I
Not Specified Permanent

Evanston, Illinois · USA job

Information Security Policy Manager

Interactive Brokers

Evanston, Illinois

Job description

Overview

In this role you will own and evolve IBKR's information security policy library, ensuring alignment with regulatory demands, risk appetite, and the control environment. You will drive policy development, review, and maintenance across frameworks and laws, and support audits and regulatory examinations with clear evidence of compliance. You will partner with controls and testing functions to ensure policies are actionable and enforceable. This is a collaborative, cross-functional position that shapes how IBKR translates risk management into policy and practice at scale.

Compensation / Benefits
  • Competitive salary and bonus
  • Stock grant awards
  • 401(k) with company match
  • 100% employer-paid medical premiums
  • Generous parental leave
  • Education reimbursement
Responsibilities
  • Maintain and extend the information security policy library to align with regulations, risk appetite, and IBKR's controls.
  • Coordinate policy development, reviews, and updates with defined maintenance cycles.
  • Map policies to risk and regulatory frameworks and identify gaps against laws like DORA, FFIEC, and NIST CSF.
  • Support external assessments, audits, and regulatory examinations with evidence of compliance.
  • Collaborate with the Information Security Controls Manager to ensure policies are supported by controls and testing procedures.
  • Evaluate security controls, identify improvement opportunities, and communicate recommendations.
  • Assist with other duties as assigned
Key requirements
  • 7+ years in information/cyber security, including 3+ years shaping information security policies in regulated environments (preferably financial services) and 3+ years hands-on technical cybersecurity roles.
  • Strong understanding of regulatory requirements affecting cybersecurity (DORA, SEC, FFIEC, EBA, MAS/SFC).
  • Familiar with NIST CSF and ISO 27001/27002.
  • Experience as policy or technical standards owner and leading responses to regulatory examinations and audit requests.
  • Proven ability to write clear, actionable policies grounded in risk management and existing controls.
  • Experience with GRC tooling is a plus
  • Bachelor's degree in a related field, or equivalent experience
  • CISM certification a plus
  • strong writing and editing skills
  • ability to translate complex technical concepts to business audiences
  • cross-functional collaboration
  • information security policies and standards development
  • regulatory and risk framework mapping
  • control testing and evidence collection

Explore related USA jobs

Similar jobs you may like

Related roles with a similar title and location.

Same category Similar role Same location Same country

Information Security Policy Manager

Interactive Brokers

Chicago, Illinois, United States · 60290

Same category Similar role Same location Same country

Information Security Policy Manager

Interactive Brokers

Oak Park, Illinois, United States · 60301

Same category Same postal code Same area Same location Same country

Financial Services International Tax Consulting Manager

PwC

Evanston, Illinois, United States · 60201

Same category Same location Same country

Security Operations Analyst

MASTERY SYSTEMS

Libertyville, Illinois, United States · 60048

Same category Same location Same country

Security Operations Analyst

MASTERY SYSTEMS

Lake Forest, Illinois, United States · 60045

Same category Same location Same country

Financial Services International Tax Consulting Manager

PwC

Chicago, Illinois, United States · 60290

Same category Same location Same country

Financial Services International Tax Consulting Manager

PwC

Oak Park, Illinois, United States · 60301

Same category Same location Same country

Techno-Functional PLM Consulting Manager - Chemicals/Advanced Materials

Deloitte

Oak Park, Illinois, United States · 60301

Need help finding a job?

Chat with our AI assistant.