Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Chief Information Security Officer — Insurance & Investments

thehivecareers.co

Job Summary

The Chief Information Security Officer (CISO) is the executive responsible for protecting the organization's information, technology infrastructure, applications, data, and digital services from cyber threats and security risks.

Within Insurance & Investments, the CISO leads enterprise cybersecurity, information security governance, cyber risk management, security architecture, incident response, regulatory compliance, identity and access management, third-party security, and business continuity/cyber resilience.

Key Responsibilities

  • Develop and execute the enterprise cybersecurity and information security strategy.
  • Establish information security policies, standards, controls, and governance frameworks.
  • Lead enterprise-wide cybersecurity risk management.
  • Protect sensitive customer, financial, investment, policyholder, employee, and corporate data.

Oversee:

  • Security Operations (SOC)
  • Threat Detection & Response
  • Incident Response
  • Security Architecture
  • Vulnerability Management
  • Penetration Testing
  • Identity & Access Management
  • Endpoint Security
  • Network Security
  • Cloud Security
  • Application Security
  • Data Security
  • Establish and manage cyber incident response and crisis-management processes.
  • Lead security monitoring, threat intelligence, vulnerability assessment, and security testing.
  • Develop cybersecurity controls across cloud, on-premise, applications, APIs, and digital platforms.
  • Implement and maintain Identity & Access Management (IAM), privileged access, MFA, and least-privilege controls.
  • Oversee third-party/vendor cybersecurity risk and technology due diligence.
  • Ensure security requirements are embedded into digital transformation and technology projects.
  • Lead security awareness, phishing prevention, and employee cybersecurity training.
  • Ensure compliance with applicable financial-services, privacy, cybersecurity, and regulatory requirements.
  • Manage security audits, risk assessments, control testing, and remediation programs.
  • Develop and test Business Continuity, Disaster Recovery, and Cyber Resilience plans.
  • Establish cybersecurity KPIs, KRIs, dashboards, and executive reporting.
  • Manage cybersecurity budgets, vendors, managed security providers, and strategic technology partners.
  • Lead and develop information-security and cybersecurity teams.
  • Advise the CEO, Board, Risk Committee, Audit Committee, and senior leadership on cyber risk.
  • Ensure cybersecurity risks are integrated into the organization's overall enterprise risk-management framework.

Insurance & Investments Security Focus

  • Insurance
  • Policyholder/customer data
  • Claims systems
  • Underwriting platforms
  • Actuarial systems
  • Payment systems
  • Customer portals
  • Insurance APIs
  • Fraud and identity data
  • Investments / Asset Management
  • Portfolio and investment systems
  • Trading platforms
  • Market and financial data
  • Investment research
  • Client/investor information
  • Custody and transaction systems
  • Wealth-management platforms
  • Third-party investment technology

Ideal Candidate Profile

  • 15+ years of IT, cybersecurity, information security, technology risk, or related experience.
  • 7+ years in senior cybersecurity/security leadership.

Previous experience as:

  • CISO
  • Group CISO
  • Chief Information Security Officer
  • Chief Cybersecurity Officer
  • Head of Information Security
  • Head of Cybersecurity
  • Director of Information Security
  • Director of Cybersecurity
  • VP Information Security
  • VP Cybersecurity

Strong background in Insurance, Banking, Investment Management, Asset Management, Wealth Management, or Financial Services.

Strong expertise in:

  • Cybersecurity strategy
  • Information security governance
  • Cyber risk management
  • Security architecture
  • SOC/SIEM
  • Incident response
  • Threat intelligence
  • Vulnerability management
  • IAM/PAM
  • Cloud security
  • Application security
  • Network security
  • Data security
  • Third-party risk
  • Business continuity/cyber resilience

Experience with recognized security frameworks and standards such as NIST, ISO 27001, CIS Controls, COBIT, or equivalent.

Strong understanding of financial-services cybersecurity and regulatory requirements.

Demonstrated experience presenting cyber risk to Board/C-suite stakeholders.

Strong leadership, crisis management, risk communication, and stakeholder-management skills.

