Director, Security Risk Management
- Merrick Bank
- Woodbury (Long Island)
- 4w ago
- Full-Time
- On-site
Join our team - and take the next step in achieving a fulfilling career!
What We Do
At CardWorks, we aim to help people connect with possibility and opportunity using our financial servicing expertise. Building meaningful, long-term relationships with consumers, our employees, and our clients is what matters most.
Who We Are
CardWorks, Inc. is a diversified consumer finance service provider and parent company of CardWorks Servicing, LLC, Merrick Bank and Carson Smithfield, LLC.
CardWorks Servicing, LLC provides end-to end operational servicing functions for credit cards, secured cards, and installment loans. We service consumer and small business loans across the credit spectrum and offers backup servicing and due diligence services to capital providers and trustees.
Merrick Bank is an FDIC-insured Utah Industrial Loan Bank. Merrick operates three main business lines: credit cards, recreational lending, and merchant services.
Carson Smithfield, LLC provides a variety of post-charge-off debt recovery services, including digital self-service, IVR, live agent, and external agency management.
Position Summary:
The Information Security Risk Management Director is responsible for leading the design, implementation, and oversight of the organization’s information security risk management and vendor security assessment programs. This is a hands-on leadership role that develops and ensures that cyber risk identification, assessment, mitigation, and reporting activities are consistently executed and centrally managed within the organization’s risk management framework and tools.
The Director oversees and performs information security risk assessments across internal systems, business processes, third-party vendors, and enterprise projects to ensure risks are effectively identified, rated, and managed in alignment with Enterprise Risk Management practices and regulatory frameworks such as the Cyber Risk Institute (CRI) Profile, NIST Cybersecurity Framework (CSF), and PCI DSS.
By integrating security risk management practices with business and technology initiatives, the Director drives informed decision-making, strengthens the organization’s security posture, enhances compliance with policies and standards, and promotes a culture of proactive security risk management across the enterprise.
Essential Functions:
Leadership and Program Oversight
Vendor and Third-Party Security Risk
Reporting and Continuous Improvement
Education and Experience
Proven ability to collaborate across diverse stakeholders, including IT, Enterprise Risk Management, Legal, Compliance, business units, and external partners, to embed security requirements, align with project objectives, and inform decision-making.
Summary of Qualifications:
Recognized as a trusted advisor and credible authority, capable of balancing strategic oversight with hands-on execution in a dynamic and evolving environment.
Ideally, the qualified candidate will work at the following location(s): Woodbury, NY; South Jordan, UT; Horsham, PA; Pittsburgh, PA; Orlando, FL. A hybrid work model or fully remote model can be considered based on hiring manager decision and priorities of the role.
The salary range for this position, if located in NY Metro/NY State is $151,165 to $167,961. However, please note that the salary range will vary for other geographic areas.
#INDHP
Our Employee Value Proposition
We offer a total rewards package comprised of a competitive base rate of pay, variable pay incentive programs based on the role, and a comprehensive benefit suite. Offered rates of pay are determined based on job-related knowledge, relevant experience, skills, certifications, and geographic location.
We are an equal opportunity employer, and we evaluate qualified applicants without regard to race, color, religion, sex, national origin, disability, veteran status or any other legally protected characteristic. We will conduct a thorough background check for all hires in compliance with applicable laws.