Talent.com
Manager, Information Security Risk Management

Manager, Information Security Risk Management

HearstNew York, NY, United States
2 days ago
Job type
  • Full-time
Job description

Job Description

Hearst Technology, Inc, Information Security Office seeks a Manager, Information Security Risk Management. The Manager, Information Security Risk Management is responsible for assessing risk and managing risk information for the organization and key business units. This position assesses information security risk within essential technology functions, key business processes, documentation, and collaborates with key business leaders to assist in reducing risk and maturing the overall control environment. This position will also support Audit and Compliance functions within Hearst, focusing on PCI and HIPAA.

Team Alignment : Governance, Risk, and Compliance (GRC) Team. The GRC Team is multi-faceted and focuses on driving business value. Our mission is to establish an integrated program that ensures the overall effectiveness of capabilities that impact information security across business units globally.

  • Perform security risk reviews, risk assessments and gap assessments on key business processes and new and existing technologies. Subsequently, work with various business units, as needed, to ensure controls are adequate, appropriate, and effective and that mitigation and remediation plans are in place.
  • Maintain the IT risk register and risk dashboard keeping risks, and their response plans up to date; will be required to work with cross-functional teams and businesses.
  • Prepare detailed recurring risk management reports with associated metrics.
  • Support the implementation of a risk program including enhancing processes supporting accountability, exception requests, and overall risk reduction in accordance with NIST and COBIT Cybersecurity frameworks.
  • Support vendor due-diligence process and help define overall third-party risk management efforts.
  • Support risk-focused governance entities such as forums and steering committees.
  • Support internal and external audit processes for relevant compliance areas including NIST CSF, NIST 800-53, PCI-DSS, HIPAA, SOX, and other external and internal requirements.
  • Support key capabilities and processes across the GRC function in support of the Hearst Information Security Office using an Agile methodology approach to delivering work products and key services.
  • Work collaboratively with regional and global partners in other functional units; ability to navigate a complex organization; to influence and lead people across cultures at a senior level. Collaboratively interface with global IT and business partners to provide guidance and support.
  • Design and implement improvements in risk-related documentation.
  • Other related duties as assigned.

Who You Are : As a mid-level position, comfort and experience with all aspects of governance, risk, and compliance is required.

Technical Skills

  • Experience with IT governance, risk, and compliance management in a large global environment, while working with geographically dispersed, multidisciplinary teams.
  • Experience conducting risk assessments and managing risk across departments and functions.
  • Strong foundation in PCI and HIPAA compliance requirements and testing.
  • Familiarity with an integrated risk management platform.
  • Familiarity with security frameworks, particularly NIST and COBIT Cybersecurity Frameworks and HITRUST.
  • Basic understanding and knowledge of technical fundamentals such as networking concepts, cloud computing, application development, and security best practices.
  • Proficiency with Word, Excel, PowerPoint, JIRA, SharePoint.
  • Experience with GRC and risk management platforms such as Prevalent and TruOps is desired.
  • Soft Skills

  • Strong work ethic with attention to detail and demonstrated analytical abilities.
  • Attention to detail, verbal and written communication, and initiative; able to apply constructive feedback to enhance managing risk.
  • Strong presentation skills with the ability to articulate complex problems and solutions through concise and clear messaging.
  • Self-motivated with excellent planning and organizational skills; and the ability to prioritize tasks to meet deadlines and effectively manage changing priorities.
  • Professional customer orientation with a strong commitment to providing a high standard of customer satisfaction.
  • Ability to deliver client-ready documentation and participate in relevant client meetings; able to work across teams effectively and efficiently.
  • Working understanding of project management principles, processes, and documentation.
  • Ability to collaborate with internal and external stakeholders.
  • Qualifications

  • Bachelor's Degree in Information Technology, Computer Science, or equivalent.
  • Minimum 5 years of relevant experience in a risk management role with at least 2 years of practical experience in Audit and Compliance.
  • Industry standard certification such as CISA, CRISC, CISM, ARM, CISSP, ISO 27001, ISO 27005 is desired.
  • In accordance with applicable law, Hearst is required to include a reasonable estimate of the compensation for this role if hired in New York City. The reasonable estimate, if hired in New York City, is $135,000 - $150,000. Please note this information is specific to those hired in New York City. If this role is open to candidates outside of New York City, the salary range would be aligned to that specific location. A final decision on the successful candidate's starting salary will be based on a number of permissible, non-discriminatory factors, including but not limited to skills and experience, training, certifications, and education. Hearst provides a competitive benefits package, including medical, dental, vision, disability and life insurance, 401(k), paid holidays and paid time off, employee assistance programs, and more.

