Entity
Crdit Agricole Corporate and Investment Bank (Crdit Agricole CIB) is the corporate and investment banking arm of Crdit Agricole Group, the 10th largest banking group worldwide in terms of balance sheet size (The Banker, July 2022). 8,600 employees in more than 30 countries across Europe, the Americas, Asia?Pacific, the Middle?East and North Africa support the Bank's clients, meeting their financial needs throughout the world. Crdit Agricole CIB offers its large corporate and institutional clients a range of products and services in capital market activities, investment banking, structured finance, commercial banking and international trade. The Bank is a pioneer in the area of climate finance, and is currently a market leader in this segment with a complete offer for all its clients. By working every day in the interest of society, we are a Group committed to diversity and inclusion and place people at the heart of all our transformations. All our job offers are open to persons with disabilities.
Reference
2025-105140
Update date
14 / 10 / 2025
Business type
Types of Jobs - IT, Digital et Data
Job title
Associate, Cyber Risk Management
Contract type
Permanent Contract
Job summary
Summary
CACIB is seeking a highly motivated and detail-oriented Associate, Cyber Risk Management to join our growing cybersecurity and risk team. This role will play a central part in conducting internal cyber security reviews, including enterprise control, application level, and maturity assessments. The ideal candidate will have hands?on experience performing cyber risk assessments and strong foundational knowledge of cybersecurity controls and frameworks.
Key Responsibilities
- Plan, conduct, and document cyber risk assessments for internal applications, infrastructure, and networks
- Perform control testing on cybersecurity and technology related controls to assess the design and effectiveness
- Assess risk in alignment with control standards and business context, and evaluate control effectiveness using established frameworks such as NYDFS 500, NIST CSF, ISO27001, FFIEC, and CRI
- Collaborate with internal stakeholders, including application owners, IT, and procurement, to gather risk related information, validate controls, and communicate results
- Contribute to the ongoing development of cybersecurity policies, control requirements, and risk assessment procedures
- Map and maintain controls to industry frameworks, and assist in interpreting requirements for new systems, vendors, or processes
- Support efforts to improve the maturity and efficiency of the cyber risk assessment process, including process optimization and integration with Enterprise Risk Management Framework
Additional Responsibilities
Coordinate issue management and remediation, ensuring timely resolution of identified security risks and issuesParticipate in internal readiness reviews and external audits as needed by providing evidence and control documentationPerform quality assurance checks on risk assessments and documented control gapsSupport cybersecurity training and awareness initiatives to promote best practices across the organizationHelp identify opportunities to streamline assessment workflows and improve consistency across risk domainsRequired Qualifications
2-5 years of experience in cyber risk management, IT risk, cybersecurity, or a related disciplineFamiliarity with risk assessment frameworks (e.g., NIST RMF, FAIR, etc.)Familiarity with cybersecurity principles, tools, and control frameworks (e.g., NIST CSF, CRI, CIS Controls)Salary Range
$110k-$135k
Geographical area
America, United States Of America
City
Bachelor Degree / BSc Degree or equivalent
Education Essential
Bachelors degree in cybersecurity, information technology, or related field
Advanced studies in information security or risk managementCRISC, CISA certification or equivalentRequired skills
Analytical thinking - Strong ability to analyze technical and business risk with critical thinkingRisk based judgement - Ability to evaluate and prioritize risks based on likelihood, impact, and control effectivenessAttention to detail High level of precision in assessment documentation, issue tracking, and reportingCommunication skills Effective verbal and written communicationFamiliarity with risk assessment methodologies and cybersecurity frameworks (e.g., NIST CSF, ISO 27001, SIG, FFIEC)Experience with third party / vendor risk assessment processes and due diligenceStrong organization skills with experience managing multiple tasks and assessments simultaneouslyProficiency with reporting tools (e.g., Excel) and GRC platformsKnowledge of application security concepts and cloud securityUnderstanding of regulatory environments such as NYDFS, SOX, SOC1 & 2 as they relate to cybersecurityEEO Statement
All our positions are open to people with disabilities.
#J-18808-Ljbffr