Jobs · Connecticut

Associate Director of Information Security

Knights of Columbus · New Haven, CT · 1 wk ago
Hybrid$112k–$191k/yrFull-time

The Knights of Columbus is a tax-exempt Catholic fraternal benefit society that provides financial security to members and their families through life insurance, long-term care insurance, disability income insurance, investment, and annuity products. Charity is at the core of our mission: our profits are donated to help those in need and to support our faith—$1.73B over the past ten years. While many employees are not Catholic, we follow the Church’s teachings in our investment strategies and employee benefits. As part of our religious mission, we support the pro-life cause, oppose assisted suicide and euthanasia, evangelize for the Catholic faith, and aid Christians facing religious persecution in the Middle East. We collaborate to support our two million members as they volunteer to help others in parishes and communities worldwide.

About the role

The Associate Director of Governance, Risk, and Compliance (GRC) is a resourceful and experienced information security leader responsible for managing and continuously improving the organization’s information security GRC program. This position provides strategic direction and operational oversight for the organization’s information security governance framework, including the development and maintenance of security policies, standards, and procedures; coordination of security audits and assessments; management of information security risks and exceptions; oversight of third-party security risk; and delivery of meaningful program reporting to leadership and governance committees. The Associate Director ensures alignment with applicable regulatory requirements, contractual obligations, industry standards, and organizational risk objectives. This role reports to the Deputy CISO and partners with Enterprise Risk Management, Internal Audit, Legal, Privacy, Compliance, Information Technology, and other business leaders to promote effective governance, strengthen risk management, and support continuous improvement of the information security program.

Responsibilities

  • Lead, develop, mentor, and retain a high-performing Information Security GRC team. Establish team objectives, performance measures, responsibilities, and development plans.
  • Develop, maintain, and continuously improve the organization’s information security governance, risk, and compliance strategy, operating model, and multi-year roadmap.
  • Stay current with trends and changes within the GRC community to ensure the organization adopts the latest relevant methods and practices.
  • Develop, maintain, and manage information security policies and standards. Partner with Information Security, technology, and other functional areas to ensure security standards are practical, measurable, and aligned with organizational requirements.
  • Maintain the information security risk register and exception process to ensure security risks are appropriately documented, assigned, prioritized, tracked, and reported.
  • Partner with Enterprise Risk Management to align information security risk methodologies, reporting, and governance with the broader enterprise risk management framework.
  • Develop and maintain an information security control framework aligned with applicable regulatory requirements, contractual obligations, industry standards, and organizational risk priorities.
  • Oversee information security compliance activities related to applicable laws, regulations, standards, frameworks, and customer requirements, including NY-DFS, COBIT, and various NIST frameworks.
  • Coordinate and manage information security audits, assessments, and examinations. Serve as the primary Information Security liaison for Internal Audit, External Audit, and other regulatory examiners.
  • Establish key indicators, reports, dashboards, control metrics, and security maturity measures to assess the effectiveness of the information security program.
  • Develop, maintain, and manage information security third-party risk activities.
  • Establish governance processes to evaluate security risks associated with new technologies, major business initiatives, cloud services, significant system changes, and strategic projects.
  • Partner with Privacy, Legal, and Compliance to address overlapping security, privacy, regulatory, and contractual requirements.
  • Maintain awareness of changes to cybersecurity laws, regulations, standards, industry expectations, and emerging risk trends, and assess their potential impact on the organization.

Requirements

  • Extensive knowledge of Governance, Risk, and Compliance practices.
  • Ability to process and understand complex information relevant to cybersecurity initiatives.
  • Ability to create detailed documentation and workflow diagrams.
  • Ability to multi-task between projects.
  • Exceptional written, oral, and interpersonal communication skills.
  • Understanding of the NIST CSF framework and other associated cybersecurity standards.
  • Ability to drive team outcomes through tight deadlines and prioritization of tasks.
  • Extensive knowledge of legal and regulatory compliance standards and requirements such as NYDFS, GDPR, CCRA, and CCPA.
  • Five years of relevant experience within the Governance, Risk, and Compliance field.
  • Proven working experience performing the functions listed under the core responsibilities section.

Qualifications

  • Preferred: CISSP, CISM, CRISC, CISA, or other security management certifications.
  • Preferred: Bachelor’s degree in Information Security, Cyber Security, Computer Science, or another related field.
  • Insurance and financial services industry experience is a plus.

Pay

The wage range for this role is $112,000 - $190,500, taking into account factors such as skill sets, experience, training, licensure, certifications, and business needs. The range applies if the work is performed in Connecticut; adjustments may be made for other locations. It is not typical for an individual to be hired at or near the top of the range, and compensation decisions depend on the facts and circumstances of each case.

Authorization to work in the United States is required. This position is not eligible for visa sponsorship.

Benefits

  • Time Away: 13 paid holidays per year in addition to vacation and paid sick leave, and flexible workweek schedules.
  • Professional Development: Certifications, designation, and tuition reimbursement.
  • Retirement Benefits: 401(k) retirement savings plan with matching company contributions, and cash balance retirement plans fully funded by the company.
  • Health and Wellness:
    • Short-term disability and term life insurance fully paid by the company.
    • Up to 12 weeks of childbirth leave under STD policy.
    • One week of fully paid parental leave for all new parents, including adoptive and foster parents.
    • A variety of health insurance options, including premium-level family coverage and a pre-tax Health Savings Account with employer contributions. (Note: The Order's health plans do not cover abortion, sterilization, or contraception.)
    • Long-term disability insurance, dental insurance, vision insurance, health club membership reimbursement, and an Employee Assistance Program.

Physical Demands

Must be able to remain in a stationary position for a majority of the workday.

Similar jobs

Director of Information Security

IDEA Public SchoolsTexas, United States· 1 mo ago
RemoteInformation Technology$108k–$129k/yrapply on careers.ideapublicschools.org