Jobs and Careers
NA

Lead Risk Management Analyst

Navy Federal Credit Union
United Statesfull_timeVerifiedPosted 9 Aug 2024

About the role

This role is specifically designated to support the Security Governance & Risk - Issue and Event Management with a focus on data security events, data exfiltration events, cyber incidents as well as third party events. 

Experience in cyber threat analysis, third party incident response, data breach management, risk management and an understanding of ORM framework as it relates to issue management. Responsibilities include supporting the daily operations of data security event management and partnering with the Office of General Counsel and Compliance to process data security and privacy breach events. Promote operational efficiency and service excellence through appropriate risk management strategies, process improvements and training while reducing and mitigating operational, reputational, legal/regulatory, and financial losses. Provide analytical support and execution for various business strategies to ensure Navy Federal goals are met. 

  • Manage identification of third-party events to engage applicable business partners, InfoSec, Third Party Risk Management, third party vendor and relationship owner
  • As applicable, articulate implications of risks and issues related to data management and protection to sponsors and risk owners
  • Assist in gap analysis and identification of applicable IT/Cyber related controls
  • Assist in the development and execution of Table Top Exercises related to Data security event management
  • Translate control deficiencies into action plans and provide recommendations to enhance governance practices in alignment with risk and compliance frameworks 
  • Experience in GRC tool submission for data security event tracking and capturing remediation activities
  • Participate in Security-related special projects, councils, working groups, etc. as a Risk SME
  • Aid in the development of remediation plans
  • Facilitate root cause analysis
  • Assess the impact and likelihood of an issue and provide justification for the ratings
  • Leverage various communication channels to obtain required information 
  • Support metrics and reporting focused on issues and event processes and results
  • Keep current with Information Security best practices and industry trends, and communicate/apply these practices to policy improvements and compliance actions
  • Perform other duties as assigned 
  • Bachelor’s Degree in Business Administration, Auditing, Law or related field or equivalent combination of training, education, and experience
  • Advanced knowledge and understanding of risk-based auditing techniques and methodologies
  • General knowledge of operational and regulatory risk controls, concepts, and practices
  • General knowledge of applicable federal and state regulations, company policies, and industry best practices
  • Proven ability to plan, organize and effectively execute risk mitigation and process improvement initiatives
  • Ability to maintain professionalism when delivering challenging and unfavorable messages
  • Advanced organizational, planning and time management skills in order to multi task competing priorities in a fast paced and dynamic environment 
  • Expert skill maintaining accuracy with attention to detail and meeting deadlines
  • Expert communication and negotiation skills with ability to exercise good judgement and tact in dealing with senior management
  • Significant experience in collaborating across organizational boundaries and building partnerships across various functions
  • Expert demonstrating thought-leadership, initiative-taking, decision-making and creativity solving business problems

Desired Qualifications

  • Master’s or Advanced Degree in Business Administration, Auditing, Law or related field or equivalent combination of training, education, and experience
  • NCCO, CRCM, or other applicable compliance certification
  • Working knowledge of Navy Federal’s functions, philosophy, operations and organizational objectives
  • Advanced knowledge of state and Federal laws; industry regulations, principles, and practices; and company policies that govern the business unit’s products/services
  • Professional certifications including, but not limited to any of the following: FRM, PRM, ORM, CISA, CISM, CISSP, CGEIT, CRISC, CFE, CPA, CIA, CIPP, ISA, AWS etc.
  • Working knowledge of the MITRE attack framework

Hours: Monday - Friday, 8:00AM - 4:30PM

Location: 820 Follin Lane, Vienna, VA 22180 | 5510 Heritage Oaks Drive Pensacola, FL 32526 | 141 Security Drive Winchester, VA 22602 | 9999 Willow Creek Road San Diego, CA 92131 | Remote

Navy Federal provides much more than a job. We provide a meaningful career experience, including a culture that is energized, engaged and committed; and fierce appr

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Navy Federal Credit Union

View company profile →