4,217 Avp Security jobs in the United States

AVP, Information Security Analyst

90079 Los Angeles, California The TCW Group

Posted 3 days ago

Job Viewed

Tap Again To Close

Job Description



AVP, Information Security Analyst

Job Location(s)

US-CA-Los Angeles

Job ID



Category

Information Technology

Department

Engineering Solutions

Type

Regular Full-Time

Position Summary

Overview: The AVP Security Analyst is a mid-level role within TCW's Information Security team, with a strong focus on vulnerability management and cloud security (Azure). The team is responsible for safeguarding the confidentiality, integrity, and availability of the firm's data and technology assets through proactive monitoring, response, and the continuous improvement of information security controls and processes. The AVP will play a key role in strengthening the firm's security posture by driving vulnerability management activities, advancing Azure security controls, and collaborating with both technology and business teams to reduce risk across the enterprise.

Purpose: The AVP Security Analyst will support and lead the enhancement of TCW's information security operations by managing the vulnerability lifecycle, analyzing and assessing threats, and contributing to cloud and enterprise incident response activities. The AVP will work closely with experienced security professionals and cross-functional partners to identify risks, validate security events, and coordinate remediation efforts. This position requires strong technical expertise, hands-on experience with cloud security and vulnerability management, and the ability to operate effectively in a dynamic, regulated environment.

Essential Duties

    Lead the full vulnerability management lifecycle (scanning, assessment, prioritization, reporting, and remediation) across cloud and on-prem environments.
  • Support and enhance asset discovery and management by leveraging tools such as Armis to ensure complete visibility of cloud, on-prem, and hybrid assets, enabling more effective vulnerability management, threat detection, and incident response.
  • Implement, monitor, and improve Azure-native security controls, including identity, workload, and data protection, as well as CSPM and CNAPP tooling for cloud risk management.
  • Investigate, validate, and escalate suspicious or anomalous activity through available tools and telemetry.
  • Provide strong support for incident response, including investigation, containment, remediation, and lessons learned across the lifecycle of security incidents
  • Manage and optimize SIEM and SOC operations, including detection engineering, correlation rules, alert handling, and escalation processes (Microsoft Sentinel preferred).
  • Configure, manage, and maintain EDR capabilities to ensure effective endpoint visibility, protection, and response.
  • Conduct technical and practical threat hunting in Azure and hybrid environments to proactively detect and mitigate risks.
  • Utilize basic scripting/querying skills (KQL, PowerShell, Python) to support investigations, analysis, and automation efforts.
  • Partner with infrastructure, application, and cloud teams to assess existing controls and implement security improvements.
  • Participate in regular security operations reviews and recommend improvements to processes, tools, and controls.
  • Stay current on evolving cloud security risks, vulnerability trends, and attack techniques, with emphasis on Azure.
  • Perform other security-related duties as assigned.
Required Qualifications
  • Minimum of 5 years of experience in Information Security, with at least 3 years of in-depth experience with vulnerability management, cloud security, and/or security operations.
  • Strong hands-on experience with cloud security (azure preferred), including policy enforcement, identity and access management, and secure configurations.
  • Proven track record with vulnerability scanning tools (e.g., Defender, Qualys, Tenable, Vipr) and the ability to drive remediation programs across enterprise environments.
  • Hands-on experience with SIEM/SOC operations (Microsoft Sentinel preferred), including detection engineering and event analysis.
  • Experience with EDR platforms, including configuration, management, and optimization of endpoint security capabilities.
  • Experience with asset management platforms (e.g., Armis, Axonious, ServiceNow CMDB, or similar) and applying asset intelligence to support security operations.
  • Solid understanding of incident response methodologies, threat detection, and cloud-native attack vectors.
  • Strong analytical skills with ability to identify root causes and provide actionable, risk-based recommendations.
  • Excellent written and verbal communication skills, including clear documentation of investigations and outcomes.
  • Ability to work independently and collaboratively with technical and non-technical stakeholders.
  • Comfortable managing multiple priorities in a fast-paced, evolving environment.
Professional Skills Qualifications
  • Bachelor's degree in Information Security, Computer Science, Information Systems, or related field or equitable working experience.
  • Familiarity with threat modeling frameworks (e.g., MITRE ATT&CK).
  • Knowledge of security frameworks (e.g., NIST, ISO, CSA).
  • Proficiency with scripting/querying (e.g., KQL, PowerShell, Python) for analysis and automation.
  • Certifications such as Security+, CySA+, CEH, GCIA, GSEC, AZ-500, SC-200, CISSP, CISM, GCIH or equivalent

