ISRMP Program Lead
State StreetAbout the role
Who we are looking for
The Information Security Management Program Team (ISRMP) is looking to enhance its team in the GCS application security assessment process. The team is responsible for ensuring the risk posture of the application is compliant to the industry standards. The Vice President will be engaged in efforts to manage relationships, streamline the program processes, and measure and mitigate cyber and technology risk and will report to the Managing Director of ISRMP.
What you will be responsible for
As the ISRMP Manager you will be responsible for:
Relationship Management for SNOW IRM Module
Representing the program in conversations with leadership and regulators
Representing the program in strategy sessions associated with program design, regulatory responses, and budget design
Leading the interaction with the internal technology teams, responsible for supporting the platform and implementing future enhancements
Raising awareness of the processes and the requirements with various stakeholders
Working with key stakeholders like the ISOs, business representatives to lead the ISRMP team on working toward ISRMP completion compliance across the bank
Support the operational team in their work, and be a focal point for escalations
Provide reoccurring leadership updates to support cyber risk and board reporting requirement
Produce metrics to support KPI and KRI reporting
Independently validate remediation activities as documented by business to achieve resilient and secure networks, operating systems, and applications
What we value
These skills will help you succeed in this role:
Ability to interact with and communicate professionally with multiple levels of management in multiple regions.
Excellent verbal and written communication skills, ability to express ideas and understand workflows.
Strong time management skills, problem-solving and critical thinking skills
Proven experience with a GRC tool such as Archer a plus
Experienced with frameworks such as NIST CSF, NIST 800.53R5 and/or CSA CCMv4
Experience in formulating, maintaining, and executing project plans
Experience in creating process flows, identifying controls, creating management information in PowerPoint decks
Experience with Microsoft Office Suite of tools (O365)
Must have the ability to operate in a timely in a deadline-oriented environment with simultaneous deliverables
Must be detail-oriented
Experience working in the Financial industry preferred, but not required
Education & Preferred Qualifications
B.S. or equivalent experience with over all 15-20 Years of experience
Minimum 5 years of experience working in Information Security or general IT areas related to risk management, controls assurance, compliance programs, cybersecurity and technology regulations, industry standards, and internal policies frameworks
At least 5 years of prior experience in risk management/audit team with knowledge of Archer control inventory or other similar systems preferred
At least 5 years experience working with the application development processes similar to Software Development Life Cycle management, architecture reviews, and change management
Are you the right candidate? Yes!
We truly believe in the power that comes from the diverse backgrounds and experiences our employees bring with them. Although each vacancy details what we are looking for, we don’t necessarily need you to fulfil all of them when applying. If you like change and innovation, seek to see the bigger picture, make data driven decisions and are a good team pla
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s