Talent.com
Head of IT Security, Controls & Technology Risk (LoD1)
Head of IT Security, Controls & Technology Risk (LoD1)Groupe BPCE • New York, NY, United States
Head of IT Security, Controls & Technology Risk (LoD1)

Head of IT Security, Controls & Technology Risk (LoD1)

Groupe BPCE • New York, NY, United States
10 days ago
Job type
  • Full-time
Job description

Poste et missions

We are seeking for a highly skilled and experienced Head of IT Controls, Security and Technology Risk (LoD1) who will lead a critical team within the Natixis CIB Americas (AMER) IT department. In this key role, you will oversee and be responsible for IT Security, Controls, Change Management, Incident Management, Disaster Recovery Planning and Remediation functions, while reporting directly to the AMER Chief Information Officer (CIO). You will lead three teams, comprising approximately seven direct reports, each focusing on specific areas of IT risk, controls and security (Access Management, Vulnerability and Patch Management, CyberSecurity..).

As an executive in the First Line of Defense (LoD1), you will play a crucial role in ensuring that the AMER IT organization maintains a robust Technology Risk posture that aligns with the company and regulatory standards. You will facilitate effective change management and remediation processes across various IT teams, driving operational excellence and compliance.

This position requires outstanding communication and interpersonal skills, as you will regularly engage with senior management, board members, and regulatory bodies. Your ability to clearly and persuasively convey complex information will be essential for ensuring alignment with organizational goals and adherence to industry regulations. Additionally, you will lead audits and examinations (both internal and external) related to your areas of responsibility, which include Controls, Change Management, Incident Management, Disaster Recovery Planning, Security, and Remediation functions for AMER IT (LoD1).

  • Controls and Security Governance : Ensure adherence to policies, standards, and controls across the different IT taxonomies. Address exceptions and align security risks with the organization's risk management framework, in accordance with BPCE Group / Natixis CIB strategy, industry best practices (e.g., NIST, SOC2, ISO), and regulatory compliance requirements (e.g., NY DFS Part 500, FFIEC). Regularly assess the effectiveness of AMER IT's LoD1 controls to ensure they are well-designed and operational, thereby mitigating risks and maintaining compliance with regulations. Present findings to the board and regulatory bodies, serving as the primary point of contact for auditor inquiries.
  • Controls and Security Compliance and Remediation : Regularly assess the effectiveness of AMER IT's LoD1 controls to ensure they are well-designed and operational, thereby mitigating risks and maintaining compliance with regulations. Present findings to the board and regulatory bodies, serving as the primary point of contact for auditor inquiries. Oversee the implementation of comprehensive remediation actions to effectively address identified security gaps.

Project Planning and Tracking : Collaborate with the AMER Regulatory Affairs department and Head Office partners (BPCE Group and Natixis) to plan and prioritize AMER IT Controls, Disaster Recovery Planning (DRP), and Security projects and initiatives. Track progress and report deliverables to senior management.

  • IT Change and Incident Management : Coordinate IT changes within AMER IT teams while overseeing the incident response process. Ensure timely identification, investigation, and remediation of security incidents. Work closely with the Second Line of Defense (Operational Risk, CISO-Technology Risk Management) for escalation, impact assessment, reporting, and follow-up on remediation actions.
  • Incident Response Leadership : Lead the IT incident response process, including investigation, containment, eradication, recovery, and post-incident analysis to minimize the impact of IT breaches.
  • IT Risk and Security Assurance and Reporting : Manage repositories of evidence and artifacts necessary for audits and regulatory compliance. Provide metrics and outcome-based performance indicators to assess risk management and remediation activities.
  • Team Leadership and Development : Lead, mentor, and develop a team of security professionals and IT engineers. Foster their understanding of security gaps, encourage the evaluation of treatment options, and support the implementation of remediation strategies across your reporting scope and within AMER IT.
  • Natixis is an equal opportunity employer, committed to a workplace free of discrimination. Natixis will not tolerate any form of discrimination based on age, color, mental or physical handicap or disability, pregnancy, marital status, sexual orientation, national origin, alienage, ancestry or citizenship status, race, religion, sex (including sex stereotyping, gender identity, gender expression or transgender status), veteran status, creed, genetic information or carrier status, or any other protected characteristic as established by law.