This role requires candidates to work from a TCW office a minimum of four days a week. Flexibility for remote work is offered on one day, depending on business needs.

Estimated Compensation:

Base Salary: For a CA based position, the base salary is $135-150K.

Other Compensation :In addition to the base salary, this position will be eligible to be considered for an annual discretionary bonus.

Benefits : Eligible for TCW's comprehensive benefits package. See more information here.

#LI-JS1

View Now

AVP-Cyber-Healthcare security

07390 Jersey City, New Jersey ExlService Holdings , Inc.

Posted 9 days ago

Job Viewed

Tap Again To Close

Job Description

Job Description

AVP - Cybersecurity is responsible for overseeing cybersecurity operations and strategy within EXL Health and Life Sciences business units. This role ensures Confidentiality, Integrity, and Availability of information assets, particularly sensitive data (PHI). This role also involves implementing standards and security policies that are maintained and managing technical implementation projects.

Responsibilities

The roles responsibilities involves, manages application security, infrastructure security, SOC operations, incident response, and third-party risk management. With 10+ years in information security and at least 5 years in progressive leadership roles, you bring the proven ability to build resilient security programs, lead high-performing teams, and serve as a trusted advisor. Your background in regulated environments, including HIPAA/HITECH, combined with recognized security certifications, sets you apart. If you're ready to drive security in healthcare technology.

Major Deliverables:
  • Conduct enterprise risk assessments and develop mitigation strategies.
  • Ensure compliance with federal, state, and industry regulations governing PII, PHI, and other sensitive data.
  • Coordinate security audits, vendor risk assessments, and penetration testing.
  • Integrate security into business processes, product development, and IT operations, including DevSecOps practices.
  • Overseeing all aspects of information security, including application security, infrastructure security and third-party risk management
  • Serve as the primary escalation point for security events, coordinating containment, investigation, and post-incident reviews.
  • Serving as a trusted advisor to executive leadership on security posture, risk, and enterprise resilience
  • Defining and executing the company's security strategy aligned with business objectives - building a proactive security posture that protects systems, data, and customers
  • Leading major incident response efforts, from technical containment to executive and board-level communications
  • Partnering with IT, DevOps, and business units to embed security into technology, systems, and business processes
  • Managing SOC operations, threat detection, and secure design of systems, applications, and cloud environments (AWS, Azure)
  • Ensuring adherence to leading security and compliance frameworks, including HIPAA, HITECH, FedRAMP, SOC 2, ISO 27001, and PCI DSS
  • Supporting compliance teams by providing technical security expertise during audits and assessments
  • Provide technical consultation and training to IT and business teams on secure design and operational practices.
  • Foster a culture of security awareness through focused training programs.
Qualifications