Relevant bachelor's degree; Master's degree and certifications such as CISSP, CISM, CRISC, CISA, CCSP or equivalent are advantageous.

#J-18808-Ljbffr

Vacancy posted 19 hours ago
Similar jobs that could be interesting for youBased on the Chief Information Security Officer — Insurance & Investments in Puerto Rico vacancy
  •  ...Job Summary The Head of Information Technology leads the organization's overall IT...  ...infrastructure, systems, applications, security, data, and IT services effectively...  ...and operational objectives. In an Insurance & Investments environment, the role typically covers... 
    Suggested

    Jobleads-US

    Puerto Rico
    4 days ago
  •  ...process. Full Time Senior Management OFFICE, San Juan, PR, PR 7 days ago Requisition...  ..., optimize tax structures, and secure capital solutions tailored to their needs...  ...grants, federal R&D grants, and green energy investment incentives. At DECA, we empower businesses... 
    Suggested
    Full time
    Work at office
    Local area

    DECA

    Puerto Rico
    4 days ago
  •  ...DECA in San Juan, PR is seeking a hands-on Chief Technology Officer to define and lead the company’s technology vision. This executive role is...  ...for infrastructure strategy, product engineering alignment, security standards, and scaling a world-class technical organization... 
    Suggested

    Jobleads-US

    Puerto Rico
    4 days ago
  •  ...scale our technology vision, lead infrastructure strategy, and partner with executives to align tech with our mission, while ensuring security and regulatory compliance. The role emphasizes hands-on leadership, building a world-class engineering organization, and... 
    Suggested
    Remote job

    Jobleads-US

    Puerto Rico
    5 days ago
  •  ...Software Engineering (Cloud Security) This role has been designed...  ...primarily work from an HPE office. Who We Are: Hewlett...  ...visibility into security posture, investments, and key risks. Translate...  ..., familial status, genetic information, political affiliation, or... 
    Suggested
    Work at office
    Local area
    Worldwide

    Hewlett Packard Enterprise Development LP

    Puerto Rico
    4 hours ago
  •  ...improving compliance processes, policies, and security risk dynamics. This role is responsible...  ...of client companies Career guides, information, and tools to help you successfully...  ..., term life, whole life, accident insurance, critical illness, a legal plan, and short... 
    Bi-weekly pay
    Temporary work
    Local area
    Remote work

    Kelly Services

    Puerto Rico
    a month ago
  •  ...execute projects in: Automation, Control Systems Integration, Information Technology, System Integration and Regulatory Compliance. JCA...  ...documentation and change control management Microsoft Office 365 — Project, Excel, Word, Teams Soft Skills Technical... 
    Work at office

    JC Automation Corp

    Puerto Rico
    10 days ago
  •  ...execute projects in: Automation, Control Systems Integration, Information Technology, System Integration and Regulatory Compliance. JCA...  ...approach, and major CSV deliverables (Requirements, Design, Security Plan, Test Plan, etc.). Lead development and execution of Commissioning... 
    For contractors
    For subcontractor

    JC Automation Corp

    Puerto Rico
    10 days ago
  •  ...highly capable resources at an affordable cost to build solutions and execute projects in: Automation, Control Systems Integration, Information Technology, System Integration and Regulatory Compliance. JCA is a HUBZone Certified Small Business Firm, NMSDC Certified... 
    For contractors

    JC Automation Corp

    Puerto Rico
    10 days ago
  • Job Description Job Description Job Title:  Senior Leader – Analytical (Tech) Lead Job Description: Company : OcyonBio is a partnership development and manufacturing organization focused on advancing gene and cell therapies.   OcyonBio provides dedicated...
    Full time
    Local area
    Relocation

    Biosimilar Sciences PR LLC

    Puerto Rico
    10 days ago
  •  ...maintain a U.S. government issued security clearance is required. U.S....  ...world-class operations and investments in research and development,...  ...are authorized to access information under this program/contract....  ...Medical, dental, and vision insurance Three weeks of vacation... 
    Full time
    Contract work
    Relocation

    RTX

    Puerto Rico
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Chief Information Security Officer — Insurance & Investments. Be the first to apply!