Jobs and Careers
TR

Manager, Security Risk & Compliance

Triumph Financial
United Statesfull_timeVerifiedPosted 3 Oct 2024

About the role

Join TriumphX!

TriumphX, a member of the Triumph Financial portfolio of brands, provides a concentration of technology and project management resources the members of the Triumph Financial portfolio of brands – TriumphPay, Triumph and TBK Bank – via a shared service model. We’re looking for top tech and project management talent to analyze, recommend and build strategic solutions that support Triumph Financial’s mission to become a world-class, market-leading financial and technology company.

Position Summary

The Manager, Security Risk and Compliance will build out and maintain ownership of the enterprise SOC compliance process, ensuring that all security measures are in place and that all SOC audits are completed successfully. The successful candidate will need to be detail-oriented, able to juggle multiple priorities, and have effective communication skills understanding industry standards and best practices. The position requires both an understanding of legacy systems, as well as innovative technologies. The Manager, Security Risk and Compliance position reports to the VP, IT Risk & Compliance and will engage in many facets of the information security and GRC programs while providing guidance and functioning as an experienced SOC compliance resource to control owners and business partners. The Manager will be given the ability to collaborate with various teams to identify risks, deficiencies, create controls and report on SOC compliance progress. As a primary point of contact for SOC auditors, the Manager monitors progress and enforces resolution of outstanding issues that may lead to non-compliance or security threats to the business. As a key member of the security team, the Manager must focus on strong risk management and corporate resiliency, and not be driven solely by compliance.

Essential Duties and Responsibilities

  • Create, implement, support, and maintain an effective and mature SOC compliance program within the GRC team at Triumph Financial.

  • Establish and maintain SOC compliance processes that ensure customer data is secure and all applicable regulations are met.

  • Learn existing products and the supporting technology within the SOC scope, as well as new products and the supporting technology on the roadmap ahead.

  • Establishes the control framework, evidence, and testing requirements for the enterprise to use for SOC compliance and maintains the framework to keep up to date with technological changes.

  • Serves as the central point of contact with Triumph Financial business partners and clients regarding questions, issues and requests for SOC reports and provides guidance and support to the team on value-add solutions.

  • Establish key relationships and partner with Divisional Presidents, as well as Enterprise CIO, CTOs and CISO to support the SOC program.

  • Coordinates External (SOC1 and SOC2) audits.

  • Provides documentation and evidence to respond to SOC audits and collaborates with the functional areas to gather evidence.

  • Monitor industry standards and best practices to ensure SOC compliance.

  • Develop and maintain relationships with internal and external stakeholders.

  • Explains SOC controls with clarity to business and technical subject matter experts.

  •  Identifies requirements needed for successful SOC compliance and certification.

  • implements a standardized process for initiative-taking and timely control self-assessment testing and deficiency communication of all SOC related controls to control owners and management.

  • Leads the design, development, and remediation of SOC controls.

  • Perform certain vendor due diligence tasks, such as, reviewing vendor SOC reports and any associated Complimentary User Entity Control (CUEC) mapping activities.

  • Prepares SOC compliance metrics and effectively communicates this through Executive level presentation and reporting.

  • Contributes to team objectives.

  • Other duties as assigned.

Experience and Education

  • Bachelor’s degree in business, Management, Accounting, Finance, Information Security, Information Systems, Computer Science, or equivalent work experience

  • 6+ years of prior relevant IT risk, IT security and/or IT audit experience

  • 4+ years of experience leading and managing technology

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Triumph Financial

View company profile →