Skip to content

Open nowPosted 10 days ago

Information Security & Risk Manager

Empyrean5 open roles

Where
Houston, TX, USA
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowInformation Security & Risk ManagerEmpyrean · Houston, TX, USA
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Empyrean's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 10 days ago

The posting

The Information Security & Risk Manager (ISRM) is an individual contributor responsible for supporting and advancing Empyrean’s information security governance, risk, compliance, and assurance program. The role provides leadership for the ISO 27001 Information Security Management System (ISMS), security risk assessments, control evaluation, policy governance, audit readiness, and remediation activities. The ISRM partners with business, technology, Security, Privacy, and leadership stakeholders to identify, assess, document, monitor, and communicate information security risks and to promote practices aligned with established policies, standards, and control requirements.   ESSENTIAL DUTIES AND RESPONSIBILITIES

Lead Empyrean’s ISO 27001 certification, surveillance, internal audit readiness, and ongoing ISMS compliance activities. Coordinate ISO 27001 control testing and communications with control owners, business partners, and audit stakeholders. Support directly or indirectly other assessments and assurance activities, including SOC 2, NIST AI RMF, NIST CSF, NIST 800-53, HIPAA, and other applicable frameworks or requirements. Coordinate and collaborate with Empyrean business units to identify, assess, and communicate risks and control gaps in support of the established control environment and second-line-of-defense (2LoD) oversight. Partner with business and technology management to develop, implement, track, and validate corrective action and risk-remediation plans. Manage and coordinate audit and assessment activities related to ISO 27001, SOC, information security, cybersecurity, business applications, and integrated technology controls. Lead and/or coordinate information security risk assessments associated with major technology initiatives, material environmental changes, third parties, emerging technologies, control exceptions, and other identified risk events. Support and facilitate recurring security risk and governance meetings, including preparation, documentation, and follow-up activities. Maintain the enterprise information security risk register and related risk, issue, exception, and remediation documentation. Provides technical expertise to the teams and uses sound security and  compliance practices. Applies analytical skills to review information and determine potential control weaknesses. Uses technical and compliance skills to design secure ways to accommodate exceptions to the established security policy in order to support the business. Participate in meetings with business units and control owners to discuss control requirements, assessment results, risks, and remediation activities. Partner with Security and Privacy teams to understand the information security and privacy risk profile and apply that knowledge to risk, audit, and assurance planning. Lead the development and coordination of information security and technology responses for client security questionnaires, RFPs, due-diligence requests, internal inquiries, and related materials; participate in client meetings as a security and risk subject-matter expert when needed. Partner with security and engineering teams to review, assess, and evaluate the effectiveness of the enterprise cybersecurity threat and vulnerability monitoring and management plan. Identify gaps in security policies, standards, and supporting documentation and develop or revise documentation to address identified needs. Maintain and coordinate updates to information security policies, standards, and related governance documentation. Work cross-functionally on technology initiatives to provide security risk and IT controls expertise, evaluate control design and implementation, and support alignment with established control requirements. Apply knowledge of applicable legal, regulatory, contractual, and privacy requirements when evaluating information security controls. Work with management and users to interpret the significance of audit findings, conclude on findings, make practical recommendations, and verify that remediation plans are implemented. Provide cross-functional support to broader information security initiatives, incidents, escalations, and priority projects as business needs require. Support security roadmaps, business plans, incidents, escalations, and strategic initiatives as needed.

    REQUIRED SKILLS AND ABILITIES 

Strong communication, presentation, and organization skills Strong time-management skills and the ability to manage multiple priorities effectively Ability to effectively engage and work with a variety of roles and teams

Prior security compliance, risk, or audit experience, particularly with ISO 27001; experience with SOC 2, HIPAA, NIST, FedRAMP, or similar frameworks is a plus. Ability to contribute to cross-functional security, technology, risk, and assurance initiatives. Strong written and verbal skills with experience preparing work papers, audit reports, and presentations Strong interpersonal skills with experience dealing with people of various levels of seniority Working knowledge of information security, technology risk, audit, and control-assurance practices; familiarity with relevant IIA and ISACA guidance is beneficial. Strong understanding of security and control frameworks, including ISO 27001, SOC 2/TSC, NIST CSF, NIST 800-53, NIST AI RMF, CIS, COBIT, and other applicable frameworks. Experience with enterprise workflow, ticketing, directory, IT infrastructure, GRC, and security technologies; experience with ServiceNow and Jira is beneficial. High level of integrity and confidentiality. Relevant certifications such as CISA, CISM, CISSP, CIA, ISO 27001 Lead Implementer/Lead Auditor, or equivalent are preferred.

    KNOWLEDGE, EXPERIENCE AND/OR EDUCATION REQUIREMENTS

5+ years of experience in information security risk, governance, compliance, technology audit, security engineering, or related areas, preferably within a technology or regulated environment. ISO 27001 Lead Implementer or Lead Auditor training and/or relevant certifications such as CISA, CISM, or CISSP are preferred. Working knowledge of information technology and security best practices and control frameworks such as NIST CSF, SOC 2/TSC, CIS, ISO 27001/ISMS, COBIT, and ITIL. Demonstrated knowledge of technology risks, including direct experience evaluating the effectiveness of cybersecurity, privacy and engineering controls. Strong understanding of cybersecurity processes and technology concepts, including vulnerability management, security governance, software development, incident response, physical security, logging and monitoring, microsegmentation, secure access service edge (SASE), zero trust, insider threat, vendor risk management, PKI, penetration testing, application controls, and segregation of duties. Advanced understanding of internal controls and the demonstrated ability to evaluate and determine the adequacy of control design and operating effectiveness.

    Disclaimer: This job description is not intended to be an exhaustive list of all duties, responsibilities, or qualifications associated with the job. Management reserves the right to modify or reassign job duties as business needs evolve.   #LI-RZ1  #LI-Remote  

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Empyrean's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Empyrean's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Empyrean's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.