Minimum Requirements:
  • Minimum of 10 years of experience in cybersecurity, with deep expertise in healthcare regulations such as HIPAA, HITECH, and HITRUST
  • Equivalent experience or a degree in cybersecurity, information systems, or a related field. Advanced certifications (e.g., CISSP, CISM) or degrees are highly desirable
  • Proven success in shaping and executing security strategies and initiatives that improve patient data protection, regulatory alignment, and secure care delivery
  • Strong executive communication and facilitation skills, with experience leading workshops, building consensus, and influencing senior stakeholders
  • Demonstrated ability to lead cross-functional engagements, drive alignment, and proactively contribute to strategic opportunities
  • Familiarity with Generative AI (e.g., Copilot, Gemini) and its implications for security, governance, and risk management
  • Experience with agile methodologies, design thinking, and collaborative solution development
  • Ability to conduct market research and translate insights into actionable security strategies and content
  • Strong collaboration, influencing, and negotiation skills, with a relentless focus on customer success
  • Enjoyment from working in a fast-paced, dynamic environment where initiative and assertiveness are key
  • Passion for mentoring, sharing knowledge, and contributing to a culture of continuous learning
  • Research and evaluate emerging privacy technologies from academia and industry, contributing to open-source tools and AI privacy standards
  • Act as consultant and advocate for privacy best practices as central to our mission of Responsible AI
Preferred Qualifications:
  • Strong communicator with the ability to positively influence engineers, developers, architects, and business leaders alike
  • Thoughtful, pragmatic, and able to execute in a high-velocity, agile environment
  • Deeply collaborative and experienced at embedding security into developer culture
  • Track record of reducing risk without slowing down innovation
  • Being articulate and precise to the internal stakeholders who are seeking counsel on what are the risks, why are they impactful, and options on how to resolve them
  • Broad knowledge across the Security domain, as well as demonstrated focus in AI security evaluations and in one (or more) areas of Cybersecurity such as Red Teaming, Purple Teaming, Vulnerability Research, and Exploitation
  • Master's degree (or foreign degree equivalent) in Information Systems Engineering, Computer Science, Engineering, Information Security, Cyber Security, Information Assurance, or related field


About Us

EXL (NASDAQ: EXLS) is a leading data analytics and digital operations and solutions company. We partner with clients using a data and AI-led approach to reinvent business models, drive better business outcomes and unlock growth with speed. EXL harnesses the power of data, analytics, AI, and deep industry knowledge to transform operations for the world's leading corporations in industries including insurance, healthcare, banking and financial services, media and retail, among others. EXL was founded in 1999 with the core values of innovation, collaboration, excellence, integrity and respect. We are headquartered in New York and have more than 54,000 employees spanning six continents. For more information, visit

EXL never requires or asks for fees/payments or credit card or bank details during any phase of the recruitment or hiring process and has not authorized any agencies or partners to collect any fee or payment from prospective candidates. EXL will only extend a job offer after a candidate has gone through a formal interview process with members of EXL's Human Resources team, as well as our hiring managers.

About the Team

EXL is the indispensable partner for leading businesses in data-led industries such as insurance, banking and financial services, healthcare, retail and logistics. We bring a unique combination of data, advanced analytics, digital technology and industry expertise to help our clients turn data into insights, streamline operations, improve customer experience, and transform their business. Our partnerships with clients are built on a foundation of collaboration - and we've been chosen as a partner by nine of the top ten leading US insurance companies, nine of the top 20 global banks, and six of the top ten US health care payers. We function as one team to make your goals our goals, whether that's unlocking the value of generative AI or embedding analytics into workflows that reduce risk or power your growth. Clients choose EXL as their transformation partner for many reasons. Our geographic diversity make talent all over the world instantly accessible. Digital accelerators enable unmatched speed-to-value, letting you realize results fast. It's our people that truly set us apart, though, including the 1,500 data scientists we have dedicated to our generative AI practice. And our more than twenty years of experience in delivering business services, garnering stellar client references, and maintaining a solid balance sheet are reassuring to our C-suite clients. Find out for yourself why clients, employees, and analysts think we're some of the best in the business. Contact us to see how we can help you achieve your goals.
View Now

AVP, Deputy Chief Information Security Officer

33441 Deerfield Beach, Florida JM Family

Posted today

Job Viewed

Tap Again To Close

Job Description

Deputy Chief Information Security Officer

As a strategic leader at JM Family Enterprises, the Deputy Chief Information Security Officer (Deputy CISO) plays a critical role in aligning business unit IT priorities with enterprise security and platform capabilities. Reporting directly to the Chief Information Security Officer (CISO), this role serves as a bridge between technical teams and business stakeholders, ensuring secure, scalable, and cost-effective solutions are delivered across the organization. The Deputy CISO will drive cross-functional collaboration, governance, and oversight to uphold our security standards and enable innovation.

