Manager, Information Security Assurance Services
$146.43k - $198.11kThrivent Financial
- # Manager, Information Security Assurance ServicesApply: United States: Full time: Posted Yesterday: REQ-47402The Manager, Information Security Assurance Services is responsible for leading the design, build, and continuous maturation of the program. This role requires a proven track record of establishing and scaling information security assurance capabilities, including control frameworks, regulatory compliance, and audit readiness, information security awareness, policy governance, third-party risk management, and Payment Card Industry Data Security Standards (PCI DSS). This leader will oversee a team accountable for executing and evolving assurance processes, with a clear mandate to drive automation, standardization, and gain operational efficiency across all Assurance Services products and services. The role partners closely with business, technology, and regulatory stakeholders to ensure controls are effectively implemented, measured, and aligned to organizational risk tolerance and regulatory requirements. The ideal candidate brings demonstrated experience building GRC programs from the ground up and advancing them to a mature, technology-enabled function, leveraging automation, integrated tooling, and data-driven insights to reduce manual effort, improve control effectiveness, and enhance transparency. This role will be responsible for executing the strategic direction, establish scalable processes, and ensure the team delivers consistent, high-quality outcomes that strengthen the organization’s overall security posture and resilience.**Job Duties and Responsibilities*** Program leadership across assurance domains —Lead and continuously mature governance, controls design and testing, audit and regulatory response, security awareness, policy governance, third-party/vendor risk management (TPRM), and the PCI DSS program, with full accountability for adherence to established controls, policies, and regulatory requirements.* Hands-on subject matter expertise — Serve as the team's go-to expert across information security assurance disciplines. Step in as an active contributor on control narratives, audit walkthroughs, regulator engagements, and remediation plans when program needs demand it.* Control framework ownership — Build, maintain, and continuously improve the control framework, ensuring alignment with NYDFS Part 500, NIST Cybersecurity Framework, CIS Controls, HIPAA, FDIC, PCI DSS v4.x, and other applicable standards. Maintain control libraries, control-to-framework mappings, and a defensible evidence model.* Audit and regulatory response — Direct the end-to-end response to internal audits, external audits, regulatory examinations, and PCI engagements. Personally review high-risk responses, evidence packages, and management responses prior to submission.* PCI DSS program oversight — Provide senior oversight and governance of the PCI DSS v4.x program, including scope validation, strategy, control implementation, ISA coordination, AOC/ROC readiness, compensating controls, and establish a clear multi-year roadmap to support enterprise goals.* Third-party risk management — Mature the TPRM program including inherent risk tiering, due diligence depth-of-review, contractual security requirements, ongoing monitoring, fourth-party visibility, and concentration risk reporting.* Policy governance — Own the enterprise information security policy governance (policies, standards, procedures, guidelines), including a defined lifecycle, exception management, ownership accountability, and executive committee approval cadence.* Security awareness — Direct the strategy, content, and measurement of the enterprise information security awareness program, including annual training, role-based training, phishing simulations, and Cybersecurity Awareness Month (CSAM) campaigns and activities.* Executive translation and stakeholder partnership — Translate strategic priorities, regulatory expectations, and informal executive conversations into structured roadmaps, OKRs, deliverables, sprint commitments, and team execution plans. Partner with business, technology, regulatory stakeholders, and third parties to communicate complex issues, drive alignment on contentious topics, and advocate for business-aligned outcomes.* People leadership and talent development — Manage, coach, and develop a multi-disciplinary team of assurance professionals. Set clear expectations, establish accountability, conduct performance management, and build a high-performing and high-trust team.* Continuous improvement and automation — Drive process maturity, automation of evidence collection and control testing, improved reporting routines, reduced manual effort, and effective use and management of GRC/IRM platforms (e.g., ServiceNow IRM) to scale the program and sustain operations.* Metrics and reporting — Define and operationalize KPIs/KRIs across each assurance domain. Deliver board-ready and executive-ready dashboards, and narrative reporting that articulate program health and remediation trajectory.