

AVP IT Risk (443322) NUMÉRO DE POSTE: 443457
DETAILS
Location: 100% Remote | DFW-local candidates strongly preferred, but not required, for the occasional onsite quarterly meetings, required events, etc.
Position Type: 6M C2H or Direct-Hire (based on candidate preference)
Hourly / Salary: $120K-$160K 20% bonus structure
JOB SUMMARY
Vaco Technology is currently seeking an Assistant Vice President of IT Risk for a 6M C2H or Direct-Hire (based on candidate preference) that is 100% remote-based. The AVP IT Risk will coordinate and deliver the IT Risk Program, including information security, business continuity / disaster recovery, and enterprise IT program management. The AVP IT Risk will identify, evaluate, and report on information technology risks, ensuring compliance and regulatory standards are met and aligns / supports the overall risk posture.
- Expertise in Information Security – Proven History of Developing / Implementing / Managing / Auditing Cybersecurity Strategies / Policies / Procedures
- Assist IT Risk Team in Continuously Enhancing the Global Infrastructure Security Program – Delivering Security Projects Addressing Identified Risks / Business Security Requirements
- Manage / Deliver the Business Continuity / Disaster Recovery Program – Enhancing Existing Practices / Continuity Testing
- Manage / Coordinate Enterprise Infrastructure Technology Programs – Aligning with Business Requirements
- Perform Ongoing Enhancement of Global Information Security Policies / Procedures – Ensuring Operating Efficiency / Regulatory/Legal Compliance
- Support Global Team in Incident Response – Coordinating Operational Components of Incident Management
- Provide Guidance to Senior Management on Remediation – Information Security Gaps / Reporting Remediation Activities, etc.
- Collaborate / Perform IT Risk Assessments – High-Level Monitoring of Security Vulnerabilities / Cybersecurity Threats / Audits / Tests, etc.
- Define Metrics / Reporting Strategies – Effectively Communicating Successes / Progress of Security Program
- Support the Provision of Regular / Appropriate Cybersecurity Communications / Awareness / Training
- Deliver Information Security Vendor / Key 3rd Party Risk Assessments
- Prepare Regular Information Technology Risk Management Updates – Relating to IT Risk Operations / Attend Security Governance/Operational Meetings
- Support the Global Data Governance Program Operational / Project Deliveries
- Complete Security Assessments / Assurance Updates – Relating to Key 3rd Parties / Investors / Rating Agencies
- Exceptional Communication / Organizational Skills / Attention to Detail – Ability to Interface with All Levels (including Execs / Stakeholders) / Ability to Successfully Communicate Security/Risk-Related Concepts to Technical/Non-Technical Audiences
About the Project: The current AVP IT Risk is retiring at the end of May 2025 and they are looking to bring on a new AVP IT Risk, as soon as possible, to participate in deep and rich knowledge transfer. The current AVP IT Risk has been with the company for many years and the role has grown over time. The AVP IT Risk has no direct reports. The AVP IT Risk will be heavily involved in Information Security, Business Continuity, and Disaster Recovery, where previous experience implementing and maintaining these programs will be critical. Currently, they heavily utilize NTT Americas as their MSP / MSSP Partner as well as additional 3rd Party Vendors, for monitoring threats / incidents, vulnerability, penetration testing, and risk assessments. The AVP IT Risk will not have access to the SIM so there will be no direct hands-on analysis / activities but will be heavily involved in the coordination of remediation, guiding and leading the SOC, and coordinating with internal business users / IT teams when security events are occurring. The AVP IT Risk will coordinate vulnerability, pen testing, and risk assessments with 3rd Party Vendors, assessing results, and coordinating with the MSP and/or internal tech teams to ensure tickets are being entered and remediated in a timely manner. The current AVP IT Risk also came with an Enterprise Architecture background and stepped in when new tools were being introduced and/or optimizing existing tools, including enhancing meetings, coordination, and overall management. The ideal AVP IT Risk will have a technology-driven mindset and be willing to dig into technologies, that may not be initially familiar, to learn it, understand it, and then identify ways to best optimize it. As an example, the current AVP IT Risk recently took over their enterprise Teams initiative. The AVP IT Risk had no prior Teams experience but embedded herself within the technology to provide recommendations on how the company could more effectively and efficiently utilize the product to get the absolute most out of it. While this type of responsibility typically falls outside of the normal scope of an AVP IT Risk, they are looking for someone who is tech savvy, driven, and willing to take on side projects as they arise.
OnPrem-to-Azure Cloud Migration: Currently, they are in the middle of a large-scale effort to migrate OnPrem to the Cloud. They have successfully migrated a data center into Azure and they are currently working towards getting their Europe and North America operations migrated, where they have 30-40 North American servers successfully migrated to the cloud. The overall goal is to have as much as possible migrated to the cloud by the end of 2025, understanding that some areas may not be able to be fully migrated and other areas that may extend beyond the end of 2025 due to required testing, etc.