Responsibilities:

  • Build, inspire, and lead a high-performing, multidisciplinary security team
  • Serve as principal deputy to the CISO, assuming leadership in their absence
  • Collaborate closely with the CISO to manage and execute the enterprise security strategy
  • Partner with BU IT leaders to ensure ERP, CRM, HCM, and SaaS platforms are secure and effective
  • Lead the enterprise Application Security program, including secure coding, application scanning, penetration testing, and secure architecture reviews
  • Oversee application security and enablement program across custom, SaaS, and packaged applications
  • Lead the secure enablement of enterprise-wide IT initiatives, including ERP/CRM implementations, cloud migrations, digital transformation, and infrastructure modernization
  • Drive secure adoption and transformation of enterprise platforms (ex. Oracle, Salesforce, Workday, ServiceNow, industry-specific apps)
  • Enable DevSecOps practices for enterprise application teams, embedding automated security checks into application delivery pipelines
  • Partner with application owners and business leaders to ensure security is a business enabler, not a blocker, to transformation initiatives
  • Champion secure user experience and adoption of enterprise platforms
  • Monitor and manage risks associated with enterprise applications and integrations
  • Lead strategic planning and adopt global cybersecurity best practices
  • Develop, implement, and maintain the organization's information security program
  • Drive enterprise-wide information security risk management and mitigation
  • Ensure compliance with regulatory, industry, and contractual security standards (SOX, PCI DSS, HIPAA, GDPR, ISO, NIST)
  • Oversee third-party/vendor risk management and due diligence
  • Partner with executive and business unit leaders to integrate cybersecurity into decision-making
  • Embed "security by design" into digital transformation, cloud, and emerging tech initiatives
  • Promote a culture of security through training, simulations, and awareness campaigns
  • Develop future cybersecurity leaders and support succession planning
  • Align business demand with platform capabilities and delivery feasibility
  • Escalate unresolved platform or security design issues as appropriate
  • Collaborate with Internal Audit, Legal, and Compliance to ensure audit readiness
  • Ensure BU IT programs and services meet business expectations
  • Develop executive-level reporting and metrics to demonstrate business enablement

Qualifications:

  • Bachelor's Degree in Computer Science, Information Security, or related field (Master's preferred)
  • 15+ years of experience in Information Security and/or Application Development including 7+ years leading Information Security at the executive level in cloud-native or high-scale technology environments
  • Proven track record managing end-to-end software/application development lifecycles
  • Relevant industry certifications ex. Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC) are preferred
  • Proven track record managing budgets totaling $ 20 million +, showcasing financial acumen in IT operations
  • Deep understanding of technical architecture patterns and platform constraints
  • Proven working knowledge of cybersecurity principles, Identity and Access Management (IAM), and other non-functional requirements
  • Strong Understanding of Application Development Lifecycle
  • Demonstrated effectiveness of establishing standards and best practices for Agile development, DevSecOps, CI/CD pipelines, and test automation
  • Experience driving cloud-native development, SaaS adoption, and enterprise modernization
  • Proven track record enabling enterprise application solutions (ERP, CRM, HR, Finance, Supply Chain, Digital Platforms)
  • Deep knowledge of application development methodologies (Agile, SAFe, DevSecOps)
  • Strong understanding of enterprise architecture, integration, and data platforms
  • Ability to interpret, assess, and validate complex technical solution proposals
  • Deep understanding of current and emerging cyber threats, attack vectors, and risk mitigation strategies
  • Leadership and effective communication skills, with a strong ability to analyze and problem resolution; while also being self-motivated and results driven
  • Demonstrated effectiveness as a leader for staff management, development, and mentorship
  • Strong business acumen with ability to translate complex security concepts into business-relevant language
  • Exceptional communication and influencing skills with senior leadership
  • Demonstrated ability to lead and inspire large, distributed teams across multiple disciplines
  • Strategic thinker with an execution mindset, balancing risk and enablement
  • Experience managing technical intake and demand processes across enterprise environments
  • Strong leadership in facilitating cross-functional technical trade-off discussions and decision-making
  • Must stay current with industry trends, threat intelligence, and emerging technologies
  • Comfortable working in a fast-paced, highly visible role with enterprise-wide influence
  • Collaborates with Legal and Government Relations/Compliance teams to ensure compliance with relevant laws, regulations, and policies
View Now

