Cybersecurity Risk Manager positions focus on delivering results in their domain. This page aggregates open Cybersecurity Risk Manager roles and what employers typically expect.
**ABOUT THE ROLE:** The Cybersecurity Risk Manager serves as the technical risk leader within the Information Security Program, responsible for advancing the Credit Union's ability to identify, assess, and manage cybersecurity, artificial intelligence, and third-party risks. This position directly supports the VP, Information Security Officer in shifting the Program to proactive, intelligence-driven risk management. **WHAT YOU WILL DO:** 1. Conducts technical risk assessments across infrastructure, applications, and data environments. 2. Evaluates emerging risks including artificial intelligence (AI), automation, and advanced threat actor capabilities. 3. Translates technical findings into actionable risk insights for leadership. 4. Assists in the development and leads the operationalization of the AI Governance Program. 5. Assesses internal AI use and Third-party AI utilization and controls. 6. Partners with Legal, Compliance, and Data Governance on AI regulatory considerations, privacy implications and ethical usage. 7. Monitors evolving external AI threats that have direct impacts to the Credit Union, its employees, and members. 8. Leads risk based technical due diligence of third parties including architecture and security control validation; data flow, hosting, and integration risks; AI usage; and supply chain risks. 9. Establishes a risk-tiered information security review model for Analyst-level vs. Manager-level technical reviews. 10. Implements ongoing monitoring of threat intelligence on critical vendors and breach/event alert correlation. 11. Partners with IT to validate integrations and configurations 12. Leads continuous monitoring of industry trends and AI-driven attack techniques to proactively provide VP, ISO insights, develop/ enhance controls, and build risk registers. 13. Owns technical readiness of incident response and tabletop exercises, incorporating third-party breach scenarios and AI-related incidents. 14. Collaborates with IT and business areas to conduct post-incident root cause analysis and control improvements. 15. Ensures risk data such as artificial intelligence, third-party risk, and cyber events are actionable within the risk management solution, Archer IRM. 16. Drives Program evolution from data collection to risk intelligence. 17. Trains and elevates Information Security Analysts technical and analytical development. 18. Establishes clear role segmentation of operational tasks and analytical ownership. 19. Acts as escalation point for complex risk decisions. 20. Performs all other duties as assigned by the VP, Information Security Officer. **QUALIFICATIONS:** ***Education*** Bachelor's degree required, with a concentration in/focus on cybersecurity, information assurance or risk. An equivalent amount of related job experience may be considered in lieu of a degree. ***Experience***/***Skills/Knowledge***: 1. 5+ years of experience in risk management required, preferably in a credit union or financial institution. 2. Certification in Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), or equivalent certification preferred. 3. Experience with enterprise risk management technology required. 4. Excellent organizational, analytical, and problem-solving skills required. 5. Must have the ability to handle multiple projects/ priorities simultaneously with an effective outcome. 6. Must have excellent verbal, written, and interpersonal communication skills, including ability to communicate risks and concepts to business lines outside the Risk Department. 7. Must be a self-motivator and have a strong accountability mindset. 8. Understanding of regulatory requirements including GLBA, NIST and FFIEC Guidance required . 9. Must have the ability to deal with highly confidential information. Must have strong service orientation in alignment with the Credit Union's mission and core values. 10. PC proficient, including Microsoft Office (Word, Excel, PowerPoint, Outlo…