489,618open jobs
16,287companies
72,295added this week
Browse all
Salary
$215k – $290k per year
Location
In office
Seniority
Staff · 10+ years exp
Overview
Company
Impact
Profile match
Headquartered in New York City, New York, Bloomberg is a global leader in financial technology, data, and business media. The company is best known for its proprietary Bloomberg Terminal, which provides financial professionals with real-time market analytics, trading tools, and execution capabilities. Through its multi-platform news division, it delivers economic reporting, research, and analysis across television, digital, print, and audio outlets worldwide.

The energy of a newsroom, the pace of a trading floor, the buzz of a recent tech breakthrough; we work hard, and we work fast - while keeping up the quality and accuracy we'reknown for. It'swhat keeps us inventing and reinventing, all the time. Our culture is wide open, just like our spaces. We bring out the best in each other through collaboration. Through our countless volunteer projects, we also help network with the communities around us, too. You can do amazing work here. Work you couldn'tdo anywhere else. It'sup to you to make it happen.

About the Role:

We’re looking for an Information Security Risk Oversight Lead who can translate cybersecurity risk into executive insight and action. Sitting in theCompany’sSecond Line of Defense, the Chief Risk Officeand reporting directly to our Head of Technology Risk, you will provide independent oversight and credible challengeacross the firm’s enterprise-wide information security program. Operating at the intersection of technology, riskmanagement,cybersecurity,governance, and strategy, you will partner with the Chief Information SecurityOffice, Engineering, and CTOteams to ensure cyber risks are appropriately identified, measured, monitored, and aligned with the firm’s risk appetite. The "so what" is critical: your oversight will enable leadership to understand not only what the risks are, but whether they are being managed effectively-and where decisive action is requiredto strengthen the firm’s overall security posture.

Key Responsibilities

* Serve as the primary Second Line risk advisor for cybersecurity -related risksand lead independent oversight and credible challengeof First LineofDefenseactivities.

*Identifyand measure threat-actor initiatedrisks and risk scenariosthat may impactthe confidentiality, integrity, and availability of information systems.

* Evaluate the design and operating effectiveness of security controls, particularly across complex, high-risk, or enterprise-scale technology initiatives.

*Quantify risk and control posture to support executive decision-makingthrough scenarioanalysis and metrics (e.g., KRIs, KPIs, SLA/SLOs, ALE).

* Review and challenge security-driven programs and initiatives to ensure alignment with enterprise risk appetite, industry control frameworks, and regulatory expectations.

* Partner closely with Information Security and Engineering teams to enhance risk awareness, accountability, and control ownership.

* Identifyroot causes of control failures, security incidents, or systemic weaknesses and support the development of actionable, preventative recommendations.

* Prepare and present risk oversight materials to senior leadership committees, internal audit,Boardof Directors,andregulatory bodies as required.

* Act as a strategic thought partner to senior leaders by advising on emergingthreats, evolving regulatory requirements, and industry best practices.

Required Qualifications

* Bachelor’s Degreerequired.

* 10+ years of experience in Information Security.

* 10+ years of experience in ITor CyberRisk Management.

* Demonstratedexperience operating within a Second Line of Defense or independent risk oversight function.

* Strong understanding of cybersecurity control frameworks (e.g., NIST CSF, NIST 800-53, MITREATT&CK, ISO 27001, COBIT, CIS).

* Experience interacting with Boards, regulators, internal audit, and/orexecutive governance forums.

* Authorized to work in the United States.

Preferred Qualifications

* Relevant professional certifications (e.g., FAIR, CISSP, CISM, CRISC, CISA).

* Experience in regulated industries (e.g., financial services).

* Strong understanding of cloud security, application security, identity and access management, and cyber resilience.

* Familiarity with enterprise risk management methodologies and risk appetite frameworks.

Core Competencies

* Strong analytical and critical thinking skills with the ability to provide constructive challenge.

* Executive-level communication and presentation skills.

* Ability to influence without direct authority.

* Strategic mindset with strong attention to detail.

* High integrity and independent judgment.

Salary Range = 215,000 - 290,000 USD Annual + Benefits + Bonus

The referenced salary range is based on the Company's good faith belief at the time of posting. Actual compensation may vary based on factors such as geographic location, work experience, market conditions, education/training and skill level.

We offer one of the most comprehensive and generous benefits plans available and offer a range of total rewards that may include merit increases, incentive compensation (exempt roles only), paid holidays, paid time off, medical, dental, vision, short and long term disability benefits, 401(k) +match, life insurance, and various wellness programs, among others. The Company does not provide benefits directly to contingent workers/contractors and interns.

Discover what makes Bloomberg unique - watch our podcast series for an inside look at our culture, values, and the people behind our success.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
489,618 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$130k – $160k per year • Remote • Full-Time • 8+ years exp
Python
PowerShell
Databases
Redis
Azure SQL Database
AI/ML
Anomaly Detection
DevOps
Terraform
Azure DevOps
CloudFormation
Consul
Datadog
PagerDuty
Azure
CI/CD
Jenkins
AWS
Kubernetes
Cloudflare
SaltStack
Configuration Management
Azure AKS
Amazon S3
Amazon CloudWatch
Cybersecurity
ISO 27001
SOC 2
NIST 800-53
FedRAMP
Microsoft Entra ID
Delinea
Management
Jira
Apply
$178k – $330k per year • In office • Full-Time • 7+ years exp • Bachelor's Degree • Richardson • Chicago
Cybersecurity
ISO 27001
NIST CSF
HIPAA
Apply
Corporate IT Manager 2 hours ago
$82k – $239k per year (Estimated) • Remote/Hybrid • Full-Time • 2+ years exp • Bogotá
DevOps
SLI/SLO/SLA
IAM
Cybersecurity
ISO 27001
SOC 2
Least Privilege
Apply
$9k – $17k per year (Estimated) • In office • Full-Time • 2+ years exp • Bengaluru
DevOps
SLI/SLO/SLA
Analytics
Microsoft Excel
Apply
Eletromecânico 10 min ago
In office • Full-Time • São Paulo
DevOps
SLI/SLO/SLA
Apply
$110k – $210k per year • Remote/Hybrid • 4+ years exp • Bachelor's Degree
AI/ML
LLM
Time Series Forecasting
Apply
$155k – $285k per year • In office • 4+ years exp • Bachelor's Degree
SAS
Apply
Apply
Apply
$160k – $240k per year • In office • 4+ years exp
Python
Java
DevOps
Terraform
Ansible
eBPF
IAM
Cybersecurity
CyberArk
Least Privilege
Teleport
Apply
See all jobs
This is one of many
489,618 more open roles from verified company boards, updated every day.