Find Jobs
Find Jobs Near You – Available Work in Your Location
Skip to job details
BI
BankUnited, Inc.
Technology Risk, Cyber Governance & Third-Party Risk Manager
Career Insights for Cyber Security Manager / Administrator
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Florida data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Cyber Security Manager or Administrator monitors, controls, and maintains systems that protect the security of large databases, including databases with customer information and patient files. Manages and administers the examination of client computer systems, identification of weak points in security, development and implementation of new systems, and monitoring and response to security issues.
$119,608 / year median in Florida
+12% projected growth
Job Description
Job Description Help for Job Description. Opens a new window.
JOB SUMMARY
This position is responsible for providing independent second-line oversight of technology, cybersecurity, third-party, cloud, and emerging technology risks across the organization. The role serves as a trusted advisor and challenge function to Information Technology, Information Security, Enterprise Architecture, Procurement, Legal, Compliance, Enterprise Risk Management, and business stakeholders. The incumbent leads cybersecurity third-party risk management activities, performs independent risk assessments, evaluates technology control environments, reviews technology and security architectures, and provides governance oversight of technology initiatives and vendor relationships. The position is responsible for identifying, assessing, monitoring, and communicating technology-related risks while ensuring alignment with the organization's risk appetite, regulatory requirements, and industry best practices. This role also supports regulatory examinations, internal and external audits, enterprise risk reporting, technology governance forums, and ongoing enhancement of technology risk and third-party risk management programs.ESSENTIAL DUTIES AND RESPONSIBILITIES
Technology Risk Governance & Second-Line Oversight:
Serves as an independent Second Line of Defense (2LOD) challenge function for technology, cybersecurity, cloud, data, AI, and third-party risks. Provides objective review and challenge of technology initiatives, cybersecurity programs, system implementations, and vendor onboarding activities. Assesses whether proposed controls, architectures, and risk mitigation strategies are appropriately designed and commensurate with organizational risk. Evaluates risk acceptance requests, compensating controls, documented exceptions, and remediation plans. Ensures technology risks remain within approved risk appetite thresholds. Participates in governance committees, steering committees, risk forums, and working groups as a technology risk subject matter expert. Advises management regarding technology risk, cybersecurity risk, operational risk, and third-party risk implications.Cybersecurity Third-Party Risk Management:
Leads cybersecurity due diligence reviews for new and existing third-party relationships. Evaluates vendor security controls through reviews of SOC reports, ISO certifications, SIG questionnaires, audit reports, penetration tests, security policies, regulatory documentation, and other independent attestations. Assesses vendor risks associated with cloud hosting, managed services, software development, professional services, artificial intelligence, critical infrastructure, and data processing. Evaluates subcontractor and fourth-party dependencies and associated risks. Reviews third-party incidents, breaches, control failures, and operational disruptions for potential impacts to the organization. Develops cybersecurity due diligence opinions and risk recommendations for business owners and management. Presents vendor risk assessments and residual risk determinations to stakeholders and governance bodies. Supports ongoing monitoring activities for critical and high-risk third-party relationships.Contract & Third-Party Governance Review:
Reviews contractual requirements related to information security, cybersecurity, privacy, resilience, artificial intelligence, business continuity, regulatory compliance, and audit rights.Assesses contractual provisions related to:
Breach notification Security obligations Data retention and destruction Subprocessor management Right-to-audit provisions Regulatory cooperation AI model training restrictions Cloud hosting controls Data residency requirements Identifies contractual gaps and recommends risk mitigation strategies. Collaborates with Legal, Procurement, Compliance, and business stakeholders during contract negotiations.Technology Risk Assessments:
Performs risk assessments for applications, systems, technologies, cloud implementations, and technology projects. Assess cybersecurity, operational, regulatory, architectural, resilience, and data protection risks. Evaluates security architectures, cloud deployments, integrations, and emerging technologies. Reviews technology designs for alignment with security standards, regulatory guidance, and enterprise control requirements. Identifies control weaknesses, security gaps, and operational risks. Recommends practical risk mitigation strategies and compensating controls.Technology & Security Advisory Services:
Provides risk and cybersecurity consultation to technology teams, security teams, architects, project teams, and business stakeholders. Assists teams in understanding regulatory requirements and industry expectations. Supports development of secure and compliant technology solutions. Advises stakeholders on cybersecurity frameworks, cloud security, third-party risk, technology resilience, data protection, and emerging threats. Provides technical guidance during vendor selection, technology implementations, and operational changes.Architecture Review & Security Governance:
Participates in Security Review Boards, Architecture Review Boards, and technology governance forums. Reviews proposed technology architectures for risk, security, resilience, recoverability, and compliance considerations. Challenges incomplete documentation, undefined controls, security gaps, unsupported assumptions, and unresolved risks. Ensures technology initiatives maintain appropriate design documentation and evidence of control implementation prior to approval.Risk Program Development:
Designs, develops, and enhances technology risk and third-party risk management methodologies. Maintains and improves inherent risk assessment methodologies, questionn... Visit the Employer site for more detailsBenefits
- Dental Insurance