Freddie Mac - McLean, VA
posted 6 months ago
At Freddie Mac, you will do important work to build a better housing finance system and you'll be part of a team helping to make homeownership and rental housing more accessible and affordable across the nation. This position offers an exciting career opportunity that allows you to engage in rewarding work with the newest technologies while growing your cybersecurity and risk management skillsets. The role can be performed remotely within the U.S., provided you are within a 2-hour time zone differential from EST. Travel is expected approximately once per quarter to HQ in McLean, VA, if working remotely. As part of Freddie Mac's Enterprise Risk Management (ERM), the Information Risk Management Team provides second-line oversight of the company's Cybersecurity and Identity Access Management (IAM) programs. We are looking for a team member to support the development, validation, and monitoring of cybersecurity capabilities. As a subject matter expert in the Cybersecurity risk domain, you will provide oversight and challenge functions for the Information Security programs of the IT division and other lines of business. This includes reviewing Information Security operations, solutions, and architecture to identify risks, evaluate the effectiveness and completeness of cybersecurity capabilities, and report findings for enhancement and opportunities. You will enhance and mature Risk Management practices by supporting the development of enterprise-wide cybersecurity policies and standards. Additionally, you will provide oversight and advisory services to first-line partners regarding the application of standard requirements across a wide variety of technologies to manage risk. Your role will also involve supporting the development and execution of controls to monitor cybersecurity compliance and drive organizational change, as well as developing effective and measurable metrics (KRI, KPI, and KCI) to analyze data and proactively identify trends or new/emerging risks. You will execute risk analytics and reporting, provide advisory consultation to lines of business, and make course of action recommendations to manage risk. In terms of oversight, you will effectively challenge our first line of defense technology teams while collaborating with the third line (Internal Audit) and internal second-line partners. You will collaborate with key risk areas, business partners, and IT counterparts to design action plans to address Cybersecurity and IAM risk. Autonomously leading program execution with documented project plans, expectations, and schedules will be part of your responsibilities, along with providing status reports, escalation, and impediment resolution when needed. You will also support the Director in leading and managing the team, mentoring and guiding team members.