Cloud Security Analyst, AVP

07070 Rutherford, New Jersey Citigroup

Posted 2 days ago

Job Viewed

Tap Again To Close

Job Description

**Overview of the Role**
Citi, the leading global bank, has approximately 200 million customer accounts and does business in more than 160 countries and jurisdictions. Citi provides consumers, corporations, governments, and institutions with a broad range of financial products and services, including consumer banking and credit, corporate and investment banking, securities brokerage, transaction services, and wealth management.
As a bank with a brain and a soul, Citi creates economic value that is systemically responsible and in our clients' best interests. As a financial institution that touches every region of the world and every sector that shapes your daily life, our Enterprise Operations & Technology teams are charged with a mission that rivals any large tech company. Our technology solutions are the foundations of everything we do from keeping the bank safe, managing global resources, and providing the technical tools our workers need to be successful to designing our digital architecture and ensuring our platforms provide a first-class customer experience. We reimagine client and partner experiences to deliver excellence through secure, reliable, and efficient services.
Our commitment to diversity includes a workforce that represents the clients we serve from all walks of life, backgrounds, and origins. We foster an environment where the best people want to work. We value and demand respect for others, promote individuals based on merit, and ensure opportunities for personal development are widely available to all. Ideal candidates are innovators with well-rounded backgrounds who bring their authentic selves to work and complement our culture of delivering results with pride. If you are a problem solver who seeks passion in your work, come join us. We'll enable growth and progress together.
**The Role:** The Cloud Security Testing & Assurance team works in a multi-disciplinary team of teams driving cyber security services and solutions to enable Citi to securely adopt Private, Hybrid, and Public Cloud platforms. This role will be responsible for liaising between various Citi businesses/organizations. The candidate will work specifically with Cloud security monitoring and logging tooling and large amounts of data to produce high quality and actionable metrics from various security and management tools.
**Responsibilities:**
+ Develop corrective action language for Information Security (IS) gaps and ensure risk closure meets Citi requirements or industry best practices
+ Create of Business Requirement Documents (BRDs) for implementation and integration of security controls
+ Utilize Security Information and Event Management systems (SIEMs) to verify control implementation and collect relevant metrics
+ Run Cloud Continuous Monitoring reporting/metrics governing all security compliance/hygiene issues across the entire Cloud ecosystem
+ Manage the security project workstream by using JIRA to create, track and follow-up on tasks
+ Collect security-related operational metrics through automation and increase security visibility across the organization
+ Measure the coverage and effectiveness of security tools, while providing transparency over the security state of the Cloud
+ Mitigate risk by analyzing the root cause of issues, impacts to business, and required corrective actions and develop security solutions
+ Analyze large amounts of Data, generate actionable metrics, and create presentations for key stakeholders
+ Manage project workflows via JIRA and Confluence
+ Provide Information Security advice and counsel as needed
+ Demonstrate appropriate consideration for the firm's reputation and safeguarding Citigroup, its clients, and assets by driving compliance with applicable laws, regulations, and Citi Policy
+ Apply sound ethical judgment regarding personal behavior, conduct and business practices, while escalating, managing and reporting control issues with transparency
**Qualifications:**
+ 3+ years' Data Analysis experience
+ 1-2 years' hands-on experience working with Cloud platforms (AWS, GCP, Azure, etc.)
+ Strong knowledge of the tools and processes to provide operational security support to Citi's Cloud ecosystem
+ Strong foundational knowledge of Cloud security concepts/best practices in various Cloud Service Providers like AWS, GCP, and Azure
+ Experience with SIEM tooling (Splunk, ArcSight, etc.)
+ Strong proficiency in Excel, PowerPoint, etc.
+ Consistently clear and concise written and verbal communication
+ IT Project management experience using JIRA and Confluence highly preferred
**Education:**
+ Bachelor's degree/University degree or equivalent experience
+ Additional technical certifications are preferred
This job description provides a high-level review of the types of work performed. Other job-related duties may be assigned as required.
---
**Job Family Group:**
Technology
---
**Job Family:**
Information Security
---
**Time Type:**
Full time
---
**Primary Location:**
Rutherford New Jersey United States
---
**Primary Location Full Time Salary Range:**
$109,120.00 - $163,680.00
In addition to salary, Citi's offerings may also include, for eligible employees, discretionary and formulaic incentive and retention awards. Citi offers competitive employee benefits, including: medical, dental & vision coverage; 401(k); life, accident, and disability insurance; and wellness programs. Citi also offers paid time off packages, including planned time off (vacation), unplanned time off (sick leave), and paid holidays. For additional information regarding Citi employee benefits, please visit citibenefits.com. Available offerings may vary by jurisdiction, job level, and date of hire.
---
**Most Relevant Skills**
Please see the requirements listed above.
---
**Other Relevant Skills**
For complementary skills, please see above and/or contact the recruiter.
---
**Anticipated Posting Close Date:**
Oct 27, 2025
---
_Citi is an equal opportunity employer, and qualified candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by law._
_If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review Accessibility at Citi ( ._
_View Citi's EEO Policy Statement ( and the Know Your Rights ( poster._
Citi is an equal opportunity and affirmative action employer.
Minority/Female/Veteran/Individuals with Disabilities/Sexual Orientation/Gender Identity.
View Now

