{"id":1307382,"url":"https://alion.io/job/bloomberg-information-security-risk-manager","title":"Information Security Risk Manager","company":{"id":7892,"name":"Bloomberg","domain":"bloomberg.com","url":"https://alion.io/company/bloomberg","size_band":"5000+","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Avature","truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"explicit","locations":["New York, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":160000,"max":215000,"currency":"USD","period":"year","gross":null,"usd_annual":215000},"salary_estimate":null,"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"ISO 27001","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"NIST 800-53","optional":false},{"name":"NIST CSF","optional":false}],"status":"live","first_seen_at":"2026-09-26T14:12:15Z","employer_posted_date":"2026-09-26","last_verified_at":"2026-09-26T17:24:12Z","board_verified":false,"closed_at":null,"days_open":2,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":2},"description":"We’re looking for an Information Security Risk Manager who can bring together cybersecurity knowledge, risk management, and strong analytical skills.\nReporting to the Head of Information Security Risk within the Chief Risk Office, you will support independent oversight and credible challenge across the firm’s information security program. You will work closely with colleagues across Information Security, CISO, Engineering, Technology Risk, and Enterprise Risk Management to identify, assess, communicate, and resolve cybersecurity risks.\nThis role is well suited to someone with a strong foundation in cybersecurity who is looking to broaden their experience within an independent risk oversight function. You will have exposure to a range of security topics, from technical security findings and control effectiveness to cyber resilience, emerging threats, and regulatory requirements. You will help translate technical security risks into clear, actionable insights and support the organization in understanding where controls can be strengthened and risks appropriately managed.\nKey Responsibilities\nSupport Second Line oversight and credible challenge of cybersecurity and information security risks across the organization.\nAssess security risks and consult on the design and effectiveness of security controls across technology initiatives and security programs.\nReview security programs and initiatives to assess alignment with enterprise risk standards, established security frameworks, and regulatory expectations.\nPartner with Information Security, CISO, Engineering, Technology Risk, and Enterprise Risk Management teams to strengthen risk awareness, accountability, and control ownership.\nAnalyze security findings, incidents, control weaknesses, and risk scenarios to identify themes, root causes, and opportunities for improvement.\nDevelop practical recommendations to address identified security and control risks.\nAssist in developing cybersecurity risk assessments, reporting, metrics, and materials for management and governance forums.\nMonitor emerging cybersecurity threats, regulatory developments, and industry practices and assess their potential relevance to the organization.\nParticipate in risk assessments of areas including cloud security, application security, identity and access management, cyber defense, vulnerability management, and cyber resilience.\nBuild strong relationships across technical and risk teams and provide thoughtful, constructive challenge when appropriate.\nRequired Qualifications\nBachelor’s degree or equivalent professional experience.\n5+ years of relevant experience across Security Engineering, Security Architecture, Application Security, Cyber Defense, or a related technical discipline.\nWorking knowledge of cybersecurity risks, controls, and security principles.\nExperience assessing technology or security risks and communicating findings and recommendations to stakeholders.\nFamiliarity with one or more cybersecurity or technology control frameworks, such as NIST CSF, NIST 800-53, MITRE ATT&CK, ISO 27001, COBIT, or CIS.\nStrong written and verbal communication skills, including the ability to explain technical risks to both technical and non-technical audiences.\nAbility to work collaboratively across technology, security, and risk teams.\nAuthorized to work in the United States.\nPreferred Qualifications\nExperience conducting assessments as part of Information Security, Technology Risk, Risk Management, Internal Audit, Security Architecture, or another technology control function.\nRelevant technical or professional certification such as CISSP, CISM, CRISC, CISA, GIAC, or FAIR.\nFamiliarity with enterprise risk management concepts and risk assessment methodologies.\nExperience within a regulated industry, including financial services, is helpful but not required.\nCore Competencies\nStrong analytical and problem-solving skills.\nTechnical depth in one or more security domains.\nAbility to assess information objectively and provide constructive challenge.\nClear and concise written and verbal communication.\nStrong collaboration and stakeholder-management skills.\nAbility to manage multiple priorities in a fast-moving environment.\nAttention to detail while maintaining an understanding of broader risk implications.\nHigh integrity, sound judgment, and a commitment to independent risk management.\nSalary Range = 160,000 - 215,000 USD Annual + Benefits + Bonus\nThe referenced salary range is based on the Company's good faith belief at the time of posting. Actual compensation may vary based on factors such as geographic location, work experience, market conditions, education/training and skill level.\nWe offer one of the most comprehensive and generous benefits plans available and offer a range of total rewards that may include merit increases, incentive compensation (exempt roles only), paid holidays, paid time off, medical, dental, vision, short and long term disability benefits, 401(k) +match, life insurance, and various wellness programs, among others. The Company does not provide benefits directly to contingent workers/contractors and interns.\nDiscover what makes Bloomberg unique - watch our podcast series for an inside look at our culture, values, and the people behind our success.","description_format":"text","description_chars":5277,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":true},"security_clearance":false,"languages":[]},"benefits":["Life insurance","Wellness"],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Information Security","Financial Data & Market Intelligence","Financial News & Media"],"lifecycle":[{"event":"open","at":"2026-09-26T14:12:15Z"}],"liveness":{"score":88,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.878,"p_room":1,"age_days":1,"expected_fill_days":9,"reasons":["conf:36","velocity","win:early","comp:brand"],"computed_at":"2026-09-28T05:45:00Z"},"pay":{"stated_usd_annual":215000,"is_top_pay":true},"html_url":"https://alion.io/job/bloomberg-information-security-risk-manager","json_url":"https://alion.io/job/bloomberg-information-security-risk-manager.json","meta":{"generated_at":"2026-09-28T23:27:54Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1095,"day_limit":5000,"remaining_today":3905,"minute_limit":60,"resets_at":"2026-09-29T00:00:00Z"}}}