FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates extensive expertise in Information Security governance, risk management, and technical analysis, with a strong ability to provide independent oversight and articulate risk opinions. Capable of synthesizing complex information and delivering clear, executive-level communication while maintaining independence and objectivity.
Highest-signal resume keywords
Information Security GovernanceRisk ManagementTechnical AnalysisVulnerability ManagementIncident Management
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Risk AssessmentsSecurity ArchitectureControl DesignData ProtectionIdentity and Access ManagementApplication SecurityAPI SecurityCloud SecuritySecurity MetricsRegulatory Compliance
Soft Skills
Critical ThinkingProblem SolvingProfessional SkepticismCommunication SkillsRelationship Building
Certifications & Qualifications
CISSPCISACRISCCISM
Industry Keywords
Second Line of DefenseInternal AuditSecurity EngineeringRegulatory GuidanceIndustry Standards
Tech Stack
Tools & technologiesCloudCyber Security
About the role
Key responsibilities & impact- Operate with significant autonomy and manage an oversight portfolio based on material risk, regulatory significance, and business impact
- Develop independent conclusions rather than relying solely on first line narratives, existing processes, or consensus views
- Provide independent oversight and credible challenge across Information Security governance, risk assessments, security architecture, controls, metrics, and issue management
- Analyze technical designs, security processes, control environments, risk assessments, and supporting evidence to identify gaps, weaknesses, systemic concerns, and emerging risks
- Formulate and articulate independent risk opinions supported by technical analysis, evidence, regulatory expectations, and professional judgment
- Challenge assumptions, inherited processes, and accepted ways of working
- Evaluate alignment with applicable laws, regulations, regulatory guidance, industry standards and frameworks, internal risk appetite, and policy requirements
- Assess first line risk identification, risk acceptance, control design, issue remediation, and management reporting
- Monitor key risk indicators, security metrics, assessment results, incidents, and issue trends
- Escalate material risks, control weaknesses, ineffective practices, or unsupported risk positions through governance and reporting channels
- Act as a technically credible risk advisor while maintaining Second Line of Defense independence and objectivity
- Engage stakeholders, ask probing questions, and ensure conclusions are evidence-based
- Provide practical recommendations without assuming ownership of first line decisions or execution
- Contribute to executive-level reporting by translating complex technical issues into concise statements of risk, impact, trend, and required action
- Stay current on cybersecurity threats, technology changes, regulatory expectations, and industry practices
Requirements
What you’ll need- Bachelor's degree, or equivalent work experience
- Typically, more than eight years of applicable experience in information security, technology risk, audit, engineering, architecture, or risk management
- Strong technical knowledge across multiple information security domains, such as vulnerability management, identity and access management, application and API security, cloud security, data protection, security architecture, incident management, and security governance
- Ability to independently analyze complex technical and risk information, identify what is missing, and reach a well-supported conclusion
- Critical-thinking and problem-solving skills
- Experience evaluating process and control design, risk alignment, efficiency, and industry best practice
- Professional skepticism and confidence to raise concerns and sustain evidence-supported risk positions
- Ability to synthesize information from technical teams, data, assessments, standards, and regulatory sources
- Experience operating in or with a Second Line of Defense, internal audit, regulatory, security engineering, or security architecture function
- Ability to work independently, prioritize competing demands, and deliver high-quality work with limited direction
- Strong written and verbal communication skills for explaining technical risk and recommended action in clear, executive-ready language
- Ability to build productive working relationships while maintaining independence, objectivity, and accountability
- Relevant certifications such as CISSP, CISA, CRISC, or CISM are preferred but not required
- Ability to work from a U.S. Bank location three (3) or more days per week
- Ability to comply with U.S. Bank policies and procedures, including the Code of Ethics and Business Conduct and workplace conduct and safety policies
Benefits
Comp & perks- Healthcare (medical, dental, vision)
- Basic term and optional term life insurance
- Short-term and long-term disability
- Pregnancy disability and parental leave
- 401(k) and employer-funded retirement plan
- Paid vacation (from two to five weeks depending on salary grade and tenure)
- Up to 11 paid holiday opportunities
- Adoption assistance
- Sick and Safe Leave accruals of one hour for every 30 worked, up to 80 hours per calendar year unless otherwise provided by law
- Incentive and recognition programs
- Equity stock purchase
- 401(k) contribution
- Pension