JOB REQUIREMENTS
- AVP IT Risk – Develop / Implement / Manage / Audit Cybersecurity Strategies / Policies / Procedures | Managing Outsourced Environments
- Disaster Recovery / Business Continuity Frameworks | ISO-22301 – Continuity Planning / Risk Assessment and BIA (Business Impact Analysis) / Resource Management / Emergency Response and Recovery / Testing and Exercising / Monitoring and Continuous Improvement
- Vendor Management – Security-Related Vendor / MSP / 3rd Party Management
- Monitoring Threats / Incidents – Heavy Coordination with MSP and/or Internal Tech Teams for Remediation / Guiding and Leading SOC / Coordination with Internal Business Users/IT Teams During Security Events
- Vulnerability / Pen Testing – Coordination with 3rd Party Vendor / Reviewing and Assessing the Results / Coordination with MSP and/or Internal Tech Teams to Ensure Tickets are Entered / Remediated Timely
- Risk Assessment – Coordinate / Manage Risk Assessments with 3rd Party Vendors
- MS Suite of Tools – Teams (strongly preferred)
Vaco by Highspring promeut un milieu de travail diversifié et encourage fortement les femmes, les personnes de couleur, les membres des communautés LGBTQ+, les personnes handicapées, les membres de minorités ethniques, les résidents nés à l’étranger et les anciens combattants à postuler.
Avis : Égalité des chances en matière d’emploi
Vaco by Highspring garantie l’égalité des chances et ne discrimine pas les employé.e.s ou candidat.e.s en fonction de la race (y compris les traits historiquement associés à une race tels qu’une coiffure ou la texture des cheveux), couleur de la peau, sexe (y compris la grossesse ou des conditions connexes), religion ou croyances, origine nationale, citoyenneté, âge, situation de handicap, statut d’ancien.ne combattant.e, appartenance à un syndicat, origine ethnique, genre, identité de genre, expression de genre, orientation sexuelle, état matrimonial, affiliation politique, ou toute autre caractéristique protégée comme requis par la loi.
Vaco by Highspring et ses sociétés mères, sociétés affiliées et filiales (Vaco by Highspring) s’engagent à inclure pleinement toutes les personnes qualifiées. Dans le cadre de cet engagement, Vaco by Highspring veillera à ce que les personnes handicapées bénéficient d’aménagements raisonnables. Si un aménagement raisonnable est nécessaire pour participer au processus de candidature ou d’entrevue, pour vaquer à des fonctions professionnelles essentielles et/ou pour bénéficier d’autres avantages et privilèges liés à l’emploi, veuillez contacter HR@vaco.com.
Vaco by Highspring souhaite également que tous les candidats connaissent leurs droits, à savoir que la discrimination sur le lieu de travail est illégale.
En vous soumettant à ce poste, vous acceptez de donner à Vaco by Highspring le droit exclusif de présenter votre candidat pour l’opportunité d’emploi précédente. Vous convenez en outre que vous avez représenté des informations vous concernant avec exactitude et que vous n’avez pas déformé vos qualifications de manière affirmative. Vous acceptez également de garder confidentielle, dans toute la mesure permise par la loi, toute information que vous apprenez de Vaco by Highspring sur le poste et vous limiterez la divulgation des informations sur le poste uniquement dans la mesure nécessaire pour exécuter toute obligation dans la poursuite de votre candidature. En échange, Vaco by Highspring accepte de faire des efforts raisonnables pour vous représenter par le biais de toute sollicitation, sélection d’emploi et dispersion de CV.
Avis de confidentialité
Vaco by Highspring, ses sociétés mères, ses filiales et les sociétés du même groupe (« nous », « nos » ou « Vaco by Highspring») respectent votre vie privée et s’engagent à présenter un avis transparent concernant leurs politiques.
- Les résidents de la Californie peuvent consulter l’avis relatif à la collecte de renseignements publié par le service des RH de Vaco by Highspring à l’intention des candidats et des employés de la Californie ici.
- Les résidents de la Virginie peuvent accéder à nos politiques propres à leur État ici.
- Les résidents de tous les autres États peuvent accéder à nos politiques ici.
- Les résidents canadiens peuvent consulter nos politiques en anglais ici et en français ici.
- Les résidents des pays où le RGPD s’applique peuvent accéder à nos politiques ici.
Avis sur la transparence salariale
La détermination de la rémunération pour ce poste (et d’autres) chez Vaco by Highspring dépend d’un large éventail de facteurs, notamment :
- les compétences, l’expérience et la formation de la personne;
- les exigences relatives au permis d’exercice et à l’agrément;
- l’emplacement du bureau et d’autres considérations géographiques;
- d’autres besoins professionnels et de l’entreprise.
Ainsi, comme l’exige la loi locale, Vaco by Highspring estime que l’échelle salariale ci-dessus représente une estimation raisonnable de la rémunération de base d’une personne embauchée à ce poste dans des régions qui requièrent la divulgation de l’échelle salariale. La personne peut également être admissible à des primes discrétionnaires.