Chief Information Security Officer (CISO) — Insurance & Investments

thehivecareers.co
  • San Juan, San Juan
    4 days ago

    Job Description

    Job Summary

    The Chief Information Security Officer (CISO) is the executive responsible for protecting the organization's information, technology infrastructure, applications, data, and digital services from cyber threats and security risks.

    Within Insurance & Investments, the CISO leads enterprise cybersecurity, information security governance, cyber risk management, security architecture, incident response, regulatory compliance, identity and access management, third-party security, and business continuity/cyber resilience.

    Key Responsibilities

    Develop and execute the enterprise cybersecurity and information security strategy.

    Establish information security policies, standards, controls, and governance frameworks.

    Lead enterprise-wide cybersecurity risk management.

    Protect sensitive customer, financial, investment, policyholder, employee, and corporate data.

    Oversee:

    Security Operations (SOC)

    Threat Detection & Response

    Incident Response

    Security Architecture

    Vulnerability Management

    Penetration Testing

    Identity & Access Management

    Endpoint Security

    Network Security

    Cloud Security

    Application Security

    Data Security

    Establish and manage cyber incident response and crisis-management processes.

    Lead security monitoring, threat intelligence, vulnerability assessment, and security testing.

    Develop cybersecurity controls across cloud, on-premise, applications, APIs, and digital platforms.

    Implement and maintain Identity & Access Management (IAM), privileged access, MFA, and least-privilege controls.

    Oversee third-party/vendor cybersecurity risk and technology due diligence.

    Ensure security requirements are embedded into digital transformation and technology projects.

    Lead security awareness, phishing prevention, and employee cybersecurity training.

    Ensure compliance with applicable financial-services, privacy, cybersecurity, and regulatory requirements.

    Manage security audits, risk assessments, control testing, and remediation programs.

    Develop and test Business Continuity, Disaster Recovery, and Cyber Resilience plans.

    Establish cybersecurity KPIs, KRIs, dashboards, and executive reporting.

    Manage cybersecurity budgets, vendors, managed security providers, and strategic technology partners.

    Lead and develop information-security and cybersecurity teams.

    Advise the CEO, Board, Risk Committee, Audit Committee, and senior leadership on cyber risk.

    Ensure cybersecurity risks are integrated into the organization's overall enterprise risk-management framework.

    Insurance & Investments Security Focus

    Particularly relevant experience includes protecting:

    Insurance

    Policyholder/customer data

    Claims systems

    Underwriting platforms

    Actuarial systems

    Payment systems

    Customer portals

    Insurance APIs

    Fraud and identity data

    Investments / Asset Management

    Portfolio and investment systems

    Trading platforms

    Market and financial data

    Investment research

    Client/investor information

    Custody and transaction systems

    Wealth-management platforms

    Third-party investment technology

    Ideal Candidate Profile

    15+ years of IT, cybersecurity, information security, technology risk, or related experience.

    7+ years in senior cybersecurity/security leadership.

    Previous experience as:

    CISO

    Group CISO

    Chief Information Security Officer

    Chief Cybersecurity Officer

    Head of Information Security

    Head of Cybersecurity

    Director of Information Security

    Director of Cybersecurity

    VP Information Security

    VP Cybersecurity

    Strong background in Insurance, Banking, Investment Management, Asset Management, Wealth Management, or Financial Services.

    Strong expertise in:

    Cybersecurity strategy

    Information security governance

    Cyber risk management

    Security architecture

    SOC/SIEM

    Incident response

    Threat intelligence

    Vulnerability management

    IAM/PAM

    Cloud security

    Application security

    Network security

    Data security

    Third-party risk

    Business continuity/cyber resilience

    Experience with recognized security frameworks and standards such as NIST, ISO 27001, CIS Controls, COBIT, or equivalent.

    Strong understanding of financial-services cybersecurity and regulatory requirements.

    Demonstrated experience presenting cyber risk to Board/C-suite stakeholders.

    Strong leadership, crisis management, risk communication, and stakeholder-management skills.

    Relevant bachelor's degree; Master's degree and certifications such as CISSP, CISM, CRISC, CISA, CCSP or equivalent are advantageous.

    Numbers & Facts

    LocationSan Juan, San Juan
    Websitethehivecareers.co

    Skills

    • Application Programming Interface (API)unmatched
    • Asset Managementunmatched
    • Auditingunmatched
    • Banking Servicesunmatched
    • Budget Managementunmatched
    • Business Developmentunmatched
    • CCSP - Cisco Certified Security Professionalunmatched
    • CISA - Certified Information Systems Auditorunmatched
    • CISM - Certified Information Security Managerunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Computer Securityunmatched
    • Control Objectives for Information and related Technology (COBIT)unmatched
    • Crisis Managementunmatched
    • Customer/Client Researchunmatched
    • Disaster Recoveryunmatched
    • Due Diligenceunmatched
    • Embedded Systemsunmatched
    • Financial Servicesunmatched
    • ISO (International Organization for Standardization)unmatched
    • Identity Data Managementunmatched
    • Incident Responseunmatched
    • Information Technology & Information Systemsunmatched
    • Information/Data Security (InfoSec)unmatched
    • Insuranceunmatched
    • Internet Securityunmatched
    • Investment Managementunmatched
    • Leadershipunmatched
    • Performance Metricsunmatched
    • Phishingunmatched
    • Policy Developmentunmatched
    • Regulatory Complianceunmatched
    • Regulatory Requirementsunmatched
    • Reporting Dashboardsunmatched
    • Riskunmatched
    • Risk Analysisunmatched
    • Risk Managementunmatched
    • Risk Management Framework (RMF)unmatched
    • Security Analysisunmatched
    • Security Architectureunmatched
    • Security Attacksunmatched
    • Security Auditingunmatched
    • Security Monitoringunmatched
    • Staff Trainingunmatched
    • Technical Strategyunmatched
    • Test Plan/Scheduleunmatched
    • Testingunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • Wealth Managementunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder