Principal Information Security Analyst
$121k - $173kFM Corporation
Job Description:
Established nearly two centuries ago, FM is a leading mutual insurance company whose capital, scientific research capability and engineering expertise are solely dedicated to property risk management and the resilience of its policyholder-owners. These owners, who share the belief that the majority of property loss is preventable, represent many of the world’s largest organizations, including one of every four Fortune 500 companies. They work with FM to better understand the hazards that can impact their business continuity to make cost-effective risk management decisions, combining property loss prevention with insurance protection.
Schedule & Location : This position requires on-site work one day per week at our Corporate Headquarters and flexibility to be on-site when needed based on the demands of the business.
Relocation is not offered for this position .
Summary
FM is seeking a Principal Information Security Analyst with deep expertise in cybersecurity regulatory compliance and oversight. In this high-impact role, you will lead the execution of FM’s global cybersecurity regulatory compliance program, ensuring the organization proactively identifies, understands, and responds to evolving global cybersecurity requirements.
You will play a critical role in protecting FM by evaluating how cybersecurity regulatory expectations apply to our systems, data, and internal processes, and translating those requirements into actionable controls and practices. This is a highly visible role where your expertise in cyber risk, regulatory frameworks, and control design will help shape business decisions, strengthen our security posture, and ensure ongoing alignment with regulatory obligations.
You will partner closely with security, technology, risk, legal, and business teams to identify gaps, define expectations, and recommend practical, business-aligned solutions. Additionally, you will act as a primary point of coordination for external cybersecurity inquiries, including regulators, auditors, and clients.
You will lead end-to-end cybersecurity regulatory assessments and control evaluations, going beyond standard compliance activities to evaluate alignment across systems, data, and technical processes.
Key Responsibilities
Regulatory & Compliance: Lead the end-to-end cybersecurity regulatory compliance function, including governance, processes, tooling, and reporting.
Respond to External Inquires: Coordinate and lead responses to regulatory exams, client cybersecurity questionnaires, and other external information requests. Partner with Information Security, IT, Risk, Legal, and business stakeholders to gather, validate, and communicate accurate, consistent, and audit-ready responses aligned to FM’s control environment.
Regulatory Horizon Scanning & Impact Analysis: Proactively monitor and evaluate emerging cybersecurity regulations, standards, and guidance globally. Perform impact assessments to determine applicability and required changes to FM’s control environment.
Gap Identification & Remediation Oversight: Lead regulatory gap assessments and control evaluations. As necessary, partner with technical and business teams to define remediation actions and track remediation progress, validate closure of gaps, and escalate risks as needed.
Governance, Reporting, & Audit Readiness: Develop and maintain metrics, dashboards, and reporting on compliance posture, risks, and trends. Provide clear, concise updates to senior leadership and governance committees.
Advisory & Stakeholder Engagement: Act as a trusted advisor on regulatory and compliance matters across IT, security, and business teams. Provide guidance on control design, risk treatment, and regulatory alignment. Influence decisions to ensure alignment with FM’s risk appetite and regulatory obligations.
Program Maturity & Continuous Improvement: Identify opportunities to enhance program efficiency, automation, and maturity. Implement leading practices in regulatory compliance, controls management, and assurance.
Lead and mentor: Lead complex initiatives and provide direction to cross-functional contributors. Promote a culture of accountability, transparency, and continuous improvement.
8+ years of experience in cybersecurity, information security, cyber risk, audit, or regulatory compliance. Global experience desired.
Experience applying cybersecurity frameworks (NIST CSF 2.0, CIS v8.1), including mapping controls to regulations and using a risk-based approach to solve problems.
Regulatory & Compliance:
Hands-on experience responding to regulatory exams, audits, or client security assessments, including evidence collection, control mapping, and response coordination.
Experience supporting or participating in IT general controls (ITGC) or cybersecurity control audits, with an understanding of audit expectations, testing approaches, and evidence requirements.
Familiarity with global regulatory requirements across regions (e.g., APAC, EU, US), including regulatory bodies such as APRA, IRDAI, OFSI, or MAS.
Experience identifying control gaps, assessing compliance against regulatory expectations, and supporting remediation tracking.
Control Framework & Risk Analysis
Strong problem-solving and analytical skills, with the ability to interpret regulatory requirements and apply them in a practical, risk-based manner.
Documentation & Audit Readiness
Ability to develop and maintain clear, accurate, and audit-ready control documentation and supporting evidence.
High attention to detail, particularly in documentation, quality, and accuracy of responses.