* Decision-making and influence — Make and own operational and strategic decisions with significant impact to program effectiveness, and guide senior leaders through informed recommendations, best practices, and trade-off discussions.**Required Job Qualifications****Required Experience:*** Minimum 10 years of progressive experience across GRC, information security, technology risk, internal/external audit, controls, cybersecurity assurance, or closely related disciplines.* Minimum 5 years of direct people leadership experience, including coaching, performance management, workforce planning, and talent development.* Demonstrated experience operating within or directly supporting PCI DSS environments, including scope definition, control design, testing, remediation, evidence management, and QSA/ISA interaction.* Strong working knowledge of governance and control frameworks including NYDFS Part 500, NIST Cybersecurity Framework, CIS Controls, and PCI DSS, with the ability to design and defend control rationale to auditors and regulators.* Demonstrated experience designing, testing, and remediating IT general controls (ITGCs) and application-level controls.* Proven ability to communicate complex risk and control topics clearly to executive audiences, audit committees, regulators, and cross-functional stakeholders.* Ability to operate independently under limited direction, prioritize competing demands, and consistently deliver results in ambiguous, fast-moving environments.* Bachelor's degree in Information Security, Computer Science, Information Systems, related discipline, or equivalent professional experience.**Preferred Experience:*** Experience implementing or operating ServiceNow Integrated Risk Management (IRM) or comparable GRC platforms (e.g., Archer, AuditBoard, OneTrust, MetricStream).* Experience operating within a Product Operating Model, including roadmap planning, backlog grooming, sprint-based delivery, feature commitment management, and metrics-driven execution.* Experience in financial services, banking, or other highly regulated industries, including direct interaction with regulators such as state banking authorities, the OCC, FDIC, or NYDFS.* Industry certifications such as CISSP, CISA, CISM, CRISC, CGEIT, or CIA.* Demonstrated success improving control automation, continuous control monitoring, assurance testing efficiency, audit-readiness practices, and evidence-as-code approaches.**Other Critical Factors****Skills:*** Strategic ownership — Sets multi-year vision for the assurance portfolio; does not wait for direction to identify gaps or propose roadmaps.* Executive presence — Comfortable engaging directly with the CISO, CIO, General Counsel, Chief Risk Officer, business unit leaders, audit committee members, and external regulators. Presents findings with confidence and influences decisions without escalation dependence.* Decision ownership — Makes defensible decisions on control design, risk acceptance recommendations, exception treatment, and resource allocation. Documents rationale and owns outcomes.* Talent multiplier — Develops individual contributors into the next generation of assurance leaders through structured coaching, stretch assignments, and clear feedback.* Outcome bias — Holds the team accountable to measurable outcomes (audit results, exemption rates, control coverage, completion velocity), not activity.* Hands-on when needed — Models the way. Willing to personally write the control narrative, sit through the examiner walkthrough, or draft the board bullet when the situation requires senior-level execution.Pay TransparencyThrivent’s long-term growth depends on attracting, rewarding, and retaining people who are committed to helping others thrive with purpose. We accomplish this by offering a wide variety of market competitive compensation programs to attract, reward, and retain top talent. The applicable salary or hourly wage range for this full-time role is $146,428.00 - $198,108.00 per year, which factors in various geographic regions. The base pay actually offered will be determined by a variety of factors including, but not limited to, location, relevant experience, skills, and knowledge, business needs, market demand, and other factors Thrivent deems important.Thrivent is unique in our commitment to helping people to be wise with money and live balanced and generous lives. That extends to our benefits.The following benefits may be offered: various bonuses (including, for example, annual or long-term incentives); medical, dental, and vision insurance; health savings account; flexible spending account; 401k; pension; life and accidental death and dismemberment insurance; disability insurance; supplemental protection insurance; 20 days of Paid Time Off each year; Sick and Safe Time; 10 paid company holidays; Volunteer Time Off; paid parental leave; EAP; well-being benefits, and other employee benefits. Eligibility for receipt of these benefits is subject to the applicable plan/policy documents. Thrivent’s plans/policies are subject to change at any time at Thrivent’s discretion.*Thrivent provides Equal Employment Opportunity (EEO) without regard to race, religion, color,* *sex, gender identity, sexual orientation, pregnancy, national origin, age, disability, marital status, citizenship status, military or veteran status, genetic information, or any other status protected by applicable local, state, or federal law. This policy applies to all employees and job applicants.**Thrivent is committed to providing reasonable accommodation to individuals with disabilities. If you need a reasonable accommodation, please let us know by sending an email to View email address on click.appcast.io or call View phone number on click.appcast.io and request Human Resources.*
