Member of Information & Security chez Anchorage Digital
Anchorage Digital · United States Of America · Remote
Technical Skills:
- Expert knowledge and wide-ranging experience with the regulatory and industry frameworks/standards/methodologies/technology: NIST 800-53, NIST Cybersecurity Framework, ISO 27001, SOC 1/2, cloud environments, logical security, change management, and computer operations
- Ability to quickly grasp new technologies and systems, articulate related risks, develop and implement appropriate risk mitigating measures, and “connect the dots” between the company’s service offerings and products to the IT/Information Security environment
- Resolves a wide range of issues in creative ways to ensure regulatory requirements are being met, including managing and tracking findings (from risk assessments, audits, etc.) from identification to remediation
- Comprehension of core information security principles in order to reason and continuously improve the core Anchorage Digital security model
- Deep understanding of the IT threat landscape for the industry and cloud environments along with the ability to anticipate any impact on the business with the goal to drive a proactive response
- Excellent project management skills to support stability and successful execution in a very fast moving and cross-functional environment
Complexity and Impact of Work:
- Strategically guide the Global Information & Security Team in building and maintaining the overall Information Security and IT Risk Management Program
- Translate IT compliance and risk strategy into functional and actionable plans and guides execution. Accountable for results and implementing solutions with a longer term view that impact multiple functions across Anchorage Digital
- Lead and execute key team projects from start to finish, including but not limited to risk assessments, cybersecurity assessments, requirements mapping, and gap analyses
- Develop meaningful reporting, metrics, analysis, and controls commensurate with business needs and regulatory expectations
- Drive the maturity of the enterprise information security and IT risk management program commensurate with national and international standards (e.g. NIST, FFIEC, ISO, SOC 2)
- Maintain entity controls and identify, report, and control incidents relevant to the services offered by the business lines and supported jurisdictions
- Drive resolution of IT security internal and external audit issues, including developing and implementing management action plans
- Work autonomously, defines priorities under broad direction, and applies problem solving skills to translate regulations and compliance obligations into technical controls, and vice-versa.
Organizational Knowledge:
- Understanding of enterprise-level information security programs and the ability to maintain a control set and policy framework which satisfies regulatory requirements in an efficient and elegant manner
- Understands how the company’s priorities relate to their own area of work, and clearly communicates the ‘why’ behind the work.
- Engages with other peers to develop methods, techniques and evaluation criteria for projects, programs, and people that have enterprise-wide impact
- Works on complex issues where analysis of situations or data requires an in-depth knowledge of the company
- Stays aware of changes through cross-functional collaboration to anticipate and prevent obstacles from hindering team performance
Communication and Influence:
- Communicates proactively, takes ownership in assigned work/projects, and is comfortable asking questions when something is unclear or to further knowledge in a specific area
- Contributes to cross-functional projects, collaborates with their team and adjacent teams working directly with subject matter experts and doing meaningful translation of compliance requirements into actionable processes
- Builds effective relationships with stakeholders including clients, team managers, cross-functional partners, and external partners. Is engaging, easy to approach and builds appropriate rapport, with diplomacy and tact, and recognized as a technical leader whose knowledge, ideas and critical thinking impact the strategic direction of Anchorage Digital
- Consistently expresses clear, thoughtful, analytical and solutions-oriented communications, whether in high-impact slides/decks, written communications in slack or email, or verbal communications
- Ensure compliance with the changing laws and applicable regulations
- Mentors and guides others on the team within the cybersecurity and cloud security domains
You may be a fit for this role if you have:
- A background working on programs and the ability to manage multiple processes and projects at once while building constructive working relationships with stakeholders across the different teams,
- A strong understanding of key cloud architecture principles, cryptography, APIs, as well as appropriate enterprise security practices
- Knowledge and experience of Information Security Risk and Security Governance
- Experience with NIST 800-53, NIST Cybersecurity Framework, ISO 27001, SOC 1/2
Although not a requirement, bonus points if:
- You have experience working in start-ups tech and/or fin-tech companies
- You have experience working as information systems auditor or consultant
- You were emotionally moved by the soundtrack to Hamilton, which chronicles the founding of a new financial system. :)