Talent.com
SellerServicer Information Security Risk Oversight Manager
SellerServicer Information Security Risk Oversight ManagerFreddie Mac • McLean, Maryland, USA
SellerServicer Information Security Risk Oversight Manager

SellerServicer Information Security Risk Oversight Manager

Freddie Mac • McLean, Maryland, USA
3 hours ago
Job type
  • Full-time
Job description

At Freddie Mac our mission of Making Home Possible is what motivates us and its at the core of everything we do. Since our charter in 1970 we have made home possible for more than 90 million families across the country. Join an organization where your work contributes to a greater purpose.

Position Overview :

Freddie Mac is seeking an experienced Manager to join our Third Party Risk Governance (TPRG) Information Security (Cyber) team. Your role will be vital in identifying potential risks and ensuring that effective mitigation strategies are in place. If you have a strong foundation in risk management and cybersecurity and are committed to protecting organizations from threats we invite you to apply for this critical role at Freddie Mac.

Our Impact :

The Seller / Servicer Information Security Oversight Team within Third-Party Risk Management is responsible for monitoring the information security standards of seller / servicers to ensure the safeguarding of Freddie Macs data in alignment with the Freddie Mac Guide. Our team of cyber risk specialists is actively involved in monitoring identifying detecting and responding to cyber threats. Through regular vulnerability scans they work diligently to mitigate information security risks to Freddie Mac.

Your Impact :

  • As a Manager you will play a key role in enhancing our oversight of third-party risk management. Your responsibilities will include :
  • Leading initiatives to conduct thorough cybersecurity risk assessments.
  • Applying the Cybersecurity Framework (CSF) to structure and improve our risk management processes.
  • Collaborating with various stakeholders to identify and assess potential information security risks.
  • Developing and implementing strategic plans to effectively mitigate identified risks.
  • Ensuring the continuous improvement of our cybersecurity posture through proactive risk management and oversight.
  • Conducting comprehensive Information Security risk reviews and interviews with seller / servicers as part of the annual Consolidated Origination and Risk Evaluation (CORE) review.

Analyzing findings from these reviews and developing a detailed risk assessment backed by supporting evidence.

Qualifications :

  • 8 years of experience in risk management internal controls audit or compliance preferably within financial services or mortgage operations
  • 8 to 10 years of experience in cybersecurity or cyber risk management with a focus on highly regulated industries.
  • Bachelors degree in computer science engineering or a related field or equivalent work experience preferred.
  • Proficiency in performing risk analyses vulnerability assessments and threat modeling.
  • Proven track record of leading risk assessment and controls initiatives across business functions
  • Proven experience engaging with senior leadership to understand and align with strategic goals.
  • Experience in IT governance risk and controls including familiarity with frameworks such as COBIT FFIEC ISO 2700x and NIST.
  • Strong analytical and problem-solving skills.
  • Excellent communication skills for articulating technical risks to non-technical audiences.
  • In-depth knowledge of cybersecurity principles networks and operating systems with experience in relevant frameworks like NIST and ISO 27001.
  • Industry certifications such as Sec SSCP GSEC or CEH preferred
  • Keys to Success :

  • Significant understanding of the Third-Party Risk Governance process
  • Ability to perform additional duties as assigned to support the organizations evolving needs.
  • Strong analytical and problem-solving skills.
  • Excellent communication skills for articulating technical risks to non-technical audiences.
  • In-depth knowledge of cybersecurity principles networks and operating systems with experience in relevant frameworks like NIST and ISO 27001
  • Possess a deep understanding of NIST standards and evaluate seller / servicers compliance with the Freddie Mac Guide.
  • Identify and assess potential risks and vulnerabilities to our systems and data posed by third parties utilizing approved monitoring tools.
  • Conduct thorough risk assessments analyze potential threats and evaluate third-party information security processes and procedures.
  • Identify associated risks and provide a comprehensive risk assessment with supporting evidence.
  • Current Freddie Mac employees please apply through the internal career site.