    Respect for all means that we deal with each person as an individual and not as a member of any group. All qualified applicants will receive consideration for employment. Management is expected to provide leadership in supporting the firms EEO program by taking steps to promote EEO in all facets of employment including recruitment, hiring, retention, promotion, performance assessment, and career-development opportunities.

    The salary range for Executive Director will be between $240,000 - $290,000. Natixis is required by law to include a reasonable estimate of the compensation range for this role. Actual base salary will vary and will be based on several factors including, but not limited to, relevant experience, education, skills set, applicable licensure and certifications, and other business and organizational needs. Base salary is only one component of our total rewards package. Natixis also offers a generous benefits package, and you may be eligible for a discretionary incentive award depending on company and individual performance

    Profil et compétences requises

    BA / BS related field.

    Strong experience in Cybersecurity and IT Controls, with significant experience in a senior or managerial role focused on security remediation, vulnerability management, and incident response

    Expertise in security frameworks (e.g., NIST CSF, ISO 27001, SOC 1,2) and security risk management principles

    Strong knowledge on FFIEC and NY DFS regulation and implementation

    Experience with GRC tools and best practices, preferably RSA Archer

    Excellent verbal and written communication skills

    Relevant certifications such as CRISC, CISM, CISA, CISSP, or similar advanced security certifications are highly desirable

    Knowledge of cloud security and securing hybrid IT environments is a plus.

    Ability to work effectively and decisively in dynamic and ambiguous situations.

    Ability to manage testing projects, track progress, and meet deadlines.

    Commitment to professional development and staying updated on emerging security threats and technologies.

    Create a job alert for this search

    Head Of Security • New York, NY, United States

    Related jobs
    Director - Cybersecurity & Network Security Vendor Lead

    Director - Cybersecurity & Network Security Vendor Lead

    Climb Global Solutions • Eatontown, NJ, US
    Full-time
    The Cybersecurity Vendor Director will lead Climb’s North American cybersecurity and network security business unit for a leading global vendor, driving significant revenue growth within the ...Show more
    Last updated: 4 days ago • Promoted
    Head of Technology Risk Management

    Head of Technology Risk Management

    Selby Jennings • Stamford, CT, United States
    Full-time
    Get AI-powered advice on this job and more exclusive features.This range is provided by Selby Jennings.Your actual pay will be based on your skills and experience — talk with your recruiter to lear...Show more
    Last updated: 7 days ago • Promoted
    Head of Risk Management

    Head of Risk Management

    BitGo, Inc. • New York, NY, United States
    Full-time
    BitGo is the leading infrastructure provider of digital asset solutions, delivering custody, wallets, staking, trading, financing, and settlement services from regulated cold storage.Since our foun...Show more
    Last updated: 7 days ago • Promoted
    Head of Risk Management

    Head of Risk Management

    BitGo • New York, NY, United States
    Full-time
    BitGo is the leading infrastructure provider of digital asset solutions, delivering custody, wallets, staking, trading, financing, and settlement services from regulated cold storage.Since our foun...Show more
    Last updated: 7 days ago • Promoted
    Director of Operations

    Director of Operations

    Project Redirect Inc Of The Distric • Jamaica, NY, US
    Full-time
    The Operations and Security Director works in cooperation and in conjunction with the Site Director and the Director of Social Services. The position ensures the overall operational, safety, and mai...Show more
    Last updated: 30+ days ago • Promoted
    Director, Division of Infectious Diseases

    Director, Division of Infectious Diseases

    Hackensack Meridian Health • Neptune Township, US
    Full-time +1
    Director, Division of Infectious Diseases.Jersey Shore University Medical Center.Hackensack Meridian Health – Neptune, New Jersey. Hackensack Meridian Health is seeking a Director, Division of...Show more
    Last updated: 30+ days ago • Promoted
    Director, Global Health Equity Delivery & Impact, Americas

    Director, Global Health Equity Delivery & Impact, Americas

    NY Staffing • New Brunswick, NJ, US
    Full-time
    Director, Delivery & Impact, Americas.At Johnson & Johnson, we believe health is everything.Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, ...Show more
    Last updated: 2 days ago • Promoted
    Director, Market Access & Operations