Stakeholder Engagement & Communication
Strong stakeholder management and collaboration skills, with the ability to work effectively across Information Security & Risk Management, IT, Risk, Legal, and business teams.
Strong verbal and written communication skills, with the ability to translate technical security concepts into clear, concise responses for regulators, clients, and business stakeholders.
Execution & Operating Discipline
Strong organizational and time management skills, with the ability to manage multiple concurrent requests and deadlines.
Ability to work independently, prioritize competing demands, and deliver high-quality outputs with minimal supervision.
Education
A bachelor's degree in information security, Computer Science, Information Technology, or a related field may be considered.
Relevant certifications in security, technology, or risk disciplines are preferred, such as CISA, CISM.
The hiring range for this position is $121,000 - $173,000. The final salary offer will vary based on geographic location, individual education, skills, and experience. The position is eligible to participate in FM’s comprehensive Total Rewards program that includes an incentive plan, medical, dental and vision insurance, life and disability insurance, well-being programs, a 401(k) and pension plan, career development opportunities, tuition reimbursement, flexible work, and time off, including vacation and sick time.
FM is an Equal Opportunity Employer and is committed to attracting, developing, and retaining a diverse workforce.
#LI-NL1
$78.9k - $123.3k
...continuous monitoring activities within a Federal environment. This role is responsible for managing the security authorization lifecycle for one or more information systems, ensuring compliance with Federal cybersecurity requirements, and maintaining the documentation...SuggestedPermanent employmentFull timePart timeWork at officeLocal areaRemote work- ...Centreville Bank is seeking a Vendor Management Analyst in Warwick, Rhode Island. This role supports the Third-Party Risk Management (TPRM) program by evaluating vendor risks, reviewing contracts, and maintaining documentation for compliance. Candidates should have a Bachelor...Suggested
$40 per hour
...for experienced cybersecurity professionals to join our team to help train AI models. In this role, you will evaluate AI-generated security content, solve technical cybersecurity problems, and provide feedback to improve how AI systems reason about real-world threats...SuggestedHourly payFull timePart timeRemote work- ...The opportunity As an Offensive Security Analyst on the Attack Surface Management team, you will play a key role in evaluating and reducing... ...orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability...SuggestedSummer holidayFlexible hours
- ..., KY • Rhode Island • Allentown, PA Role Overview Support the secure development and governance of AI/ML solutions by partnering with... ...initiatives Requirements Bachelor’s in Computer Science, Information Security, or related field 2+ years in cybersecurity with exposure...Suggested
$40 per hour
A cybersecurity solutions company seeks experienced cybersecurity professionals to evaluate AI-generated security content, solve technical problems, and shape AI models. This position offers flexible remote work and hourly pay starting at $40+. Ideal candidates should...Hourly payRemote workFlexible hours$40 per hour
A cybersecurity company is seeking experienced professionals to evaluate AI-generated security content and solve technical problems. This remote role offers flexible projects with payment starting at $40+ per hour. Candidates should have hands-on experience in cybersecurity...Remote jobHourly payFlexible hours$40 per hour
A leading AI security company is seeking experienced cybersecurity professionals to join their team remotely. Responsibilities include evaluating AI-generated security content, solving technical problems related to cybersecurity, and providing feedback for improving AI...Hourly payRemote work$110k - $125k
...our mission of creating opportunities for people where they live, learn, and work. CampusGuard, a Nelnet company, provides information security and privacy consulting and compliance services primarily for campus-based organizations including higher education institutions...Temporary workFixed term contractLocal areaRemote workWork from homeHome office$59.8k - $122.4k
...Financial Analyst III Location: Providence, RI, US, 02903 Requisition ID: 19451 Brightstar... ...on our renowned expertise in delivering secure technology and producing reliable,... ...approximately 6,000 employees. For more information, please visit Responsibilities This role...Contract workLocal area$114.5k - $154.58k
...Description Summary: We're looking for a Principal Sales Engineer who is not only... ...environments is preferred. Familiarity with security best practices for data handling across... ...sometimes unstructured environment. Information Security: Information security is...PrincipalRemote workWorldwide- ...Job Description Job Description ABOUT THE ROLE: The Security Analyst Intern will support the Credit Union's Security and Fraud team... ...of member accounts and transaction patterns by gathering information and conducting preliminary analysis under supervision. # Monitors...Work experience placementInternshipWork at officeRelocation
$126.2k - $264.1k