    We consider all applicants for all positions without regard to gender race color religion national origin age marital status veteran status sexual orientation gender identity / expression physical and mental disability pregnancy ethnicity genetic information or any other protected categories under applicable federal state or local laws. We will ensure that individuals are provided reasonable accommodation to participate in the job application or interview process to perform essential job functions and to receive other benefits and privileges of employment. Please contact us to request accommodation.

    A safe and secure environment is critical to Freddie Macs business. This includes employee commitment to our acceptable use policy applying a vigilance-first approach to work supporting regulatory mandates and using best practices to protect Freddie Mac from potential threats and risk. Employees exercise this responsibility by executing against policies and procedures and adhering to privacy & security obligations as required via training programs.

    CA Applicants : Qualified applications with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.

    Notice to External Search Firms : Freddie Mac partners with BountyJobs for contingency search business through outside firms. Resumes received outside the BountyJobs system will be considered unsolicited and Freddie Mac will not be obligated to pay a placement fee. If interested in learning more please visit and register with our referral code : MAC.

    Time-type : Full time

    FLSA Status : Exempt

    Freddie Mac offers a comprehensive total rewards package to include competitive compensation and market-leading benefit programs. Information on these benefit programs is available on our Careers site.

    This position has an annualized market-based salary range of $142000 - $214000 and is eligible to participate in the annual incentive program. The final salary offered will generally fall within this range and is dependent on various factors including but not limited to the responsibilities of the position experience skill set internal pay equity and other relevant qualifications of the applicant.

    Required Experience :

    Manager

    Key Skills

    International Development,EMC,JavaScript,Import & Export,Airlines,Asp.Net MVC

    Employment Type : Full-Time

    Experience : years

    Vacancy : 1

    Monthly Salary Salary : 142000 - 214000

    Create a job alert for this search

    Information Security Manager • McLean, Maryland, USA

    Related jobs
    Insider Threat Program Systems SME

    Insider Threat Program Systems SME

    Leidos • Oxon Hill, MD, US
    Full-time
    The Digital Modernization Sector at Leidos currently has an opening for a Systems Management SME supporting the HEITS Contract as part of an Insider Threat Program (ITP). This is an exciting opportu...Show more
    Last updated: 30+ days ago • Promoted
    Senior Security Manager

    Senior Security Manager

    Leidos Inc • Chantilly, VA, United States
    Full-time
    The Leidos Security Operations is seeking a proven, experienced security professional for a Senior Security Manager, to lead a multi-functional team and manage a portfolio of programs supporting ou...Show more
    Last updated: 28 days ago • Promoted
    Manager, Risk Management : Card Risk

    Manager, Risk Management : Card Risk

    Capital One • McLean, VA, United States
    Full-time +1
    Manager, Risk Management : Card Risk.Do you like working in the spotlight? Are you ready to work on the front line of a top 10 Bank? Can you build relationships as well as develop and implement inno...Show more
    Last updated: 9 days ago • Promoted
    Cyber Security Architect

    Cyber Security Architect

    Agile Defense • Quantico, VA, VA, United States
    Full-time
    At Agile Defense we know that action defines the outcome and new challenges require new solutions.That’s why we always look to the future and embrace change with an unmovable spirit and the courage...Show more
    Last updated: 30+ days ago • Promoted
    FIPS 140 Security Engineer

    FIPS 140 Security Engineer

    ALTA IT Services • Columbia, MD, US
    Temporary
    Job Title : FIPS 140 Security Engineer Location : Columbia, MD Compensation : $60.HR Duration : 6 month contract with possibility of extension In joining the team, you will get an exciting opportunity ...Show more
    Last updated: 30+ days ago • Promoted
    Manager, Cyber Threat Intelligence

    Manager, Cyber Threat Intelligence

    Capital One • McLean, Maryland, USA
    Full-time +1
    Manager Cyber Threat Intelligence.Do you love building and pioneering in the technology space Do you enjoy solving complex business problems in a fast-paced collaborative inclusive and iterative de...Show more
    Last updated: 3 hours ago • Promoted • New!
    Safety / Risk Coordinator

    Safety / Risk Coordinator

    IES Communications • Leesburg, VA, US
    Full-time
    Job Summary : The Safety Coordinator is responsible for implementing, administering, maintaining and coordinating all IES safety policies and programs including safety training and inspections for ...Show more
    Last updated: 2 hours ago • Promoted • New!
    Quality Assurance Manager

