CRO - Information Security & Risk Oversight Lead Job at Bloomberg, New York, NY

  • Bloomberg
  • New York, NY

Job Description

CRO - Information Security & Risk Oversight Lead Location New York Business Area Legal, Compliance, and Risk Ref # 10052405 Description & Requirements The energy of a newsroom, the pace of a trading floor, the buzz of a recent tech breakthrough; we work hard, and we work fast - while keeping up the quality and accuracy we're known for. It's what keeps us inventing and reinventing, all the time. Our culture is wide open, just like our spaces. We bring out the best in each other through collaboration. Through our countless volunteer projects, we also help network with the communities around us, too. You can do amazing work here. Work you couldn't do anywhere else. It's up to you to make it happen. About the Role: We’re looking for a Head of Information Security Risk who can translate cybersecurity risk into both executive insight and technical solutions. Reporting directly to our Head of Technology Risk as part of the Chief Risk Office, you will provide independent oversight, technical consultation and credible challenge across the firm’s enterprise-wide information security program. Operating at the intersection of cybersecurity, risk management, governance, and strategy, you will be the senior cyber-risk partner to the Chief Information Security Office, Engineering, and Chief Technology Office. You will engage on topics ranging from technical security findings to programmatic decisions and regulatory strategy to ensure the company is operating within its target risk appetite and regulatory expectations. Your oversight will enable Bloomberg’s senior leadership to understand not only what the risks are, but where decisive action is required to strengthen the firm’s overall security posture. Key Responsibilities * Serve as the primary Second Line advisor for cybersecurity-related risks and lead independent oversight and credible challenge of First Line of Defense activities. * Evaluate and consult on the design and operating effectiveness of security programs and controls, particularly across complex, high-risk, or enterprise-scale technology initiatives. * Review and challenge security-driven programs and initiatives to ensure alignment with enterprise risk appetite, industry control frameworks, and regulatory expectations. * Partner closely with Information Security, CISO, ERM, and Engineering teams to enhance risk awareness, accountability, and control ownership. * Identify root causes of control failures, security incidents, or systemic weaknesses and support the development of actionable, preventative recommendations. * Prepare and present risk oversight materials to senior leadership committees, internal audit, Board of Directors, and regulatory bodies as required. * Act as a strategic thought partner to senior leaders by advising on emerging threats, evolving regulatory requirements, and industry best practices. *Attract, hire and manage a team of technical risk professionals to identify and measure threat-actor initiated risks and risk scenarios that may impact the confidentiality, integrity, and availability of information systems. Required Qualifications * Bachelor’s Degree required. * 10+ years of experience in one or more technical Information Security disciplines (security architecture, penetration testing, application security, cyber defense, etc.) * Demonstrated experience operating within an independent oversight function as part of a Risk, Information Security, or Architecture team. * Strong understanding of cybersecurity frameworks (e.g., NIST CSF, NIST 800-53, TLPT/TIBER-EU, MITRE ATT&CK, ISO 27001, COBIT, CIS). * Experience interacting with Boards, regulators, internal audit, and/or executive governance forums. * Authorized to work in the United States. Preferred Qualifications * Relevant technical and/or professional certifications (e.g., GIAC GPEN/GDAT, CREST,FAIR, CISSP, CISM, CRISC, CISA). * Experience in regulated industries (e.g., financial services). * Strong understanding of cloud security, application security, identity and access management, and cyber resilience. * Familiarity with enterprise risk management methodologies and risk appetite frameworks. Core Competencies * Strong analytical and critical thinking skills with the ability to provide constructive challenge. * Executive-level communication and presentation skills. * Ability to influence without direct authority. * Strategic mindset with strong attention to detail. * High integrity and independent judgment. Salary Range = 215,000 - 290,000 USD Annual + Benefits + BonusThe referenced salary range is based on the Company's good faith belief at the time of posting. Actual compensation may vary based on factors such as geographic location, work experience, market conditions, education/training and skill level. We offer one of the most comprehensive and generous benefits plans available and offer a range of total rewards that may include merit increases, incentive compensation (exempt roles only), paid holidays, paid time off, medical, dental, vision, short and long term disability benefits, 401(k) +match, life insurance, and various wellness programs, among others. The Company does not provide benefits directly to contingent workers/contractors and interns. Discover what makes Bloomberg unique - watch our podcast series for an inside look at our culture, values, and the people behind our success.

Job Tags

Temporary work, For contractors, Work experience placement, Work at office

Similar Jobs

Saxon Global

Mainframe Systems Programmer Job at Saxon Global

Job Title Job Requirements: - BM z/OS Operating System installation, configuration, customization, and upgrades. - JCL (Job Control Language) creating, debugging, and optimizing batch jobs. - System Utilities & Tools ISPF, TSO, SDSF, REXX, CLIST. - System...

IDA Center for Computing Sciences

Cisco Network Engineer Job at IDA Center for Computing Sciences

 ...administration. Possess advanced knowledge in IP-based network and telecommunication system design, administration, and support, preferably Cisco. Experience with Cisco Nexus platforms and NX-OS, Cisco VoIP, and components ASAs firewalls and network hardening, as well as... 

US Family Health Plan @ SVCMC, Inc.

Clinical Quality Reviewer Job at US Family Health Plan @ SVCMC, Inc.

 ...to Team Lead, Clinical Quality and Record Review. Works independently and with other...  ...applicable, to obtain information and/or medical records needed to conduct a comprehensive...  ...cases and final determinations. Conduct chart reviews and audits both electronic and at... 

PFG Customized

CDL-A Delivery Driver Job at PFG Customized

PFG Customized, a division of Performance Food Group, is seeking a CDL-A Delivery Driver to support national and regional restaurant and retail chains in our wholesale foodservice distribution network. In this fast-paced, safety-first role, you will operate CDL-A tractors... 

Goldfish Medical Staffing

Physician Senior Recruiter Job at Goldfish Medical Staffing

 ...Job Description Job Description Physician Recruiter Goldfish Medical Staffing is growing, and were looking for a Permanent Recruiter who thrives in a fast-paced, performance-driven environment and takes real ownership of outcomes. This role is ideal for someone...