- J-18808-Ljbffr Thrivent Financial
Vacancy posted 23 hours ago
Similar jobs that could be interesting for youBased on the Manager, Information Security Assurance Services in Eastern, KY vacancy
- ...The Manager, Information Security leads Jewelers Mutual's security engineering and operations function, overseeing information security engineers... ...‑driven insights to continuously improve our products, services, and customer experience. Our mission is to be the industry...SuggestedContract workWork experience placement
- ...software company providing comprehensive business management solutions for law firms and other professional services organizations with a mission to help them run... ...management software for law firms, and the Information Security team protects the systems, data, and client...Suggested
- ...in building out a mature, right-sized information security program to protect patient data, clinical... ...across all sites. We are seeking a Manager, Information Security to own the company... ...Discounts – Save on products and services with special discounts just for you...SuggestedFull timeTemporary workImmediate start
- ## Manager, Information SecurityApply: Bingen, WA: Full time: Posted 7 Days Ago: R0003762Are you passionate about protecting critical assets... ...innovation? Join our team and be the driving force behind a secure and resilient enterprise. We’re seeking a strategic and hands...SuggestedFull timeWork at officeFlexible hours3 days per week
- ...Director of Information SecuritySkip to main contentBSU... ...CareersDirector of Information Security page is loaded##... ..., oversee Information Assurance Specialists, and... ...also be responsible for managing external audits at the... ...employment to all programs and services provided by the...SuggestedWork at office
$200k - $260k
...development and lifecycle management—delivering measurable and transformational... ...is seeking a Head of Information Security to lead the company’s... ...the business, sustain assurance commitments, and build customer... ...external contractors or service providers accountable for results...Temporary workFor contractors- ...and evolve our global security operations and cybersecurity... ...directly to the Chief Information Security Officer (CISO... ...partner closely with managed security and XDR... ...communications. Partner with XDR service providers and managed... ..., and customer assurance activities with timely...Full timeContract workWork experience placement
$95k - $193k
## Senior Manager - Cloud SecurityAplikuj: United States Remote Office... ...the Senior Manager - Cloud Security will make an impact:The... ...retaining accountability for services owned by Cloud Security.Key responsibilities... ...Define security testing and assurance approaches that identify and...Work at officeLocal areaRemote workWorldwide$165k - $185k
...appointment scheduling, queue management, and experiential events... ...retail, banking, and financial services brands. About the role... ...platform fast, reliable, and secure. As Director of DevOps, Security... ...the direction for jrni's Information Security program against ISO...Remote work- ## Director, Information SecurityApplylocations: PA - Yardleytime type: Full timeposted on:... ...future.**Job Description:****Information Security Director****Role Overview**Crown Holdings... ...business growth, and effectively manages evolving cyber risk.The Information Security...Work experience placementWork at office
- ...the trust of over 200 million athletes by securing our platform, our data, and the systems... ...distributed company. As the Senior Manager of Enterprise Security Engineering, you... ...strategic security vendors and managed service providers. Bonus Points Experience...Work at officeFlexible hours3 days per week
- ...Position Summary The Director of Information Security owns Fetch's security function end to end: vulnerability management and AppSec, incident response and forensics, security architecture, GRC/compliance, third-party risk, and security awareness. This role is the...Full timeFor contractors
- American Savings Bank Hawaii is seeking a Manager, IT Audit to lead planning and execution of IT risk assessments and internal control reviews. The role emphasizes information security, regulatory compliance, and collaboration with technology teams. The ideal candidate...
