Manager, Cybersecurity Governance and Compliance
Ares Management CorporationAbout the role
Over the last 20 years, Ares’ success has been driven by our people and our culture. Today, our team is guided by our core values – Collaborative, Responsible, Entrepreneurial, Self-Aware, Trustworthy – and our purpose to be a catalyst for shared prosperity and a better future. Through our recruitment, career development and employee-focused programming, we are committed to fostering a welcoming and inclusive work environment where high-performance talent of diverse backgrounds, experiences, and perspectives can build careers within this exciting and growing industry.
Job Description
We are seeking a highly motivated Cybersecurity Governance Risk and Compliance (GRC) professional who will be responsible for monitoring and supporting our global IT and Security related GRC efforts. Responsibilities of a successful candidate would also include ensuring the organizations adherence to Cybersecurity policies, standards, and procedures, developing sector specific security training programs, managing cybersecurity risk, and maintaining compliance with relevant regulations and security frameworks. This candidate must have excellent technical writing skills, strategic process development capabilities, and a deep understanding of various industry standard cybersecurity frameworks. A successful candidate will be expected to participate in cross functional support of programs run and operated by our Compliance, Enterprise Risk Management, Internal Audit, and Legal teams. This candidate should also have excellent verbal communication skills with the ability to present GRC information to internal and external parties.
The candidate will be part of a talented team of Cybersecurity Professionals that demonstrate excellent technical competencies. This is an opportunity to support mission critical Cybersecurity Governance efforts by ensuring we are proactively identifying gaps in security and proposing security controls to address them. If you are a candidate looking to be a part of a dynamic team, that continuously challenges itself, is committed to learning and improving, and passionate about cybersecurity, then this could be the right opportunity for you!
Primary Functions & Responsibilities
Write policies, standards, procedures, guidelines, and other technical security documents.
Design technical and administrative enforcement mechanisms for defined security rules.
Develop and deliver sector specific annual cybersecurity awareness training and manage overall cybersecurity training program, including phishing campaigns and other components of training.
Contribute to data governance working group initiatives around data security and data privacy.
Select, design, develop and implement security controls within our internal control catalog.
Facilitate security control testing and integrate controls into existing processes.
Maintain inventory of succinct and accurate security program descriptions for answering RFPs/RFIs/DDQs/etc.
Coordinate comprehensive risk assessment within the risk management program and develop/propose risk mitigation strategies.
Conduct security TPRM for Vendors at onboarding, contract review, RFP/RFI, and annual re-assessments while managing the continuous monitoring strategy.
Maintain GRC Metrics, risk tolerances/triggers.
Develop automated reports and use data visualization tools to visualize GRC KPIs.
Interpret audit request lists and perform evidence collection activities in support of various audits.
Minimize user disruption due to burdensome security controls or duplicative evidence collection.
Qualifications
Education:
Bachelor’s degree in Cybersecurity, Engineering, Information Security, Information Technology, Computer Science or other related disciplines.
Experience Required:
5+ years of Governance, Information Technology, Security, or Risk Management experience in the finance or technology sector.
General Requirements:
Fundamental understanding and familiarity with global cybersecurity regulatory requirements, and security frameworks (ex. National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF), International Organization for Standardization (ISO)27001, American Institute of Certified Public Accountants (AICPA) Trust Services Criteria), General Data Protection Regulation (GDPR).
Strong technical writing skills for policy, standard, and procedure writing/editing.
Strong strategic process development skills with a tendency toward automation.
Proven experience conducting cybersecurity risk assessments and compliance audits.
Famil
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s