Jobs and Careers
EN

Information Security Risk Management Director

Envestnet
United Statesfull_timeVerifiedPosted 8 Sept 2025

About the role

Envestnet is seeking an Information Security Risk Management Director to join our Technology department. This is a hybrid role, with in-office work required at either our Berwyn, PA or Raleigh, NC office.

Envestnet is transforming the way financial advice is delivered through its connected technology, advanced insights, and asset management solutions – backed by industry-leading service and support. Since 1999, Envestnet has served the wealth management industry and today supports trillions in platform assets, serving over a hundred thousand financial advisors. The vast majority of the nation’s leading banks, the largest wealth management and brokerage firms, and over 500 of the largest RIAs rely on Envestnet’s wealth management platform and solutions to drive business growth, boost productivity, and deliver better financial outcomes for their clients. 

Envestnet’s Strategy:

  • Deliver the industry-leading wealth management platform, powered by advanced data and insights 
  • Leverage our scale and efficiencies to serve our clients’ needs comprehensively 
  • Enable financial advisors to deliver more holistic advice – reflecting a more complete view of their clients’ financial lives, and in a more connected environment

For more information, please visit www.envestnet.com.

Job Summary: 

Reporting into the Head of Information Security, the Information Security Risk Management Director will lead the Information Security Risk Management function. The ideal candidate will bring a blend of technical acumen and strategic insight, capable of effectively communicating with stakeholders and guiding team members in alignment with our security culture and business priorities. The candidate will possess a strong background in information security risk management and cybersecurity, with working knowledge and experience in risk management frameworks such as NIST Cybersecurity Framework, NIST Risk Management Framework, NIST AI Risk Frameworks. The candidate will have an evolved understanding of the regulatory landscape for Information Security and Data Protection for the financial sector. Envestnet is looking for a strong transformational risk expert who can work closely with cross-functional security, operations, and engineering teams supporting leadership to ensure a robust comprehensive security risk management program is in place. This includes top down and bottom-up assessments, while ensuring communicate identified risks effectively, and ensure timely remediation from a technical perspective, in addition to enhancing the security risk management program capabilities.

Job Responsibilities:

  • Owns the information security risk management function to conduct security risk and control assessments to identify potential risks from threats and vulnerabilities within the organization's information assets, infrastructure and applications. 
  • Responsible for assuring that all risk management activities are properly performed, documented, communicated professionally and clearly, and that all documentation is organized efficiently and effectively within the Archer GRC tool.
  • Ensure that control effectiveness assessments are aligned with our NIST based policies and standards by collaborating with cross-functional teams to understand technical implementations and assess control effectiveness
  • Partner and work closely with the peers to develop an approach to an expanded insider threat program and provide related structure, and management practices for the Envestnet enterprise.
  • Responsible for refining and documenting the process used by the risk Management team and managing the adherence to it; develops new processes or modifies existing processes in alignment with NIST CSF 2.0 and other relevant risk models as needed.
  • Drive information security risk orchestration activities and process improvements to ensure proper full coverage across products and services
  • Communicate identified security risks and their potential impact to stakeholders, including technical and non-technical audiences using a NIST based framework for quantified and qualitative models.
  • Develop and facilitate threat driven cyber scenarios and architectural visuals to support the assessment process to feed into the risk assessment pipeline and subsequent roadmaps for remediation.
  • Provide metrics and outcome-based performance indicators on risk management activities and assessment results using risk quantification as needed.

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Envestnet

View company profile →