information Security, IT environment and its impact on business risk.

• Deep understanding of enterprise security tools preferred (i.e., SIEM, vulnerability scanners, firewalls, identity governance and administration).

• Knowledge of common information security management frameworks, such as ISO/IEC 27001, ITIL, COBIT and NIST-800 series.

• Demonstrated understanding of technological trends and developments in the areas of information security, risk management, and business continuity.

• Demonstrated managerial experience, specifically in the administration and management of the information security function.

• People and team leadership experience is needed. There is a team of 9 this person will lead.

• Strong interpersonal skills with the ability to work effectively in a matrixed organization.

• Strong project management skills, technical writing, and presentation skills.

• Ability to rapidly learn and apply advanced and emerging technical security principles, theories, and concepts.

• Experience working in a complex global environment is needed, preferably in one that was moving toward centralization.

• Certified in one or more of the following: ISO27001, CISA, CRISC, CGEIT, CISM, CISSP, CCSK, CCSP, PCI, ITIL.


Skills and Abilities:

• Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate security and risk-related concepts to technical and nontechnical audiences.

• Excellent problem solving and analytical skills, individual must be a team player, strategic and analytical thinker, able to think “big picture”, as well as focus on trends and data coupled with industry themes, and able to multi-task on projects.

• Ability to build-out security strategy aligned with business objectives that will continually improve and enhance cybersecurity within the organization.

• Demonstrate the ability to manage multiple projects under strict timelines, as well as the ability to work well in a demanding, dynamic environment and meet overall objectives.

• Possess a strong technology background with the ability to challenge or validate technology decisions from a position of knowledge and experience.

• Possess the ability to rapidly assimilate business strategies, coupled with the insight to seize high impact opportunities by applying creative problem-solving solutions.

• Track record of managing across multiple global locations, with a solid understanding of the challenges and benefits.

• Ability to lead and motivate global cross-functional, interdisciplinary teams to build-out new capabilities and achieve tactical and strategic goals.



  • Dallas, Texas, United States Dallas Risk Management, LLC Full time

    Company OverviewDallas Risk Management, LLC is a leading Managing General Underwriter for health insurance policies. Our team of experts provides tailored services to address the risks involved during the health insurance lifecycle. We exceed client expectations by offering superior results through our partnerships with top carriers.


  • Dallas, Texas, United States RISK THEORY Full time

    We are seeking an experienced Risk Management Professional to lead our Commercial Property Claims team. This role requires strong analytical skills, attention to detail, and excellent communication abilities.Key responsibilities include:Managing a portfolio of Commercial Property claims, ensuring timely resolution and minimal lossesInvestigating claims,...


  • dallas, United States Lamoreaux Search Full time

    INFORMATION RISK MANAGEMENT LEADOur global marketing communications client has a rich 100+ year history of excellence in service and growth predominantly through acquisition. Their portfolio of companies reaches over 1,500 agencies in over 100 countries connected by a parent company dedicated to leveraging their collective and individual offerings.Role...


  • Dallas, Texas, United States Risk Theory, LLC Full time

    Role SummaryWe are looking for a Risk Management Expert to handle first-party Garage Claims for Auto Dealerships and apartment complexes. This role involves managing claims from the first notice of loss through resolution/settlement and payment process, ensuring quality claim handling throughout the claim life cycle while maintaining compliance with internal...


  • Dallas, Texas, United States Novatae Risk Group Full time

    Career Opportunity:Novatae Risk Group is seeking a skilled and motivated Producer/Broker to join our team. As a key member of our sales team, you will be responsible for identifying and pursuing new business opportunities, managing client relationships, and driving revenue growth. If you have a passion for commercial insurance and a proven track record of...


  • Dallas, Texas, United States Wheeler Staffing Partners Full time

    Job SummaryWe are seeking an experienced Information Security GRC Analyst to develop, implement, and operationalize Information Security governance and risk management functions for Wheeler Staffing Partners.Key ResponsibilitiesRisk Management: Implement established risk frameworks for the Information Security program, ensuring compliance with security...


  • Dallas, Texas, United States Prime Healthcare Management Inc Full time

    We are looking for a seasoned Senior Cybersecurity Risk Manager to join our team at Prime Healthcare Management Inc. As a key member of our Security Operations team, you will be responsible for leading and coordinating in the Computer Security Incident Response and Digital Forensics operations during a security incident to identify, quantify, and neutralize...