    Director, Market Access & Operations

    Legend Biotech • Somerset, NJ, US
    Full-time
    Director, Market Access & Operations.Legend Biotech is a global biotechnology company dedicated to treating, and one day curing, life-threatening diseases. Headquartered in Somerset, New Jersey, we ...Show more
    Last updated: 1 day ago • Promoted
    Director, R&D, Innovation

    Director, R&D, Innovation

    Chobani • North Brunswick, NJ, US
    Full-time
    The Research and Development Director will lead major innovation initiatives, focusing on creating better tasting, natural and more nutrient dense foods & beverages, and implementing them for launc...Show more
    Last updated: 3 days ago • Promoted
    IT Security Identity and Access Management (W2 Only)

    IT Security Identity and Access Management (W2 Only)

    Neotecra, Inc. • New York, NY, US
    Full-time
    We are seeking a skilled Privileged Access Management (PAM) Engineer to join our cybersecurity team.This role will focus on securing privileged identities across Active Directory (AD), Entra ID, Li...Show more
    Last updated: 12 days ago • Promoted
    IT Risk and Security Engineer (PKI-Certificate Management

    IT Risk and Security Engineer (PKI-Certificate Management

    Hire Talent • Jersey City, NJ, United States
    Full-time
    The Cyber Security Services domain protects from cyber security risks through world-class security architecture, engineering, and governance practices. Enterprise Certification Management Services (...Show more
    Last updated: 30+ days ago • Promoted
    Global Operations Director

    Global Operations Director

    IVI RMA North America • Eatontown, NJ, US
    Full-time
    Global Chief Transformation Officer.The Global Director of Operations is a strategic enabler who partners with IVIRMA’s regional COOs and CEOs to elevate operational capabilities and drive pe...Show more
    Last updated: 10 days ago • Promoted
    ZTD Global IT Service Management Lead

    ZTD Global IT Service Management Lead

    Zoetis, Inc • Parsippany-Troy Hills, NJ, United States
    Full-time
    We are seeking an experienced and visionary ITSM Leader to establish and own the process and governance of a consistent IT Service Management (ITSM) practice across our ZTD organization.This is a p...Show more
    Last updated: 14 days ago • Promoted
    Senior Director - Security Infrastructure & Endpoint Protection

    Senior Director - Security Infrastructure & Endpoint Protection

    Gartner • Stamford, CT, United States
    Full-time
    Senior Director Analyst - Security Infrastructure & Endpoint Protection.What makes Gartner Research a GREAT fit for you?. You are a team player who values expert insights, bold ideas and intellectua...Show more
    Last updated: 30+ days ago • Promoted
    Head of Security

    Head of Security

    Metronome Technologies, Inc. • New York, NY, United States
    Full-time
    Metronome is the leading usage-based billing platform built for modern software companies.With Metronome, companies can launch products faster, offer any pricing model, and streamline finance workf...Show more
    Last updated: 30+ days ago • Promoted
    Vice President Strategy Director

    Vice President Strategy Director

    Health And Wellness Partners • Red Bank, NJ, US
    Full-time
    Health & Wellness Partners, LLC (HWP), is a medical and scientific communications agency that collaborates with life science industry stakeholders to develop award-winning solutions that advanc...Show more
    Last updated: 20 days ago • Promoted
    IT Solutions for Risk Management Intern

    IT Solutions for Risk Management Intern

    Santander US • New York, NY, United States
    Full-time
    IT Solutions for Risk Management Intern.Country : United States of America.Santander is a global leader and innovator in the financial services industry. We believe that our employees are our greates...Show more
    Last updated: 4 days ago • Promoted
    Senior Category Manager IT Infrastructure services

    Senior Category Manager IT Infrastructure services

    Becton Dickinson • Franklin Lakes, NJ, US
    Full-time
    Senior Category Manager IT Infrastructure Services.The Senior Category Manager IT Infrastructure Services develops and maintains leading edge global sourcing strategy and appropriate supply base ...Show more
    Last updated: 19 hours ago • Promoted • New!