Sr. Cybersecurity GRC Manager

Hyundai Capital America

Irvine, California

JOB DETAILS
SKILLS
Analysis Skills, Business Operations, CISM - Certified Information Security Manager, CISSP - Certified Information Systems Security Professional, Career Development, Computer Security, Dental Insurance, Disability Insurance, Finance, Financial Regulations, Financial Services, ISO (International Organization for Standardization), ITIL (IT Infrastructure Library), Information/Data Security (InfoSec), Insurance, Internet Security, Leaching, Life Insurance, Maintain Compliance, Metrics, PCI-DSS, Performance Metrics, Product/Service Launch, Regulations, Regulatory Compliance, Regulatory Requirements, Risk, Risk Analysis, Risk Management, Risk Management Framework (RMF), Security Analysis, Security Compliance, Security Monitoring, Software Development Lifecycle (SDLC), Team Building, Threat Modeling, Threat and risk analysis (TRA), Vendor/Supplier Evaluation, Vision Plan
LOCATION
Irvine, California
POSTED
3 days ago
Description

Who We Are

Through our service brands Hyundai Motor Finance, Genesis Finance, and Kia Finance, Hyundai Capital America offers a wide range of financial products tailored to meet the needs of Hyundai, Genesis, and Kia customers and dealerships. We provide vehicle financing, leasing, subscription, and insurance solutions to over 3 million consumers and businesses. Embodying our commitment to grow, innovate, and diversify, we strive to reimagine the customer and dealer experience and launch innovative new products that broaden our market reach. We believe that success comes from within and are proud to support our team members through skill development and career advancement. Hyundai Capital America is an Equal Opportunity Employer committed to creating a diverse and inclusive culture for our workforce. We are a values-driven company dedicated to supporting both internal and external communities through volunteering, philanthropy, and the empowerment of our Employee Resource Groups. Together, we strive to be the leader in financing freedom of movement.

We Take Care of Our People

Along with competitive pay, as an employee of HCA, you are eligible for:

• Medical, dental, and vision plans with no-cost and low-cost options

• Annual employer HSA contribution

• 401(k) matching and immediate vesting

• Vehicle purchase and lease discounts, plus monthly vehicle allowances by job level:

o Associate / Sr. Associate: $350

o Manager / Sr. Manager: $600

o Director: $800

o Executive Director: $900

o VP or Above: $1,000

• 100% employer-paid life and disability insurance

• No-cost health and wellbeing programs, including a gym benefit

• Six weeks of paid parental leave

• Paid Volunteer Time Off, plus a company donation to a charity of your choice

What to Expect

The Sr. Cybersecurity Risk Manager requires a deep understanding of security risk management and the evolving threat landscape, ensuring the internal security risk strategy is resilient and forward-thinking to oversee the security risk posture internally, proactively identifying, assessing, and mitigating risks that could impact business operations, financial stability, and regulatory compliance. In addition, this role may assist the development of vendors/partners security risk evaluation to ensure alignment with our cybersecurity policies, regulatory requirements, and risk mitigation strategies.

What You Will Do

1. Develop and executive internal security risk assessments, threat modeling, and impact analyses to identify vulnerabilities across internal leveraged solutions, systems, applications, and processes including guiding and supporting team to ensure effective collaboration for assigned projects and work efforts.

2. Develop, execute and enhance a cybersecurity risk management framework aligned with business objectives and regulatory requirements.

3. Establish and maintain security risk metrics by t racking Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs), along with reporting mechanisms to communicate cybersecurity effectiveness and provide actionable insights to executives and stakeholders.

4. Manage governance around internal cybersecurity risks, ensuring compliance with internal security policies and regulatory requirements.

Qualifications

What You Will Bring

• Minimum 8 years progressive experience in cybersecurity governance, risk management, or compliance with a deep understanding of security risk management, system development life cycle (SDLC), and the evolving threat landscape ensuring the internal security risk strategy is resilient and forward-thinking.

• Financial services industry preferred.

• Bachelor's degree in finance, business or related discipline.

• Certifications such as CISSP, CISM, CRISC, CGEIT, and ITIL are highly desirable.

• Strong knowledge of Information Security risk management frameworks, Governance, Risk, and Compliance process, IT general controls (e.g. asset classification, risk assessments, vulnerability and threat analysis, risk treatment, audit controls and remediation, vendor risk management, and IT risk management & reporting)

• Strong knowledge of Information Security & Risk Frameworks including ISO 27001/2, ISO 310002018, ISO 270052022; NIST Special Publications and Methodologies (e.g. SP800-12, 30, 37, 39, 53, 150, 161)

• Working knowledge of California Consumer Privacy Act (CCPA), Gramm-Leach-Bliley Act (GLBA), NYDFS Cybersecurity Regulation, PCI-DSS, FFIEC,

About the Company

H

Hyundai Capital America