  • Dallas, Texas, United States Novatae Risk Group Full time

    Job OverviewNovatae Risk Group is seeking a highly motivated Insurance Portfolio Executive to join our team. In this role, you will manage a portfolio of clients, focusing on relationship building and client account development. This position is based in our Dallas office.Job DescriptionThe successful candidate will have a Property & Casualty license and a...


  • Dallas, Texas, United States Echelon Risk + Cyber Full time

    We are committed to creating a secure environment at Echelon Risk + Cyber. As a Senior Security Engineer, you will play a vital role in shaping our security policies and procedures.Job DescriptionCompany Overview: Echelon Risk + Cyber is a leading cybersecurity consulting firm dedicated to defending human rights to security and privacy.About the Role: We...

  • Risk Manager

    2 months ago


    Dallas, United States Rockpoint Group Full time

    Firm Profile Rockpoint is a real estate private equity Firm headquartered in Boston with additional domestic offices in San Francisco and Dallas. Rockpoint employs a fundamental value approach to investing and targets select product types located in major markets in the United States. Rockpoint utilizes a consistent strategy across distinct return profiles...


  • Dallas, United States The Beck Group Full time

    Who we are We're The Beck Group, the largest and most innovative integrated building firm in the country. We are focused on delivering design and construction excellence on a broad range of project types. Headquartered in downtown Dallas, with offices in Atlanta, Austin, Charlotte, Denver, Fort Lauderdale, Fort Worth, Mexico City, and Tampa, we believe a...


  • Dallas, Texas, United States Palo Alto Networks, Inc. Full time

    Palo Alto Networks, Inc. is a leading provider of cybersecurity solutions. Our mission is to protect our digital way of life by providing the highest quality incident response, risk management, and digital forensic services to clients of all sizes.Job SummaryWe are seeking an experienced Cybersecurity Expert Lead - Governance and Risk Management to join our...

  • Risk Analytics Lead

    3 weeks ago


    Dallas, Texas, United States Underground Administration Full time

    Job Description:">We are seeking a highly skilled Quantitative Risk Associate Director to join our team in Dallas, Washington D.C., Jersey City, Boston or Tampa. This role offers a competitive salary of up to $185,000 per annum with a 40% annual bonus potential.">About the Position:">The successful candidate will be responsible for designing, developing,...


  • Dallas, Texas, United States Palo Alto Networks Full time

    About This RoleThis is an exciting opportunity to join our team as a Cybersecurity Risk Management Consultant.As a trusted advisor, you will play a crucial role in helping clients proactively manage and mitigate cyber risks. You will lead security audits, analyze monitoring and alerting systems, and conduct risk assessments using industry-accepted...


  • Dallas, Texas, United States Technology Recruiting Solutions Full time

    Role OverviewWe are seeking an experienced Information Security Compliance Lead to join our team at Technology Recruiting Solutions. The successful candidate will be responsible for developing and implementing IT security governance and risk management functions to ensure compliance with established internal controls, regulatory, and legal requirements.Key...


  • Dallas, United States Clinical Management Consultants Full time

    One of Texas's top hospitals is seeking a highly skilled and experienced RN Director Quality and Risk to lead all of their quality management activities.In this role, the RN Director Quality and Risk will oversee patient care and relations, regulatory compliance, risk management, performance improvement, safety, and infection control. You will collaborate...


  • Dallas, Texas, United States Underground Administration Full time

    Job Title: Risk Management SpecialistAbout Us: At Underground Administration, we are committed to maintaining market stability and risk management frameworks within our clearing and settlement processes.Salary: The estimated salary for this position is between $90,000 and $115,000 per year, with a cap of $105,000 in Tampa.Job Description:We are seeking a...


  • Dallas, Texas, United States Crypto Full time

    About the RoleWe are seeking a talented Risk Management Professional to join our Compliance team. In this role, you will be responsible for analyzing data to identify trends and evaluating changes in risk exposure. You will also develop MIS reports for Senior Management and regulatory reporting, lead initiatives to leverage technology to gain efficiencies in...

  • Insurable Risk Manager

    20 hours ago


    Dallas, United States Ecobat Full time

    I. Position Description The Insurable Risk Manager is responsible for identifying, evaluating, and planning strategies for improving risk management, including suggesting behaviors and developing processes to optimize a global risk services organization. This is a hands-on position to manage a ~$20M cost of risk that is largely property and workers'...


  • Dallas, Texas, United States Palo Alto Networks Full time

    Palo Alto Networks is seeking a highly skilled Cybersecurity Risk Management Leader to join our team. This role will be responsible for leading our Governance, Risk, and Compliance (GRC) team across a comprehensive portfolio of clients.The ideal candidate will have 6+ years of experience performing information security and risk assessments based upon...