Information Security Policy Manager
This is Hybrid role (4 days in office /1 day remote)
About your Team:
The Information Security Policy Manager leads the continual development and improvement of information security policy at IBKR and ensures it is effectively integrated across IBKR's global Information Security Governance, Risk, and Compliance (GRC) function. This includes aligning policy to regulatory requirements and industry best practices, in consideration of IBKR's control environment and risk appetite.
What will be your responsibilities within IBKR:
Enhance and extend IBKR’s information security policy library in alignment with regulatory requirements, business risk appetite, industry-accepted risk frameworks, in consideration of IBKR’s control environment.
Evolve IBKR’s capability to demonstrate compliance with applicable cybersecurity frameworks, regulatory requirements, and laws through policy mapping and gap analysis.
Drive and measure policy compliance through the development of, and mapping to, appropriate controls and testing procedures, in partnership with the Information Security Controls Manager.
Evaluate security controls, identify opportunities for improvement, and communicate constructive recommendations.
Support security-related external assessments, audits, and regulatory examinations by providing evidence of compliance.
Other responsibilities related to the GRC function, per demonstrated aptitude.
What required skill’s you need:
7+ years of experience in information / cyber security experience, including 3+ years developing and managing information security policies in a regulated industry (preferably financial services) and 3+ years hands-on, technical cybersecurity roles.
Fluent understanding of regulatory requirements affecting cybersecurity, including DORA, SEC, FFIEC, and common regulations issued in Europe (EBA) and APAC (SFC, MAS) – and how multi-national financial services companies address them.
Working familiarity with common security frameworks, such as NIST CSF.
Proven ability to write clear, actionable policies addressing complex regulatory and technical requirements, grounded in industry accepted practices and risk management concepts, and based on existing controls and technology environments.
Experience as lead responder to regulatory examinations, audit requests, and client due diligence questionnaires related to policy and compliance a plus.
Experience working with GRC (Governance, Risk, and Compliance) tooling a plus.
Bachelor’s degree in Information Security, Computer Science, Information Technology or a related field, or equivalent experience
CISM certification a plus.
To be successful in this position, you will have the following:
Strong critical thinking, analytical, organizational, time management, and writing and editing skills – all with attention to detail.
Track record of building bridges with technology practitioners and translating complex technical concepts into simple, accessible language for business audiences.
A self-motivated, open, collaborative, client-centric, consensus-building problem-solving mentality.
Ability to navigate ambiguity through structured thinking and exercise good judgment when solving problems with incomplete information.
Company Benefits & Perks
Competitive salary, annual performance-based bonus, and stock grant awards
401(k) retirement plan with competitive company match
Excellent health and wellness benefits, including medical, dental, and vision benefits. 100% employer-paid medical premiums, with generous employer contributions to dental & vision plans as well.
Wellness screening and assessments, health coaches, and counseling services through an Employee Assistance Program (EAP)
Generous paid parental leave (up to 16 weeks paid parental leave for eligible employees)
Company-paid basic life insurance, accidental death & dismemberment (AD&D), and short- and long-term disability coverage
Flexible Spending Accounts (Healthcare, Dependent Care, and Commuter FSAs)
Quarterly fitness stipend to offset costs associated with traditional gym and fitness memberships or fees
Education reimbursement and professional development opportunities
Legal services, telehealth access, and voluntary insurance options
Backup child and adult care support through Care.com
Daily lunch allowance and fully stocked kitchen with healthy breakfast and snack options