$220.2k - $351.8k
...Full time: Posted Yesterday: P751400## About the teamZillow’s Information Security team is the engineering-first security organization at the... ...security engineers, and then go present business risk. You will manage a team of managers and senior individual contributors across...Permanent employmentFull timeLive inWork at officeRemote workShift work$172k - $237k
...in mind every step of the way. As Manager, Security Operations, you will defend our infrastructure... ...dedicated teams and award-winning service, customers get personalized support... ...U.S. Equal Opportunity Employment Information Forward Financing is proud to be...Work at officeRemote workWork from homeFlexible hours- ## Director Of Security OperationsApply: Hybrid: OH - Columbus -... ...call rotation.● Vulnerability Management: Drive vulnerability... ...for confidential financial information, including classification, encryption... ...Technology Operations leads service restoration and tracks...Full timeH1bWork at office
$85k
...inclusive and dynamic environment. You will provide direct security and related public services. Compensation: $85,000.00/annually Benefits:... ...operations and tasks to the security officers and hotel managers Manage officer scheduling and accurately report hours...Full timeTemporary workFor contractorsWork at officeShift work$119.7k - $272.2k
...happen. We’d love to have you join us. As a key leader within Security Services, you will play a vital role in advancing a culture of safety... ...alarm monitoring, incident response, access control management, and close coordination with law enforcement. This team is essential...$150.7k - $226.1k
...Senior Manager, Regional Security – Americas Organization: Location: Description: About the job Why... ...delivering cutting-edge hardware and network services to more than 100 million people and... ..., and external partners to stay informed on emerging trends and best practices...Work at office2 days per week- Accumulus Technologies, Inc. is seeking a Head of Information Security to lead the company’s information security function across corporate operations and the Accumulus Platform. Reporting directly to the COO, this leader will set security strategy, oversee governance,...
- ...over all the world’s information, far beyond Google. If... ...Define Exa’s company-wide security strategy, operating... ...controls, vulnerability management, offensive testing,... ...key, certificate, and service-trust systems across human... ..., and customer assurance, including programs such...H1b
- ...Director of Security Job ID: 2026-3198 Type: Regular Full-Time # of... ...client locations, ensuring reliable service, effective risk management, and strong client relationships. This... ...judgment, handle confidential information, and respond effectively to urgent...Full timeContract workTemporary workWork at officeLocal areaNight shift
- SPHERE is seeking a Strategic Program Manager to lead enterprise customer engagements from kickoff through delivery, owning scope, schedule, budget, and quality across multiple workstreams. This role bridges customer stakeholders with SPHERE's implementation and technical...
- Triwill Group is seeking an Engineering Manager, Rapid Response in the United States to lead a high-performing team focused on offensive security, vulnerability research, and rapid threat mitigation. You will blend people leadership with hands-on technical work, building...
- A10 Networks is seeking a Manager, Product Security and Trust to lead the security of all shipped products. The role covers hands-on testing across SAST, DAST, SCA, and container security, while embedding these processes into the development pipeline. You will partner with...
$120k - $140k
...Senior Director, End User Computing & Email Systems, the Manager, Endpoint Security & M365 Engineering is responsible for administering Windows... ...and written skills with a record of outstanding customer service. Must work well in a team environment. Demonstrated ability...Temporary workLocal area$205k - $230k
...Remote Full-time Senior Security Job Description Director, Security Operations... ...hunting, security analytics, vulnerability management, adversary emulation, identity security,... ...resilience. Establish operational priorities, service objectives, metrics, playbooks, and...Full timeWork experience placementRemote work- ...application due to a disability, contact this employer to ask for an accommodation or an alternative application process. Safety and Security Manager Full-time Regular Professionals LOUISVILLE, KY, US GENERAL SUMMARY: The Safety Manager supports the Director of...Full timeFor contractorsWork at officeLocal area
- Major Tool in Indianapolis, IN is seeking an IT Manager to lead the site IT team and oversee day-to-day IT operations, security, and reliability of systems. You will partner with the Director of IT on standardization, security, and integration initiatives. The role requires...
- Blend Labs Inc. is seeking a Manager of Security Engineering to own the day-to-day operations of the security team responsible for our product, platform, and SDLC. You will shape the team's roadmap and contribute to adversarial testing and security tooling across the organization...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Manager, Information Security Assurance Services. Be the first to apply!
Related searches
- program manager with security clearance Eastern, KY
- security operations manager Eastern, KY
- physical security manager Eastern, KY
- director information security Eastern, KY
- corporate security manager Eastern, KY
- security manager Eastern, KY
- surveillance manager Eastern, KY
- security engineering manager Eastern, KY
- director global security Eastern, KY
- security systems manager Eastern, KY

