Director, Security Risk Management

CardWorks

Woodbury, NY, US
Base: $151,165 to $167,961 (ny metro); bonus/equit...
**
Information security risk management leadership
Vendor security assessment and review
Nist cybersecurity framework application
** CardWorks is seeking a Director of Security Risk Management to lead and enhance their information security risk management and vendor security assessment programs. The ideal candidate will have extensive experience in information security leadership, risk assessment, and compliance frameworks, fostering a proactive security culture within the organization. **

Job Summary

  • The role involves leading the design, implementation, and oversight of the organization's information security risk management and vendor security assessment programs.
  • Candidates must have a deep understanding of frameworks such as NIST CSF, CRI Profile, and PCI DSS to effectively manage cyber risks across systems and vendors.
  • The company offers a competitive pay range up to $167,961 in NY Metro areas along with comprehensive benefits including medical, dental, vision, and a 401(k) match.

Matching Summary

Match Score: 75

** CardWorks is seeking a Director of Security Risk Management to lead and enhance their information security risk management and vendor security assessment programs. The ideal candidate will have extensive experience in information security leadership, risk assessment, and compliance frameworks, fostering a proactive security culture within the organization. **

Salary

Base: $151,165 to $167,961 (NY Metro); Bonus/Equity: Variable Pay Incentive Program; Benefits: Medical, Dental, Vision, 401(k) Match, Paid Vacation

Skills & Requirements

Must-have

  • Information Security Risk Management leadership
  • Vendor security assessment and review
  • NIST Cybersecurity Framework application
  • PCI DSS compliance expertise
  • Cyber Risk Institute Profile knowledge
  • GRC platform experience (Archer/ServiceNow)
  • Enterprise Risk Management integration

Nice-to-have

  • Hands-on leadership for small teams
  • Culture of proactive security risk management
  • Automation of evidence collection workflows
  • Strong analytical problem-solving skills
  • Experience with SOC 2 and ISO 27001 reports

Key Requirements

  • 8+ years in information security or risk management
  • 3+ years in leadership or program management capacity
  • Bachelor's or master's degree in related field
  • CRISC, CISM, CISSP, or CISA certification preferred

Work Rights

Not specified

Tailored Resume

Cover Letter