Jobs / United States / US Bank National Association
Information Security Risk Oversight Professional
US Bank National Association · 🇺🇸 3 Locations
Sponsorship verdict
Sponsorship possible
One solid signal, not two — worth applying, and worth asking about sponsorship early.
- Employer is on a government sponsor recordUSCIS Data Hub records 294 H-1B approvals for this employer in FY2023. Source: USCIS H-1B Employer Data Hub (US Citizenship and Immigration Services).
- The posting doesn’t mention sponsorshipSilence isn’t a refusal — ask the recruiter before investing much time.
- No salary bar for this routeH-1B has no fixed salary bar: the employer must pay at least the prevailing wage for the role and area. Cap-subject employers enter a lottery weighted by wage level. Source: https://www.federalregister.gov/documents/2025/12/29/2025-23853/weighted-selection-process-for-registrants-and-petitioners-seeking-to-file-cap-subject-h-1b, rules effective 2026-02-27.
- Confirmed live todayWhen a source last listed this job as open.
US H-1B: cap-subject employers enter a lottery weighted by wage level — Level I gets 1 entry, Level IV gets 4 (DHS projected selection odds ≈15% at Level I to ≈61% at Level IV). Universities and non-profit research employers are cap-exempt. The $100,000 fee for new petitions from abroad is currently blocked by a court order (appeal pending).
A verdict summarises public evidence; it is not legal advice and never a guarantee — the employer and the immigration authority decide. Sign in to factor in where you can already work.
Or apply yourself on the official page →
Sponsor Radar — US Bank National Association
USCIS Data Hub records 294 H-1B approvals for this employer in FY2023. Source: USCIS H-1B Employer Data Hub (US Citizenship and Immigration Services).
Past sponsorship or register membership never guarantees sponsorship for this vacancy or for you. Full Sponsor Radar for US Bank National Association →
About the role
At U.S. Bank, we’re on a journey to do our best. Helping the customers and businesses we serve to make better and smarter financial decisions and enabling the communities we support to grow and succeed. We believe it takes all of us to bring our shared ambition to life, and each person is unique in their potential. A career with U.S. Bank gives you a wide, ever-growing range of opportunities to discover what makes you thrive at every stage of your career. Try new things, learn new skills and discover what you excel at—all from Day One. Job Description The Information Security Risk Oversight Professional is a senior individual contributor within the Second Line of Defense (2LoD), reporting to the Director of Cybersecurity Risk Oversight. The role provides independent risk oversight and credible challenge across the enterprise Information Security program, including governance, risk assessments, controls, security architecture and practices, metrics, and issue management. The ideal candidate combines strong technical knowledge with critical thinking, professional skepticism, and sound judgment. This person must be able to assess information independently, distinguish fact from opinion, identify weaknesses in existing approaches, and develop a clear point of view supported by evidence. Success requires more than restating first line conclusions. The role is expected to test assumptions, evaluate whether practices are effective and efficient, and recommend stronger approaches when current methods do not reflect sound risk management or industry best practice. The successful candidate will have more than eight years of relevant experience in information security, technology risk, audit, engineering, architecture, or risk management. They must be comfortable moving across security domains, learning unfamiliar topics quickly, and translating technical concerns into clear, defensible risk insights for senior leaders. Role Expectations · Operate with significant autonomy and manage an oversight portfolio based on material risk, regulatory significance, and business impact. · Develop independent conclusions rather than relying solely on first line narratives, existing processes, or consensus views. · Use technical knowledge, evidence, and professional judgment to determine whether risks are appropriately identified, assessed, managed, monitored, and reported. · Constructively challenge practices that are inefficient, inconsistently applied, insufficiently supported, or misaligned with regulatory expectations and industry best practices. · Remain objective and solutions-oriented while engaging confidently with technical teams, risk partners, and senior leadership. Key Responsibilities · Provide independent oversight and credible challenge across multiple Information Security pillars, including governance, risk assessments, security architecture, controls, metrics, and issue management. · Analyze technical designs, security processes, control environments, risk assessments, and support evidence to identify gaps, weaknesses, systemic concerns, and emerging risks. · Formulate and clearly articulate independent risk opinions supported by technical analysis, relevant evidence, regulatory expectations, and professional judgment. · Challenge assumptions, inherited processes, and accepted ways of working when they do not produce effective, efficient, or sustainable risk outcomes. · Evaluate whether first line activities align with applicable laws, regulations, regulatory guidance, industry standards and frameworks, and internal risk appetite and policy requirements. · Assess the quality and completeness of first line risk identification, risk acce