Head of Information Security — Insurance & Investments

thehivecareers.co
  • San Juan
    4 days ago

    Job Description

    Job Summary

    The Head of Information Security leads the organization's information-security function, protecting technology systems, applications, networks, data, and digital services against cyber threats and operational security risks.

    Within Insurance & Investments, the role focuses on information-security governance, cyber risk, security operations, identity and access management, vulnerability management, incident response, third-party security, cloud/application security, and regulatory compliance.

    Key Responsibilities
    Develop and implement the Information Security strategy, roadmap, policies, and standards.
    Establish and maintain the organization's information-security governance framework.
    Conduct enterprise-wide cybersecurity and information-security risk assessments.
    Lead security operations, monitoring, threat detection, and incident response.
    Oversee:
    Security Operations Center (SOC)
    SIEM
    Threat Intelligence
    Vulnerability Management
    Penetration Testing
    Identity & Access Management (IAM)
    Privileged Access Management (PAM)
    Network Security
    Endpoint Security
    Cloud Security
    Application Security
    Data Security
    Develop and maintain information-security policies, procedures, controls, and standards.
    Manage security incidents, investigations, containment, remediation, and post-incident reviews.
    Establish vulnerability-management and security-testing programs.
    Ensure appropriate access controls, authentication, MFA, segregation of duties, and least-privilege practices.
    Protect sensitive customer, policyholder, financial, investment, employee, and corporate data.
    Partner with IT and technology teams to embed security into infrastructure, applications, cloud, APIs, and digital transformation projects.
    Conduct security reviews of new systems, applications, vendors, and technology implementations.
    Manage third-party/vendor cybersecurity risk and security due diligence.
    Support business continuity, disaster recovery, and cyber-resilience programs.
    Lead security awareness, employee training, phishing simulations, and cybersecurity culture initiatives.
    Ensure compliance with applicable financial-services, privacy, cybersecurity, and regulatory requirements.
    Coordinate internal/external security audits and remediation activities.
    Develop security KPIs, KRIs, dashboards, and management reports.
    Manage security vendors, managed security providers, budgets, and technology investments.
    Lead, mentor, and develop information-security and cybersecurity teams.
    Provide regular security-risk reporting to the CISO, CIO, executive management, Risk Committee, or Board, depending on organizational structure.
    Insurance & Investments Security Focus
    Insurance
    Policyholder and customer information
    Claims and underwriting systems
    Insurance applications and portals
    Payment systems
    Customer identity and authentication
    Actuarial and risk systems
    Fraud-management platforms
    Third-party insurance technology
    Investments / Asset Management
    Portfolio-management systems
    Trading and investment platforms
    Market and financial data
    Investment research systems
    Client/investor information
    Custody and transaction systems
    Wealth-management platforms
    Investment APIs and third-party providers
    Ideal Candidate Profile
    10–15+ years of information security, cybersecurity, IT risk, or technology experience.
    5+ years in information-security leadership.
    Previous experience as:
    Head of Information Security
    Head of Cybersecurity
    Head of Cyber Security
    Head of IT Security
    Director of Information Security
    Director of Cybersecurity
    Information Security Director
    Cybersecurity Director
    VP Information Security
    Information Security Manager
    Senior Information Security Manager
    Experience in Insurance, Banking, Investment Management, Asset Management, Wealth Management, or Financial Services preferred.
    Strong knowledge of:
    Information-security governance
    Cyber risk management
    Security operations
    Incident response
    Vulnerability management
    IAM/PAM
    Cloud security
    Application security
    Network security
    Data security
    Security architecture
    Third-party risk
    Business continuity/cyber resilience
    Familiarity with NIST, ISO 27001, CIS Controls, COBIT, or equivalent frameworks.
    Experience managing security teams and external security vendors.
    Strong understanding of financial-services security and regulatory requirements.
    Strong communication skills with IT, Risk, Compliance, Audit, Legal, and executive stakeholders.
    Certifications such as CISSP, CISM, CISA, CRISC, CCSP are advantageous.

    Numbers & Facts

    LocationSan Juan

    Skills

    • Application Programming Interface (API)unmatched
    • Applications Securityunmatched
    • Asset Managementunmatched
    • Authenticationunmatched
    • Banking Servicesunmatched
    • Budgetingunmatched
    • Business Supportunmatched
    • CCSP - Cisco Certified Security Professionalunmatched
    • CISA - Certified Information Systems Auditorunmatched
    • CISM - Certified Information Security Managerunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Cloud Applicationsunmatched
    • Communication Skillsunmatched
    • Computer Securityunmatched
    • Control Objectives for Information and related Technology (COBIT)unmatched
    • Disaster Recoveryunmatched
    • Due Diligenceunmatched
    • Financial Servicesunmatched
    • ISO (International Organization for Standardization)unmatched
    • Identity Data Managementunmatched
    • Incident Managementunmatched
    • Incident Responseunmatched
    • Information/Data Security (InfoSec)unmatched
    • Insuranceunmatched
    • Internet Applicationunmatched
    • Internet Securityunmatched
    • Investment Managementunmatched
    • Legalunmatched
    • Mentoringunmatched
    • Operations Security (OPSEC)unmatched
    • Performance Metricsunmatched
    • Phishingunmatched
    • Regulatory Compliance Softwareunmatched
    • Regulatory Requirementsunmatched
    • Reporting Dashboardsunmatched
    • Riskunmatched
    • Risk Analysisunmatched
    • Risk Managementunmatched
    • Security Analysisunmatched
    • Security Attacksunmatched
    • Security Infrastructureunmatched
    • Security Monitoringunmatched
    • Staff Trainingunmatched
    • Test Programunmatched
    • Third-Party Payerunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • Vendor/Supplier Managementunmatched
    • Wealth Managementunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder