Overview
In this role you will manage and modernize Sompo’s global information security program, aligning with external and corporate requirements. You will lead a broad, multi-location security effort, influencing policy, architecture, and incident readiness. You’ll drive risk-based improvements, vulnerability management, and security communications to keep the organization secure amid evolving threats. This is a mission-driven opportunity to shape security across a large, diverse technology footprint.
Pay / Benefits
- two medical plans with HSA
- 401(k) plan with contributions
- paid time off and holidays
- parential leave benefits
- tuition reimbursement
- Employee Assistance Program
Responsibilities
- Maintain and continuously improve technical security controls across systems and processes with documented designs and real-time instrumentation
- Oversee vulnerability management and real-time reporting for organization-wide threat data
- Operate a security alerting function that evolves with the threat landscape
- Maintain tested incident response procedures capable of handling events at any scale
- Engage in the software development lifecycle to align with the information security program
- Establish a communications program to inform users about threats, policy changes, and security recommendations
- Lead security strategy and architecture communication to non-technical and executive audiences
- Coordinate with cross-functional teams and external partners to minimize security risk
Key requirements
- 15+ years in technical, security, and risk management roles
- 7+ years in a senior management role within information security
- Technical familiarity with security controls for Windows, cloud, and SaaS environments
- Experience integrating regulatory requirements and industry standards into procedures and designs
- Ability to translate metrics into KPIs and risk quantifiers
- Strong written, verbal, and interpersonal communications skills
- Leadership experience managing a hybrid team (direct reports, matrix reports, contractors)
- Bachelor in computer science, information security, or a related field
- Recognized information security certification (CISSP, CISM, etc.)
- excellent communication across diverse audiences
- leadership and people development
- strategic thinking and risk prioritization
- security patterns, operations and controls for Windows, cloud, and SaaS
- vulnerability management and incident response
- threat intelligence integration and adversary tactics
…
