Cybersecurity Governance Manager
OneMain FinancialAbout the role
We are seeking a Manager of Cybersecurity Governance to join our dynamic team reporting to the Director of Cybersecurity Governance and Risk. This role will lead the development of a comprehensive technology and cybersecurity governance framework tailored to our on-premise and cloud environments. This role is critical in ensuring that our company's technology and cybersecurity practices are compliant with regulatory requirements and industry standards, while also effectively identifying risks.
Members of the Cybersecurity Governance team are motivated, detail-oriented, and thrive in a collaborative environment where they will add value to key business partners. This position will require you to be adaptive, willing to drive change and innovation, and work in a fast-paced environment requiring collaboration and the ability to organize and prioritize assignments.
Responsibilities:
Establish and maintain a security governance framework based on the National Institute of Standards and Technology (NIST) Cybersecurity Framework to ensure effective oversight and accountability.
Oversee the technology and cybersecurity policy program, which includes policy and control drafting, facilitating cross-functional input, and enforcement of policies, procedures, and controls.
Maintain the company’s technology and cybersecurity risk and controls matrix in alignment with multiple frameworks, including SOC2, CIS, PCI, NIST CSF, NIST 800-53, and NYDFS Part 500.
Lead the annual enterprise technology and cybersecurity risk assessment.
Establish an automated technology and cyber governance risk and compliance (GRC) program to continuously monitor and report on technology and cyber risk and control effectiveness.
Lead the company’s annual NYDFS Part 500 Cybersecurity self-assessment.
Oversee and facilitate the annual SOC2 audit and any exams and assessments focused on technology and cybersecurity controls from state examiners, regulators, and OneMain partners.
Educate, influence and provide clear directives for technology projects, either directly or through committees, to ensure the consistent application of policies, standards and controls across all technology projects, systems and services.
Partner and coordinate with the enterprise risk management team, internal audit, and other <
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s