About the Role
Jane Street Group, LLC seeks a Senior Cybersecurity Governance, Risk & Compliance Specialist to lead strategic cybersecurity vendor risk management initiatives, enhancing the firm's vendor risk posture and regulatory compliance framework.
Responsibilities
- Architect and implement comprehensive cybersecurity vendor risk governance frameworks aligned with regulatory requirements and enterprise-wide vendor risk tolerance thresholds.
- Provide strategic leadership in vendor security risk analysis, mentor junior team members, and establish standardized methodologies for vendor due diligence, security assessments, and ongoing monitoring.
- Partner with procurement, legal, and business stakeholders to lead vendor assessments across the vendor lifecycle, designing risk mitigation solutions.
- Oversee vendor incident management and breach response protocols, establishing clear escalation procedures and coordinating with vendors during security events.
- Lead operational efficiency initiatives by implementing automated vendor compliance monitoring solutions and establishing key risk indicators and dashboards.
Requirements
- Three (3) or four (4) year Bachelor's degree in Finance, Engineering, Computer Science, or a related scientific or quantitative field or foreign equivalent.
- Three (3) years of progressively responsible experience as a cybersecurity GRC analyst, or similar occupation at a financial services or technology firm.
- Two (2) years of experience applying knowledge of vendor-related regulatory requirements (FCA, DORA, SEBI, SEC, and Finra) to the vendor assessment and onboarding process.
- One (1) year of experience managing vendor risk governance programs, including stakeholder management across technical and business teams.
- One (1) year of experience developing vendor risk frameworks and conducting risk assessments of third-party integrations.
- One (1) year of experience leading vendor security assessments and determining appropriate evaluation scope based on factors such as data sensitivity, system criticality, and operational dependencies.
- One (1) year of experience conducting vendor assessments for a trading environment built primarily in OCaml and Python.
- All technical requirements may be subject to employer conducted testing to assess minimum proficiency.
Skills
- Vendor risk management
- Regulatory compliance
- Cybersecurity governance
- Risk assessment
- Due diligence
- Security assessments
- Vendor lifecycle management
- Incident response
- Risk mitigation
- Stakeholder management
- OCaml
- Python
Location
- New York, NY
Work Type
- Part time telecommuting may be permitted
Experience Level
- Senior
Education Level
- 3 or 4 year Bachelor's degree
About the Company
- Jane Street Group, LLC
