Job Description: Cyber Governance Specialist
Position Summary
The Cyber Governance Specialist is responsible for supporting and advancing the organization's cybersecurity governance, risk management, and strategic security initiatives. This role leads key governance programs, oversees third-party cyber risk management, drives regulatory and audit remediation efforts, and develops executive-level reporting to enhance the organization's overall cybersecurity posture. The successful candidate will work closely with internal stakeholders, vendors, and leadership to ensure cybersecurity initiatives are effectively executed and aligned with business objectives.
Key Responsibilities
- Execute and coordinate enterprise cybersecurity initiatives, including NIST remediation activities and the Quantum Readiness Program.
- Manage the Future Threat Readiness initiative by coordinating vendor engagement, administering security questionnaires, conducting maturity assessments, tracking remediation activities, and reporting program progress.
- Lead third-party cyber risk management activities, including vendor security assessments, risk analysis, remediation tracking, ongoing security monitoring, and governance of third-party cybersecurity risks.
- Support cybersecurity governance through the development and maintenance of policies, standards, and procedures, while assisting with risk management, control maturity assessments, and audit and regulatory activities.
- Develop cybersecurity metrics, dashboards, executive reporting, and Board/Audit Committee materials to communicate program performance and organizational risk.
- Support the execution of the cybersecurity roadmap and other strategic initiatives to strengthen the organization's security capabilities.
- Conduct cybersecurity risk assessments and provide guidance on emerging cyber threats, industry trends, and evolving technology risks.
- Collaborate with cross-functional teams to promote security best practices and ensure governance processes are effectively integrated across the organization.
Qualifications & Experience
- Experience in cybersecurity governance, risk management, and compliance (GRC).
- Demonstrated experience managing cybersecurity programs, regulatory initiatives, audit remediation, and control improvement activities.
- Strong experience with third-party cyber risk management, including vendor assessments and ongoing security oversight.
- Knowledge of cybersecurity frameworks and standards, including NIST Cybersecurity Framework and related governance practices.
- Familiarity with emerging technology risks, including quantum readiness, cryptographic risk management, and future threat preparedness.
- Experience developing executive-level reporting, dashboards, and presentations for senior leadership, Board, and Audit Committees.
- Excellent stakeholder management, communication, and presentation skills.
- Strong analytical and problem-solving abilities with the capability to independently manage multiple initiatives and deliver results in a fast-paced environment.
Preferred Qualifications
- Professional certifications such as CISSP, CISM, CRISC, CGEIT, or equivalent are considered an asset.
- Experience within a regulated industry or enterprise environment.
- Knowledge of cyber risk assessment methodologies and security control maturity models.
Key Competencies
- Cybersecurity Governance
- Cyber Risk Management
- Third-Party Risk Management
- Regulatory Compliance & Audit Support
- Executive Reporting & Communication
- Vendor Management
- Strategic Planning & Program Management
- Risk Assessment & Advisory
- Stakeholder Relationship Management
- Project Coordination & Delivery