finseats

Cyber Compliance Manager (Financial Services)new

RSM US (RSM) · Other

We are the leading provider of professional services to the middle market globally, our purpose is to instill confidence in a world of change, empowering our clients and people to realize their full potential. Our exceptional people are the key to our unrivaled, culture and talent experience and our ability to be compelling to our clients. You’ll find an environment that inspires and empowers you to thrive both personally and professionally. There’s no one like you and that’s why there’s nowhere like RSM.

In order to address the most critical needs of our clients, RSM US LLP has established the Cybersecurity and data protection risk (CDPR), comprised of dedicated cybersecurity professionals dedicated exclusively to serving the cyber security and information protection needs of our clients. This group includes experienced consultants located throughout the country dedicated to helping clients with preventing, detecting, and responding to security threats that may affect their critical systems and achieving regulatory compliance related to the handling, processing and protection of sensitive information. We serve a diverse client base within a variety of industries, and we are relied upon to provide expertise within areas of information security risk management, security testing, enterprise architecture, governance, regulatory privacy compliance, and digital forensics.

We are looking to hire a Manager within our Cyber practice to support the delivery and growth of our cybersecurity compliance services across the financial services industry. The CyberCompliance Manager will oversee the delivery of client engagements, help train and develop our people, and ensure pull-through advisory services that expand the broader Cyber Agenda within financial services industry. This role requires an understanding of financial-services-specific cybersecurity risks and regulatory expectations, including PCI DSS, NIST CSF, GLBA Safeguards Rule, NYDFS 23 NYCRR Part 500, and FFIEC cybersecurity guidance and assessment approaches. The CyberCompliance Manager will assist organizations with strengthening cybersecurity and data protection programs designed to safeguard critical assets, including cardholder data environments, customer financial data, and other sensitive information, while helping clients mature their governance, risk, compliance, and operational capabilities.

Responsibilities

  • Oversee the delivery of financial services cybercompliance engagements and help connect that work to broader cybersecurity advisory opportunities across the Cyber Agenda
  • Train, coach, and provide day-to-day oversight to managers, seniors, and staff during the delivery of cybercompliance and related cybersecurity services so our people continue to learn, grow, and deliver high-quality work
  • Help identify pull-through advisory opportunities within financial services engagements by connecting cybercompliance needs to broader cybersecurity, risk, and transformation priorities
  • Support the development of financial services cybersecurity integrated solutions, with CyberCompliance as the foundation and the broader Cyber Agenda incorporated into client service delivery
  • Understand AI and cloud security with a focus on financial services-specific risks, emerging threats, regulatory expectations, and market trends
  • Be able to communicate to clients regarding the strategic and tactical risks of account data protection, regulatory compliance, breach response, etc.
  • Support clients in designing and supporting their payment card industry and cyber compliance programs including operational processes, technology and guidelines
  • Support organizations through assessing, developing and implementing information governance frameworks.
  • Communicate complex technical issues to client senior management through the ability to transform and summarize such data into layman and executive style reports and presentations
  • Support account growth by delivering high-quality client service and helping ensure our offerings remain responsive to evolving financial services risks, regulations, and client needs

Required Qualifications

  • Relevant certifications in cybersecurity, governance, risk, and compliance are preferred, including but not limited to Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), PCI Qualified Security Assessor (QSA), or similar credentials
  • Direct experience with typical cybersecurity program components and common supporting workflows, including but not limited to:
    • Regulatory monitoring
    • Business requirements definition
    • Data inventory and information flow mapping
    • Cybersecurity risk management
    • Third party vendor management
    • Interactions with consumers / individuals (data subject requests)
    • Incident management and breach notifications
  • Bachelor’s degree in information technology, business, or related discipline from an accredited college/university
  • 5+ years of related work experience in cyber compliance, cybersecurity risk, or consulting within financial services, including experience overseeing engagement delivery, developing team members, and supporting the expansion of advisory services
  • Willingness to travel up to 30%, including international destinations requiring a passport, on short notice and for potentially extended periods of time
  • Technical knowledge and ability to speak to common topics in one or more of the following: network and IT infrastructure, common application and database design, IT governance and risk management, third party management, incident response, knowledge of typical network and IT security components
  • Working knowledge of key cybersecurity compliance standards, regulations, and sector frameworks, including but not limited to PCI DSS, NIST CSF, GLBA Safeguards Rule, NYDFS 23 NYCRR Part 500, and FFIEC cybersecurity guidance and assessment approaches
  • Proven people leadership skills with demonstrated success leading teams, overseeing engagement delivery, coaching professionals, and operating effectively within a professional services firm, large consultancy, or similar setting
  • Proven ability to effectively collaborate, especially with cross-functional teams

Preferred Qualifications

  • Demonstrated record of working with diverse organizational stakeholders, including management, business, marketing, HR, IT, Legal and others
  • Advanced degree with a focus on data protection, privacy, or a related field
  • Excellent written, oral, presentation skills, innovative thinker
  • A proven record of success working seamlessly in a virtual environment to complete projects with team members based in various locations, domestically and globally
  • Demonstrates creative thinking, individual initiative, and flexibility in prioritizing and completing tasks, particularly in face of a rapidly changing technology, regulatory, and cultural landscape and shifting client priorities
  • Keeps up to date with the Security and Privacy Industry – following the industry’s advancements, challenges, and discovery

At RSM, we offer a competitive benefits and compensation package for all our people. We offer flexibility in your schedule, empowering you to balance life’s demands, while also maintaining your ability to serve clients. Learn more about our total rewards at https://rsmus.com/careers/working-at-rsm/benefits.

All applicants will receive consideration for employment as RSM does not tolerate discrimination and/or harassment based on race; color; creed; sincerely held religious beliefs, practices or observances; sex (including pregnancy or disabilities related to nursing); gender; sexual orientation; HIV Status; national origin; ancestry; familial or marital status; age; physical or mental disability; citizenship; political affiliation; medical condition (including family and medical leave); domestic violence victim status; past, current or prospective service in the US uniformed service; US Military/Veteran status; pre-disposing genetic characteristics or any other characteristic protected under applicable federal, state or local law. 

Accommodation for applicants with disabilities is available upon request in connection with the recruitment process and/or employment/partnership. RSM is committed to providing equal opportunity and reasonable accommodation for people with disabilities. If you require a reasonable accommodation to complete an application, interview, or otherwise participate in the recruiting process, please call us at 800-274-3978 or send us an email at careers@rsmus.com.

RSM does not intend to hire entry level candidates who will require sponsorship now OR in the future (i.e. F-1 visa holders). If you are a recent U.S. college / university graduate possessing 1-2 years of progressive and relevant work experience in a same or similar role to the one for which you are applying, excluding internships, you may be eligible for hire as an experienced associate.

RSM will consider for employment qualified applicants with arrest or conviction records. For those living in California or applying to a position in California, please click here for additional information.

At RSM, an employee’s pay at any point in their career is intended to reflect their experiences, performance, and skills for their current role. The salary range (or starting rate for interns and associates) for this role represents numerous factors considered in the hiring decisions including, but not limited to, education, skills, work experience, certifications, location, etc. As such, pay for the successful candidate(s) could fall anywhere within the stated range.

Compensation Range: $107,000 - $214,500

Individuals selected for this role will be eligible for a discretionary bonus based on firm and individual performance.

Related finance jobs