Live opening · Posted 9 hours ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
Job Summary
The Head of Information Security leads the organization's information-security function, protecting technology systems, applications, networks, data, and digital services against cyber threats and operational security risks.
Within Insurance & Investments, the role focuses on information-security governance, cyber risk, security operations, identity and access management, vulnerability management, incident response, third-party security, cloud/application security, and regulatory compliance.
Key Responsibilities
Develop and implement the Information Security strategy, roadmap, policies, and standards.
Establish and maintain the organization's information-security governance framework.
Conduct enterprise-wide cybersecurity and information-security risk assessments.
Lead security operations, monitoring, threat detection, and incident response.
Oversee:
Security Operations Center (SOC)
SIEM
Threat Intelligence
Vulnerability Management
Penetration Testing
Identity & Access Management (IAM)
Privileged Access Management (PAM)
Network Security
Endpoint Security
Cloud Security
Application Security
Data Security
Develop and maintain information-security policies, procedures, controls, and standards.
Manage security incidents, investigations, containment, remediation, and post-incident reviews.
Establish vulnerability-management and security-testing programs.
Ensure appropriate access controls, authentication, MFA, segregation of duties, and least-privilege practices.
Protect sensitive customer, policyholder, financial, investment, employee, and corporate data.
Partner with IT and technology teams to embed security into infrastructure, applications, cloud, APIs, and digital transformation projects.
Conduct security reviews of new systems, applications, vendors, and technology implementations.
Manage third-party/vendor cybersecurity risk and security due diligence.
Support business continuity, disaster recovery, and cyber-resilience programs.
Lead security awareness, employee training, phishing simulations, and cybersecurity culture initiatives.
Ensure compliance with applicable financial-services, privacy, cybersecurity, and regulatory requirements.
Coordinate internal/external security audits and remediation activities.
Develop security KPIs, KRIs, dashboards, and management reports.
Manage security vendors, managed security providers, budgets, and technology investments.
Lead, mentor, and develop information-security and cybersecurity teams.
Provide regular security-risk reporting to the CISO, CIO, executive management, Risk Committee, or Board, depending on organizational structure.
Insurance & Investments Security Focus
Insurance
Policyholder and customer information
Claims and underwriting systems
Insurance applications and portals
Payment systems
Customer identity and authentication
Actuarial and risk systems
Fraud-management platforms
Third-party insurance technology
Investments / Asset Management
Portfolio-management systems
Trading and investment platforms
Market and financial data
Investment research systems
Client/investor information
Custody and transaction systems
Wealth-management platforms
Investment APIs and third-party providers
Ideal Candidate Profile
10–15+ years of information security, cybersecurity, IT risk, or technology experience.
5+ years in information-security leadership.
Previous experience as:
Head of Information Security
Head of Cybersecurity
Head of Cyber Security
Head of IT Security
Director of Information Security
Director of Cybersecurity
Information Security Director
Cybersecurity Director
VP Information Security
Information Security Manager
Senior Information Security Manager
Experience in Insurance, Banking, Investment Management, Asset Management, Wealth Management, or Financial Services preferred.
Strong knowledge of:
Information-security governance
Cyber risk management
Security operations
Incident response
Vulnerability management
IAM/PAM
Cloud security
Application security
Network security
Data security
Security architecture
Third-party risk
Business continuity/cyber resilience
Familiarity with NIST, ISO 27001, CIS Controls, COBIT, or equivalent frameworks.
Experience managing security teams and external security vendors.
Strong understanding of financial-services security and regulatory requirements.
Strong communication skills with IT, Risk, Compliance, Audit, Legal, and executive stakeholders.
Certifications such as CISSP, CISM, CISA, CRISC, CCSP are advantageous.
Work arrangement
Yes
More openings worth a look
Recently tracked roles with full details and direct application links.