    Quality Assurance Manager

    Leidos Inc • Columbia, MD, United States
    Full-time
    The National Security Sector of Leidos has a career opportunity for a talented.Cyber & Analytics Business Area.This position serves as the member of a team with the responsibility to ensure the hig...Show more
    Last updated: 30+ days ago • Promoted
    Senior Cyber Risk & Security Manager

    Senior Cyber Risk & Security Manager

    BTI • Washington, DC, United States
    Full-time
    A leading company in cybersecurity is seeking an Information Systems Security Manager to oversee risk management processes. The successful candidate will lead a team focused on IT security goals and...Show more
    Last updated: 2 days ago • Promoted
    Sailpoint Compliance & Risk Management

    Sailpoint Compliance & Risk Management

    Next Level Business Services, Inc. • Washington, DC, United States
    Full-time
    Mandatory Skills (Please detail as much as possible) Educational Qualifications and Experience : .Master’s or Bachelor’s degree(s) in Computer Science and / or Electrical Engineering.Minimum five conse...Show more
    Last updated: 9 days ago • Promoted
    Claim Specialist - Property Field Inspection

    Claim Specialist - Property Field Inspection

    State Farm • Warrenton, VA, United States
    Full-time
    Being good neighbors - helping people, investing in our communities, and making the world a better place - is who we are at State Farm. It is at the core of how we operate and the reason for our suc...Show more
    Last updated: 1 day ago • Promoted
    Cyber Security Risk Management Engineer

    Cyber Security Risk Management Engineer

    Viasat • Germantown, MD, United States
    Full-time
    At Viasat, we're on a mission to deliver connections with the capacity to change the world.For more than 35 years, Viasat has helped shape how consumers, businesses, governments and militaries arou...Show more
    Last updated: 30+ days ago • Promoted
    Information Systems Security Manager

    Information Systems Security Manager

    Leidos Inc • Bethesda, MD, United States
    Full-time
    Leidos' High Fidelity Simulation Business Area is responsible for architecting and implementing large-scale System of Systems solutions in support of world class simulation, training, and analysis ...Show more
    Last updated: 30+ days ago • Promoted
    Manager, Technology Risk Guide Enterprise Services Risk

    Manager, Technology Risk Guide Enterprise Services Risk

    Capital One • McLean, Maryland, USA
    Full-time +1
    Manager Technology Risk Guide - Enterprise Services Risk.The Enterprise Services Risk organization is expanding with a focus on attracting innovative pioneering collaborative and highly skilled pro...Show more
    Last updated: 4 days ago • Promoted
    Manager Information Technology (On-site)

    Manager Information Technology (On-site)

    Leonardo DRS • Germantown, MD, United States
    Full-time
    DRS RADA Technologies, a subsidiary of Leonardo DRS, is focused on proprietary radar solutions and legacy avionics systems supporting the defense industry globally. The company is a global pioneer o...Show more
    Last updated: 29 days ago • Promoted
    Site Risk & Due Diligence Manager, Risk and Resiliency

    Site Risk & Due Diligence Manager, Risk and Resiliency

    Amazon • Herndon, VA, US
    Full-time
    AWS Infrastructure Services owns the design, planning, delivery, and operation of all AWS global infrastructure.In other words, we're the people who keep the cloud running.We support all AWS data c...Show more
    Last updated: 30+ days ago • Promoted
    C&I Relationship Manager IV (Hybrid Central, VA)

    C&I Relationship Manager IV (Hybrid Central, VA)

    Atlantic Union Bank • Leesburg, VA, United States
    Full-time
    The C&I Relationship Manager IV assumes the overall responsibility, development and management of their borrowing and non-borrowing portfolio. The Relationship Manager is responsible for marketing a...Show more
    Last updated: 30+ days ago • Promoted
    Safety Coordinator

    Safety Coordinator

    IES Communications • Leesburg, VA, United States
    Full-time
    The Safety Coordinator is responsible for implementing, administering, maintaining and coordinating all IES safety policies and programs including safety training and inspections for the assigned p...Show more
    Last updated: 21 days ago • Promoted