Manager, Cybersecurity Risk Management [Remote]

• Must be able to work a hybrid schedule (3 days onsite) out of our Burbank office.* THE JOB The Manager Cyber Security Risk will focus efforts on managing and reporting on cyber risks globally across WBD. You will play a crucial role in assessing, managing, and driving mitigation of risks associated with our wider cybersecurity program. You will drive a comprehensive risk management program, while supporting peer cybersecurity teams in maturing and standardizing their programs. You will work on identifying, and mitigating security risks in line with the company's standards. You will also provide subject matter expertise and technical guidance to process owners. By partnering with various stakeholders, including Product Owners, Business Control Owners, Technology Operations, DTC, etc., you will contribute to the reporting of a comprehensive view of the security risk posture and its impact on the business. Your advanced knowledge of risk management principles and practices will enable you to drive innovative solutions and effectively manage a diverse team in a dynamic and evolving risk landscape. This position requires deep collaboration across cloud engineering, IT infrastructure, and application development, to effectively reduce the organization's risk exposure. You will work closely with GICS and business unit leaders to ensure strategic and tactical risk mitigation efforts align with enterprise goals. RISK OVERSIGHT • Develop and maintain a comprehensive cybersecurity risk management strategy aligned with business objectives. • Lead enterprise-wide risk assessments and remediation activities. • Collaborate with IT, legal, compliance, and business units to ensure risk mitigation strategies are embedded in operations. • Monitor emerging threats and risk posture and activities accordingly. • Present risk analysis, metrics, and mitigation plans to management and stakeholders. • Identify risk and mitigating controls for risk exceptions based on adherence to relevant company policies, standards, baselines, and industry standards (e.g., GDPR, PCI, SOX). • Mentor and develop junior risk analysts and cybersecurity professionals. • Ensure effective identification, quantification, communication, and management of technology risk, focusing on root cause analysis and resolution recommendations. • Develop and maintain robust relationships, become a trusted partner with technologists, assessments teams, and stakeholders to facilitate cross-functional collaboration and progress toward shared goals. • Proactively monitor and evaluate risk exceptions and risk register processes, identify gaps, and recommend enhancements to strengthen risk posture. • Assist InfoSec teams in developing and maturing their risk exceptions rejection and approval criteria. • Drive adoption of enterprise-wide risk assessment methodologies, frameworks, and tools. • Collaborate with key stakeholders to enhance risk governance and ensure compliance with internal and regulatory requirements. • Assist with the administration and maintenance of the Service Now GRC platform. • Display and utilize advanced understanding of relevant SDLC methodologies, practices and compliance policies/procedures to assess risk exceptions criteria. • Utilize prior experience in multiple IT disciplines and confirmed understanding of solution architecture, complex application systems design and platform integrations and various tech stacks during assessment of risk. STRATEGIC LEADERSHIP, BUSINESS PARTNERSHIP & ENABLEMENT • Translate risk insights into strategic decisions and enterprise-wide policies. • Communicate effectively with leadership and stakeholders. • Contribute to the design of cybersecurity strategies by advising on risk reduction priorities related to exception and risk register trends. • Develop metrics to track exception remediation rates, approval / review rates, aging, and SLA compliance. • Drive initiatives that reduce recurring exception requests through enterprise-wide solutions. • Engage with application, cloud, and infrastructure teams to promote remediation and risk ownership. • Foster collaboration across business units to ensure alignment between risk mitigation and delivery priorities. • Accountable for organizing and participating in and/or leading meetings with various stakeholders across the company, and across the globe. • Technical and experienced professionals who will ensure data and evidence meet remediation expectations and regulatory or policy requirements. • Responsible for tracking tasks and projects, assessment status, and are able to effectively communicate risks and overall status to your management in a timely manner. • Stay abreast of existing and upcoming projects to effectively plan your work. • Make updates to the centralized risk exceptions list, issues log, and other key team documents, ensuring accuracy, attention to detail, and overall status. • Assist in updating metrics and status updates on a regular basis for your Manager. • Ability to partner with other team members, contribute to building a positive team culture, learn internal processes, and contribute to building effective deliverables. ANALYTICS • Monitor the effectiveness of the risk exceptions process in accordance with agreed upon metrics and performance measures to drive continuous improvements. • Conduct root cause analysis on recurring issues to enhance process efficiency and reduce exception requests. • Collaborate with cross-functional teams to gather, interpret, and validate mitigating controls to ensure accuracy and relevance. THE ESSENTIALS • 8+ years of experience in security risk, with at least 3 years in a risk management role, or similar function. • Strong knowledge of cybersecurity frameworks, company policies, and regulatory requirements. • Certifications such as CISSP, CISM, CRISC, or CISA highly preferred. • Proven ability to communicate complex risk concepts to non-technical stakeholders. • Strong expertise across cloud (AWS, Azure, GCP), on-premises, and application environments. • Experience with tools such as Service Now, GRC tools, PowerBi, and cloud technologies. • Strong knowledge of risk frameworks (e.g., NIST, ISO, PCI, SOX, etc.). • Bachelor's degree in computer science, Engineering, IT, or related field. • Strong analytical, quantitative, and qualitative skills with a detail-oriented, critical thinking mindset. • Strategic thinker with deep capability in applying risk principles to business environments. • Creative problem solver with sound business judgment and a proactive approach to risk mitigation. • Passion for accuracy and translating insights into compelling, high-quality narratives. • Exceptional communication skills-verbal, written, and visual-with fluency in English. • Proven ability to translate complex technical concepts into plain language for decision-makers. • Positive influence with strong stakeholder engagement and relationship-building abilities • Skilled in preparing polished deliverables that support informed decision-making. • Team player who builds trust across technical and non-technical teams. • Has 4+ years of experience managing and training staff. • Demonstrated ability to work independently, adapt quickly, and drive tasks forward with limited direction. • Strong project management and delegation skills across diverse, cross-functional initiatives • Experience driving change to completion in dynamic, fast paced environments. • Proven ability to identify and as [more...] Note: Posting is subject to change so please refer to career site for latest availability (SBJ-G337). Apply tot his job

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...