...Job Description Principal Data Center Physical Security Systems Engineer Team Overview The Data Center Construction organization at Oracle Cloud... ...’s degree in Engineering, Construction Management, Information Technology, Security Management, or a related field, or...PrincipalTemporary workFor contractorsLive inLocal areaRelocationRelocation packageFlexible hours- ...Job Description A partner of Insight Global is looking for a Principal Security Architect to join their team. This person will lead the... ...more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy:...Principal
$126.2k - $264.1k
...transformation. About the Role As an Senior Principal Product Manager, you will own product... ..., support, engineering, design, QA, security, privacy, compliance, and operations to... ...research and competitive analysis to inform product direction. Collaborate with design...PrincipalTemporary workFlexible hours$105.79k - $141.05k
...our expansive fiber network and connected ecosystem. We enable secure, high-performance connectivity across cloud, edge, and AI... ...ready connectivity, join us today. The Role The Manager of Information Security-Cyber Threat Exposure Management plays a critical role...Temporary workRemote work$115.3k - $264.1k
...visible growth areas: data center and AI infrastructure. The Sr Principal Program Manager - Data Center Campaigns will own the operating... ..., and/or drug testing requirements.** **Range and benefit information provided in this posting are specific to the stated locations...PrincipalTemporary workLocal areaFlexible hours$72.7k
...SUMMARY The Senior Marketing Analytics Analyst plays a critical role in transforming... ...internal customers. Keeps management informed of project activity, interdependencies,... ...Policies and Procedures as well as all data security guidelines established within the...For contractorsWork at officeLocal area$126.2k - $264.1k
...applicable requirements, such as immunization/occupational health mandates, and/or drug testing requirements. Range and benefit information provided in this posting are specific to the stated locations only US: Hiring Range in USD from: $126,200 to $264,100 per...PrincipalTemporary workFlexible hours- ...Employee Type Exempt Salary Statement of Duties The Investment Analyst will support the Investment Team by acting as an efficient... ...Intelligence: The ability to acquire understanding and absorb information rapidly. A quick study. Resourcefulness: Passionately finds ways...Full timeFlexible hours
- ...A leading AI development company is seeking an Investment Operations Analyst to help train AI on financial principles. This role offers remote flexibility and can be pursued part-time or full-time. Candidates should have advanced financial reasoning skills, proficiency...Hourly payFull timePart timeRemote work
- ...We are looking to fill a Principal Scientist - Purification Chemist position working as a full-time employee of Parexel FSP on long-term assignment onsite at one of our clients located in Rahway, NJ . This position offers full benefits, sick time, 401K, paid holidays...PrincipalFull time
- ...battlefield operations through circulation control, providing area security, conducting prisoner of war operations, supervising civilian... ...your Army National Guard recruiter for the most up-to-date information. Actual MOS assignment may depend on MOS availability. Other Job...Part timeWeekend work
- ...assistance if necessary. Complete incident reports to document all Security/Loss Prevention related incidents. Handle all interruptions... .../Loss Prevention and property reports/documents; release information only to authorized individuals. Conduct investigations and gather...Work experience placementShift work
- ...Job Summary: Provide security detail as outlined in the post orders and establish working relationships with customers, local law... ...proactive in knowing all revisions to post orders and general information distributed by the customer and AFS. Patrol physical property...For contractorsLocal area
- ...Citizens Bank is seeking a Junior Business Data Analyst in Johnston, RI. This role supports the design and improvement of operational and AI-ready data solutions. The ideal candidate will facilitate communication between business stakeholders and technical teams to ensure...Flexible hours
$50 - $60 per hour
A tech company specializing in AI is seeking a Senior Financial Analyst to enhance AI models by reviewing financial responses and providing critical feedback. This position offers remote flexibility and the choice to work part-time or full-time. Ideal candidates will have...Hourly payFull timePart timeRemote work$126.2k - $264.1k
...Job Description We are seeking an experienced Principal Data Center Facilities Development Manager to oversee the onsite construction... ...delivery, address gaps in risk identification and mitigation, and inform the business of associated potential impacts. # Tenant Fit...PrincipalFull timeTemporary workFor contractorsFlexible hours- ...Additional Information Job Number 26061236 Job Category Loss Prevention & Security Location 191 Dorrance St, Providence, Rhode Island, United States, 02903 VIEW ON MAP ( Schedule Full Time Located Remotely? N Position Type Non-Management POSITION...Full timeWork experience placementRemote workShift work
$80.8k - $120k
...decisions. Collaborate cross-functionally with other financial analysts and managers on special projects, as prioritized by finance... ...religion, sex, age, national origin, veteran status, genetic information, and other legally protected categories. View The EEO Know Your...Work experience placement2 days per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Principal Information Security Analyst. Be the first to apply!