    About Us

    Hearst is one of the nation's largest global, diversified information, services and media companies.

    Hearst has been innovating for more than a century, leading with purpose, integrity and a culture of care, with a mission to inform audiences and improve lives.

    The company's diverse portfolio includes global financial services leader Fitch Group; Hearst Health, a group of medical information and services businesses; Hearst Transportation, which includes CAMP Systems International, a major provider of software-as-a-service solutions for managing maintenance of jets and helicopters; ownership in cable television networks such as A&E, HISTORY, Lifetime and ESPN; 35 television stations; 24 daily and 52 weekly newspapers; digital services businesses; and more than 200 magazines around the world.

    Hearst is always moving forward, investing in healthcare solutions to improve patient outcomes and technology that curbs emissions; providing vital analysis, data and software to the global financial services industry; delivering important service and investigative journalism; and inspiring audiences with sports and entertainment programming.

    With a commitment to maintaining the highest quality in its products and services, Hearst is dedicated to serving the communities it operates in, both civically and philanthropically.

    Hearst is an Equal Employment Opportunity employer. We do not discriminate in hiring on the basis of race, color, national origin, religion, creed, sex or gender, gender identity, gender expression, sexual orientation, age, physical or mental disability, military or veteran status, or any other characteristic protected by federal, state, or local law.

    About the Team

    The Hearst Technology Services (HTS) team partners with Hearst's businesses that operate in diverse industries to enable business outcomes leveraging modern technology solutions. We are a global, customer centric, agile and innovative organization where creativity, team work and having fun while working hard is appreciated.

    Create a job alert for this search

    Information Security Manager • New York, NY, United States

    Related jobs
    • Promoted
    Compliance- Identity and Access Management Technology, Operational Risk, Executive Director

    Compliance- Identity and Access Management Technology, Operational Risk, Executive Director

    ChaseNew York, NY, US
    Full-time
    Show moreLast updated: 30+ days ago
    • Promoted
    Information Security Manager

    Information Security Manager

    Atlas SystemsEast Brunswick, NJ, US
    Full-time
    Software Solutions company headquartered in East Brunswick, NJ.Incorporated in 2003, Atlas provides comprehensive range of solutions in the area of GRC, Technology, Procurement, Healthcare Provider...Show moreLast updated: 1 day ago
    • Promoted
    Director of Incident Management

    Director of Incident Management

    VirtualVocationsBrooklyn, New York, United States
    Full-time
    A company is looking for a Director, IDD Incident Management and Quality Outcomes, Performance-Based Contracting.Key Responsibilities Oversee the full lifecycle of incident management, including ...Show moreLast updated: 11 days ago
    • Promoted
    IT Security Manager

    IT Security Manager

    EllkayElmwood Park, NJ, United States
    Full-time
    ELLKAY started out providing connectivity solutions to laboratories and within a few years, grew to also provide data management solutions to ambulatory organizations. ELLKAY is now a trusted data m...Show moreLast updated: 2 days ago
    • Promoted
    Manager, Information Security Office Consultant

    Manager, Information Security Office Consultant

    Capital OneNEW YORK, New York, United States
    Full-time +1
    Manager, Information Security Office Consultant.At Capital One, you will help consult on initiatives, programs, and projects to raise their game in Information Security and Risk Management.You are ...Show moreLast updated: 30+ days ago
    • Promoted
    Information Security Risk Compliance Manager - ISRM

    Information Security Risk Compliance Manager - ISRM

    NYC IT IncNew York, NY, US
    Full-time
    I am writing to you regarding the.Information Security Risk Compliance Manager.I have mentioned the job Description below for your review. Please let me know if you are interested and send me your m...Show moreLast updated: 2 days ago
    • Promoted
    Manager of Cybersecurity Monitoring & Response

    Manager of Cybersecurity Monitoring & Response

    University Hospital, Newark NJNewark, NJ, United States
    Full-time
    Under the direction of the Chief Information Security Officer (CISO) / Vice President of Information Technology, the Manager of Cybersecurity Monitoring & Response plays a key role in safeguarding ...Show moreLast updated: 2 days ago
    • Promoted
    VP- Technology Information Risk Management - NYC / Florham Park, NJ

    VP- Technology Information Risk Management - NYC / Florham Park, NJ

    StaffingNew York, NY, US
    Full-time
    VP Technology Information Risk Management.Location : Ideal 2-3 days hybrid in NYC office Duration : Full Time Location Options : Open to a combo of Melville, NY (Long Island) with one day in NYC (init...Show moreLast updated: 30+ days ago
    • Promoted
    Senior Information Security Compliance Professional

