SVP, Head of Security Technology
W. R. Berkley Corporation is comprised of 60+ businesses alongside Berkley Technology Services (BTS) and other shared services groups. At Berkley Technology Services, the core of our success is our people. Our teams bring unique perspectives and experiences, enabling us to deliver adaptable, secure solutions with an unmatched user-focused experience. Our tagline "Thoughtful Minds | Empowering Possibilities" reflects our commitment to fostering an environment where innovation and entrepreneurship thrive within Berkley's decentralized model. We operate as a relatively flat organization, valuing communication, feedback, and an open-door policy that treats everyone equally, fostering trust, transparency, and engagement.
Mission: We believe in the value of every voice, translate needs into capabilities, and secure the future of Berkley.
Vision: Be the foundation of Berkley through adaptable solutions, resilient environments, and an unmatched experience.
About the role
The SVP, Head of Security Technology, leads the modernization and delivery of the enterprise's core cybersecurity technology capabilities through an AI-enabled, automation-first, engineering-led model. This role reports to the CISO and is accountable for evolving and integrating:
- Security Architecture
- Security Engineering
- Identity and Access Management (IAM)
- Continuous Threat and Exposure Management (CTEM)
The position transforms legacy, siloed security functions (e.g., Vulnerability Management, Attack Surface Management, Application Security) into a scalable, intelligence-driven security ecosystem that:
- Reduces enterprise risk through engineering and automation
- Embeds security into enterprise architecture and technology platforms
- Strengthens identity lifecycle governance and compliance
- Enables continuous, risk-based exposure management
- Improves efficiency, control effectiveness, and compliance readiness
- Drives alignment between cybersecurity capabilities and business risk priorities, ensuring security investments directly support enterprise resilience, customer trust, and growth objectives
Responsibilities
Leadership & Strategy
- Report to the CISO and lead the strategic execution across a team of security directors, managers, architects, engineers, and analysts across multiple security technology disciplines.
- Establish a global operating model with clear accountability, service ownership, and capability maturity roadmaps.
- Develop business cases tied to measurable risk reduction, operational efficiency, and cost optimization.
- Partner with executive leadership and provide board-level reporting on security posture, risk trends, and investment impact.
- Drive roadmap, investment prioritization, and tool rationalization.
- Lead and develop high-performing, multi-disciplinary teams in a positive and respectful capacity, fostering high engagement.
- Assess the current environment and design a target state architecture with accompanying diagrams and documentation.
- Provide top-level support on security and operational-related issues.
- Represent information security interests on various project teams and special assignments.
- Continuously improve existing processes, methodologies, technologies, and practices.
- Provide top-level on-call support as required for this role.
Security Architecture
- Define enterprise security architecture strategy, standards, and roadmaps.
- Embed secure-by-design principles across cloud, applications, data, and AI.
- Establish reusable design patterns and reduce exception-based approvals.
- Integrate security into transformation and modernization efforts.
- Lead Zero Trust security architecture strategy and adoption across identity, network, application, and data layers.
- Establish reference architectures for multi-cloud and hybrid environments, including CNAPP, CIEM, and data protection controls.
Security Engineering
- Lead engineering and lifecycle management of security platforms and controls.
- Establish automation-first operations (API, orchestration, policy-as-code).
- Standardize tooling and reduce manual processes through automation.
- Improve platform resilience, telemetry, and service performance.
- Transition to a product- and platform-based security engineering model with defined service ownership, SLAs, and performance metrics.
- Drive rationalization of security tools and vendors to reduce cost and complexity while improving capability coverage.
Identity and Access Management (IAM)
- Lead and own overarching IAM strategy and lifecycle governance, including provisioning (joiners), access changes (movers), and de-provisioning (leavers).
- Enhance user access reviews and certifications.
- Implement, enhance, and automate segregation of duties (SoD) monitoring and governance.
- Design and implement role and entitlement management capabilities.
- Enable access-related compliance and audit readiness in preparation for continuous control monitoring and assessment.
- Ensure least privilege, timely access removal, and reduction of orphaned accounts.
- Integrate IAM with HR, applications, and enterprise platforms.
- Enhance privileged access management and management of non-human identities in preparation for advanced agentic AI capabilities.
- Advance privileged access, machine identity, and non-human identity security in support of automation, cloud, and AI use cases.
- Implement identity-centric Zero Trust controls and continuous authentication models.
Continuous Threat and Exposure Management (CTEM)
- Transform vulnerability, attack surface, and application security into a unified CTEM function.
- Implement continuous, threat-informed prioritization of exposures.
- Align findings to asset criticality and business risk.
- Improve remediation effectiveness and reduce exploitable attack paths.
- Enhance asset visibility, ownership clarity, and dependency mapping.
- Partner with Security Operations and Security Incident and Response functions to coordinate a unified approach across teams.
- Establish attack path analysis and exploitability-based risk prioritization to reduce material exposure.
- Define measurable outcomes such as reduction in attack surface, time-to-remediation, and control effectiveness.
AI and Automation Enablement
- Deploy AI and analytics to improve prioritization and decision-making.
- Automate repetitive security processes and control validation.
- Enhance reporting, telemetry, and audit evidence generation.
- Partner with Head of Security AI to establish secure AI lifecycle practices, including model governance, data protection, prompt security, and third-party AI risk management.
- Partner with Head of Security Operations to leverage AI to enhance threat detection, anomaly identification, and predictive risk analytics.
DevSecOps and Secure Development
- Embed security into the software development lifecycle (SDLC), CI/CD pipelines, and developer workflows.
- Partner with engineering teams to implement scalable DevSecOps practices and developer-friendly security tooling.
Resilience and Risk Integration
- Partner with Security Operations and Incident Response to improve cyber resilience, recovery readiness, and crisis response integration.
- Ensure alignment with enterprise risk management and regulatory expectations through continuous control monitoring.
Requirements
- 15+ years’ experience in a cybersecurity role with at least 5 as head of senior-most security architect.
- Previous and progressive experience in a technical security leadership position.
- Demonstrated experience modernizing security organizations (tool consolidation, automation, operating model redesign).
- Strong expertise in cloud-native security, Zero Trust, IAM, and CTEM practices.
- Experience integrating cybersecurity with AI/ML technologies and governance frameworks.
- Strong strategic thinking and decision-making capabilities.
- Experience managing budgets, vendors, and large-scale programs.
- Track record of delivering measurable improvements in risk reduction, efficiency, and security posture.
- Disciplined thinker with a structured approach to security architecture and strategic planning.
- Inherent intellectual capability and curiosity to learn complex processes.
- Proven thought leadership, strategic thinking, and decision-making.
- Strong analytical and problem-solving skills with the capability to identify solutions to unusual and complex problems.
- CISSP certification is strongly preferred.
- Direct security-related AI, networking, infrastructure, cloud, operating system, development, and database experience is required.
- Ability to demonstrate proficiency in a wide range of security technologies, embedded security, and network platforms – in a global institution.
- Ability to balance multiple priorities in high-pressure situations.
- Project, portfolio, and resource management experience is required.
- Willingness to travel (domestic and international) up to 30–40% as required.
Qualifications
Bachelor’s Degree in Computer Science, Information Technology, Information Systems, or a related discipline. Equivalent experience and/or alternative qualifications will be considered.
Schedule
Primary location: Wilmington, DE. Domestic and international travel up to 30–40% as required.