Jobs · Michigan

AVP, Information Security

Amerisure Insurance · Farmington Hills, MI · 2 days ago
HybridFull-time

About the role

Amerisure is seeking an AVP, Information Security to lead the company’s cybersecurity strategy and operations. The role requires a 3-day hybrid approach onsite in Farmington Hills, Michigan.

Responsibilities

  • Lead and direct staff in area of responsibility with an emphasis on talent management and succession planning in accordance with the company’s strategic direction.
  • Serve as advisor to Chief Information Officer (CIO) and executive leadership team on cybersecurity risks, and posture.
  • Provide regular reporting on the status of the cybersecurity program to senior business leaders, the board of directors, and regulators.
  • Design and oversee the development and implementation of enterprise security policy, standards, guidelines, and procedures to maintain security posture, ensuring ongoing maintenance of security practices and consistency with best practices and regulatory frameworks (NYDFS, MI DIFS, NIST, NAIC).
  • Oversee the identification, assessment, and mitigation of cybersecurity risks across the organization, including third-party risk management.
  • Manage the cybersecurity governance program and regularly report risk metrics and status updates to executive leadership and relevant committees.
  • Create training programs of security policies, best practices and procedures to ensure that all staff has an understanding of how they contribute to the overarching security of the organization.
  • Collaborate with senior Business and IT leadership to define and evolve information security standards and controls, and mentor Security staff and associated management teams on the security process.
  • Collaborate with the Enterprise Risk Management (ERM) team and Business Continuity Program office to integrate cybersecurity measures into business resilience, including risk management and continuity planning.
  • Oversee a network of security staff and security vendors to safeguard the company's assets, intellectual property and computer systems.
  • Direct the security operations center (SOC), overseeing threat detection, threat hunting, incident response, digital forensics, and vulnerability management.
  • Maintain relationships with local, state and federal law enforcement and other related government agencies.
  • Lead cross-functional cyber incident response program and investigations, including tabletop and other preparedness exercises.
  • Work with outside consultants as appropriate for independent security audits.
  • Champion the adoption of cutting-edge security technologies and proactive defense measures to ensure operational excellence and resilience against evolving cyber threats.

Requirements

  • Minimum of 10 years of IT experience, including at least 5 years in management roles with responsibilities in budgeting and forecasting.
  • Minimum of 8 years of experience in Information Security, with expertise in analysis, design, and integration of security measures into applications, systems, and networks within a heterogeneous architecture.
  • One or more of the following Certifications: CISSP, CCISO, CISM, CRISC, GSEC or other GIAC specialization, CEH, CompTIA Security+, SSCP.
  • Insurance or financial services industry experience preferred, with an understanding of regulatory and compliance nuances specific to the sector.
  • In-depth knowledge of information security standards, processes, policies, frameworks, and metrics, covering network security, application security, data security, and cloud security.
  • Working knowledge of IT, Operating Systems, Network systems, Cloud and Operational Procedures, secure systems development lifecycle (S-SDLC), DevSecOps pipelines, business continuity planning, auditing, and risk management, as well as contract and vendor management.
  • Extensive experience in defining and executing audit processes to ensure compliance with information security standards and controls.
  • Exceptional verbal and written communication skills, with the ability to articulate technical security issues and concepts to both technical and non-technical staff, including employees, IT management, governance committee members, and senior leadership.
  • Proficient in driving cultural change and influencing all levels of the organization.
  • Demonstrated executive presence with the capability to represent cybersecurity in business forums.
  • Strong analytical skills to identify root causes of security incidents and risks.
  • Exemplary judgment in high-pressure situations, including incident response scenarios.
  • Data-driven decision-making to prioritize security initiatives based on business impact.

Qualifications

  • Master’s degree in Cybersecurity, Information Assurance, Business Administration (MBA), or a related discipline, preferred.
  • Degree in Computer Science or related Field or the equivalent combination of education and/or relevant experience.

Skills

  • Knowledge of information security standards, processes, policies, frameworks, and metrics, covering network security, application security, data security, and cloud security.
  • Experience in defining and executing audit processes to ensure compliance with information security standards and controls.
  • Exceptional verbal and written communication skills, with the ability to articulate technical security issues and concepts to both technical and non-technical staff.
  • Proficient in driving cultural change and influencing all levels of the organization.
  • Demonstrated executive presence with the capability to represent cybersecurity in business forums.
  • Strong analytical skills to identify root causes of security incidents and risks.
  • Exemplary judgment in high-pressure situations, including incident response scenarios.
  • Data-driven decision-making to prioritize security initiatives based on business impact.

Benefits

  • Competitive base pay
  • Performance-based incentive pay
  • Comprehensive health and welfare benefits
  • A 401(k) savings plan with profit sharing
  • Generous paid time off programs

Pay

Competitive base pay and performance-based incentive pay.

Schedule

3-day hybrid approach onsite in Farmington Hills, Michigan.

Company Culture

Amerisure is committed to being an employer of choice and offers a workplace that fosters excellence and professional growth. We are recognized as one of the Best and Brightest® Companies to Work For in the Nation and one of Business Insurance magazine’s Best Places to Work in Insurance.

Equal Opportunity Employer

Amerisure is an Equal Employment Opportunity employer. We provide equal employment opportunities to all employees and applicants without regard to race, color, religion, sex (to include sexual orientation and gender identity), national origin, age, disability, genetic information, veteran status, or any other protected characteristic under applicable federal, state, or local laws. We comply with all applicable laws governing nondiscrimination in employment in all locations where the company operates.

Similar jobs

AVP, Security

MacerichPhoenix, AZ· 2 mo ago
Information Technologyapply on recruiting2.ultipro.com

AVP, Security Architect

LPL FinancialTempe, AZ· 2 wk ago
Management$123k–$204k/yrapply on lplfinancial.wd1.myworkdayjobs.com

AVP, Security Architect

LPL FinancialAustin, TX· 2 wk ago
Information Technology$123k–$204k/yrapply on lplfinancial.wd1.myworkdayjobs.com