    Senior Information Security Compliance Professional

    FiservBerkeley Heights, NJ, United States
    Full-time
    Calling all innovators - find your future at Fiserv.We're Fiserv, a global leader in Fintech and payments, and we move money and information in a way that moves the world.We connect financial insti...Show moreLast updated: 2 days ago
    • Promoted
    Tech - Cyber Security - Identity and Access Mgmt -IAM - Senior Manager - Multiple Positions -1635273

    Tech - Cyber Security - Identity and Access Mgmt -IAM - Senior Manager - Multiple Positions -1635273

    Ernst & Young Advisory Services Sdn BhdJericho, NY, United States
    Full-time
    Tech - Cyber Security - Identity and Access Management (IAM) – Senior Manager.EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these ...Show moreLast updated: 30+ days ago
    • Promoted
    Manager, Network Security, Tech & Data Risk Management

    Manager, Network Security, Tech & Data Risk Management

    Capital OneNew York City, NY, United States
    Full-time +1
    Manager, Network Security, Tech & Data Risk Management Capital One is one of the fastest growing organizations in the world today, powered by our passion for our customers.We are serious about tech...Show moreLast updated: 1 day ago
    • Promoted
    Business Information Risk Lead, Audible Security

    Business Information Risk Lead, Audible Security

    AmazonNewark, NJ, United States
    Full-time
    At Audible, we believe stories have the power to transform lives.It's why we work with some of the world's leading creators to produce and share audio storytelling with our millions of global liste...Show moreLast updated: 2 days ago
    • Promoted
    Sr. Information Security Compliance Professional

    Sr. Information Security Compliance Professional

    FiservBerkeley Heights, NJ, United States
    Full-time
    Calling all innovators - find your future at Fiserv.We're Fiserv, a global leader in Fintech and payments, and we move money and information in a way that moves the world.We connect financial insti...Show moreLast updated: 2 days ago
    • Promoted
    Director of Identity and Access Management

    Director of Identity and Access Management

    VirtualVocationsJersey City, New Jersey, United States
    Full-time
    A company is looking for a Director of Information Security, Identity and Access Management.Key Responsibilities Lead a team in the evolution and operationalization of the Identity and Access Man...Show moreLast updated: 1 day ago
    • Promoted
    Security Manager

    Security Manager

    VirtualVocationsPaterson, New Jersey, United States
    Full-time
    A company is looking for a Security Manager to lead security and privacy programs.Key Responsibilities Lead security and privacy compliance programs to achieve and maintain critical certification...Show moreLast updated: 1 day ago
    • Promoted
    Information Security Manager

    Information Security Manager

    VirtualVocationsElizabeth, New Jersey, United States
    Full-time
    A company is looking for an IT Information Security Manager.Key Responsibilities : Manage the team responsible for the security of the organization's systems and information assets Oversee the de...Show moreLast updated: 30+ days ago
    • Promoted
    VP IT Security and Risk Management (Hybrid)

    VP IT Security and Risk Management (Hybrid)

    Selective InsuranceMillburn, NJ, United States
    Temporary
    At Selective, we don't just insure uniquely, we employ uniqueness.Selective's unique position as both a leading insurance group and an employer of choice is recognized in a wide variety of awards a...Show moreLast updated: 30+ days ago
    • Promoted
    Senior Information Security Analyst

    Senior Information Security Analyst

    VirtualVocationsNewark, New Jersey, United States
    Full-time
    A company is looking for a Senior Information Security Analyst in the Information Technology field.Key Responsibilities Lead complex incident response investigations and forensic analysis Conduc...Show moreLast updated: 30+ days ago
    • Promoted
    Information Security Engagement Lead, Americas

    Information Security Engagement Lead, Americas

    UnileverEnglewood Cliffs, NJ, United States
    Full-time
    Unilever seeks a strategic and collaborative Security Engagement Lead to embed cybersecurity across digital and operational ecosystems in the Americas. This role supports secure innovation and resil...Show moreLast updated: 2 days ago
    Information Security Risk Compliance Manager

    Information Security Risk Compliance Manager

    NYC IT IncNewyork, NY, us
    Full-time
    Quick Apply
    I am writing to you regarding the .Information Security Risk Compliance Manager.I have mentioned the job Description below for your review. Please let me know if you are interested and send me ...Show moreLast updated: 1 day ago