North America Information Security Officer
About the Role
The Information Security Officer (ISO) will support North America within the Regional Security Office (RSO), focusing on advancing the cybersecurity posture of the NFP business, driving secure integration of mergers and acquisitions (M&A), and ensuring alignment with New York Department of Financial Services (NYDFS) regulatory requirements. This role works closely with the North America Regional Security Officer to manage regional cybersecurity risk and involves implementing targeted remediation programs and deploying Global Cybersecurity Services (GCS) controls. The ISO serves as the main contact for cybersecurity across NFP and M&A activities, requiring a deep understanding of security controls and regulatory expectations.
Responsibilities
- Provide Cybersecurity reporting to leadership committees and Boards.
- Represent Cybersecurity to regulatory bodies and manage the Cybersecurity strategy for the designated region.
- Lead the colleague security culture program and represent the region in the Security Incident Management process.
- Manage remediation of internal audit findings, cybersecurity compliance, and conduct management.
- Lead a Cybersecurity Risk committee, track remediation of audit and compliance findings, and review cybersecurity metrics.
- Ensure necessary security controls are in place in conjunction with Data Privacy.
- Handle GCS service delivery critical issues and support GCS project implementation.
- Provide continuity and disaster recovery support, along with data governance support.
- Represent Cybersecurity on client calls, provide security advice, and support GCS service engagement.
Qualifications
- 8+ years of broad Cybersecurity experience in a large, complex corporate environment, preferably in insurance or financial services.
- Solid knowledge of Cybersecurity domains: application security, vulnerability management, network and cloud security, security operations, supplier risk management, and cyber awareness.
- Experience in effective Cyber Risk Management and regulatory compliance, particularly with NYDFS.
- Strong relationship-building and communication skills, with the ability to engage with C-level executives and technical/non-technical audiences.
- Experience with Compliance assurance and Audit practices.
- Security certifications (CISSP, CISM) are advantageous.
- Understanding of compliance standards: ISO27001, SOC 2, NYDFS.
Pay
The salary range for this position (intended for U.S. applicants) is $140,000 to $170,000 annually. The actual salary will vary based on education, experience, skills, and geographic location. This position is eligible for an annual discretionary bonus and a comprehensive benefits package.
Benefits
- 401(k) savings plan with employer contributions.
- Employee stock purchase plan.
- Medical, dental, and vision insurance.
- Paid time off, including 12 paid holidays and 15 days of paid vacation per year.
- Short-term disability and optional long-term disability.
- Health savings account and dependent care reimbursement accounts.
- Employee and dependent life insurance.
- Tuition assistance and commuter benefits.
- Two “Global Wellbeing Days” per year.
Schedule
Flexible working style solutions are available to manage work/life balance.