Security Guard Leadership Academy

76262 Santa Rosa, Texas Allied Universal

Posted 16 days ago

Job Viewed

Tap Again To Close

Job Description

**Company Overview:**
Allied Universal®, North America's leading security and facility services company, offers rewarding careers that provide you a sense of purpose. While working in a dynamic, welcoming, and collaborative workplace, you will be part of a team that contributes to a culture that positively impacts the communities and customers we serve. We offer a comprehensive benefits package that may include medical, dental, and vision coverage, life insurance, a retirement plan, employee assistance programs, company discounts, and other perks, depending on the position and eligibility.
**Job Description:**
As a Security Guard, you will serve and safeguard clients in a range of industries such as Commercial Real Estate, Healthcare, Education, Government and more.
**Responsibilities:**
+ Provide customer service to our clients by carrying out safety and security procedures, site-specific policies and when appropriate, emergency response activities
+ Respond to incidents and critical situations in a calm, problem solving manner
+ Conduct regular and random patrols around the business and perimeter. Working environments and conditions may vary by client site.
**Minimum Requirements:**
+ Be at least 18 years of age for unarmed roles; 21+ years of age for armed roles
+ Possess a high school diploma or equivalent, or 5 years of verifiable experience
+ As a condition of employment, applicants will be subject to a background investigation in accordance with all federal, state, and local laws. Allied Universal will consider qualified applications with criminal histories in a manner consistent with applicable laws.
+ As a condition of employment, applicants will be subject to a drug screen to the extent permitted by law.
+ Licensing requirements are subject to state and/or local laws and regulations and may be required prior to employment.*A valid driver's license will be required for driving positions only
**Perks and Benefits:**
+ Health insurance and 401k plans for full-time positions
+ Schedules that fit with your personal life goals
+ Ongoing paid training programs and career growth opportunities
+ Employee discounts through our perks program to your favorite restaurants, entertainment venues and much more.
Allied Universal® is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race/ethnicity, age, color, religion, sex, sexual orientation, gender identity, national origin, genetic information, disability, protected veteran status or relationship/association with a protected veteran, or any other basis or characteristic protected by law. For more information: you have any questions regarding Equal Employment Opportunity, have difficulty using the online system and require an alternate method to apply, or require an accommodation at any time during the recruitment and/or employment process, please contact our local Human Resources department. To find an office near you, please visit: Universal® is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race/ethnicity, age, color, religion, sex, sexual orientation, gender identity, national origin, genetic information, disability, protected veteran status or relationship/association with a protected veteran, or any other basis or characteristic protected by law. For more information: you have any questions regarding Equal Employment Opportunity, have difficulty using the online system and require an alternate method to apply, or require an accommodation at any time during the recruitment and/or employment process, please contact our local Human Resources department. To find an office near you, please visit: ID:**
**Location:** United States-Texas-Westlake
**Job Category:** Security Officer, Security Guard
View Now

Cyber Security Technical Advisor (GRC) - AVP

07390 Jersey City, New Jersey MUFG

Posted 9 days ago

Job Viewed

Tap Again To Close

Job Description

Do you want your voice heard and your actions to count?

Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world's leading financial groups. Across the globe, we're 120,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.

With a vision to be the world's most trusted financial group, it's part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.

Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.

The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details.

Job Summary:

This role is a member of the CISO of America's team and will provide control design guidance and conduct independent control assessments within the Cybersecurity GRC function. The primary focus will be on the design, implementation, and testing of security controls, ensuring that technical systems and information assets are appropriately protected within the Cloud and on-prem environments. The role also emphasizes comprehensive risk management, including the identification, assessment, and management of inherent, control, and residual risks.

Primary Responsibilities:

Regulatory and Compliance

  • Maintain a high degree of knowledge with current and proposed security changes impacting regulatory, privacy, and security industry best practice guidance, leveraging technological solutions to meet enterprise needs.

  • Evaluate the extent to which the first line of defense is aligned with internal and external control standards, as well as regulatory and audit requirements.

Communication and Guidance

  • Provide clear and consistent communications to lines of business related to cybersecurity topics. Guide the lines of business through assessments, translating the technology/security questions so that they can be understood by the business; then guide them as to how to gather the required information.

Risk Management and Control

  • Ensure that internal controls designed to mitigate technology and cyber risks are managed, mitigated, and commensurate with the business risk.

  • Support Information Security oversight and governance by ensuring the control environment is monitored through relevant KRI/KPIs.

  • Ensure gaps are addressed via remediation plans with timely resolution which address root cause of control failures.

Reporting

  • Compile and distribute program level reporting to relevant stakeholders.

Implementation and Sustainability

  • Drive implementation, sustainability, and maturity of the firm's Information Security control framework.

Qualifications:

  • Experience: Minimum of 5-7 years' experience in a combination of risk management, information security, and IT roles. Prior audit experience a plus. High technical knowledge across Cybersecurity domains such as Identity Access Management, Data Security, Configuration Management, Log Generation, Incident Response, security risk assessment/testing methodologies, Secure Software Development Lifecycle, evaluating the adequacy and efficiency of internal controls; and identifying issues resulting from internal and/or external compliance examinations especially in cloud environments.

  • Cloud Security: In-depth knowledge of cloud security practices and technologies for major providers.

  • Documentation: Experience in writing process documentation and designing/executing control test scripts.

  • Regulatory Knowledge: Knowledge of domestic and international banking regulations (Reg W, Basel II, FFIEC, GDPR, etc.) and experience with enforcement agencies oversight activities (regulatory examinations, matters requiring attention (MRAs), consent orders, etc.) within a global systemically important financial institution's information technology and information security environments.

  • Technical Understanding: Understanding of the regulatory environment and regulations related to technology risk, and Office of the Comptroller of the Currency (OCC) and Federal Reserve Board (FRB) expectations.

  • Certifications: Professional certifications such as CCAK, CISA, CRISC, CISM, CGEIT, CSX, CISSP.

  • Collaboration: Ability to constructively work both independently and in collaborative environments involving all levels of management and employees.

  • Multitasking: Ability to manage multiple priorities concurrently, prioritize, and efficiently complete responsibilities while maintaining the highest quality.

  • Education: Bachelor's degree in related IT or Information Security disciplines.

  • Skills: Excellent analytical, organizational, and conceptual skills. Excellent oral and written communication skills.

Education & Certifications:

  • Bachelor's degree in Information Security or a closely related discipline, or equivalent related experience

The typical base pay range for this role is between $110K - $135K depending on job-related knowledge, skills, experience and location. This role may also be eligible for certain discretionary performance-based bonus and/or incentive compensation. Additionally, our Total Rewards program provides colleagues with a competitive benefits package (in accordance with the eligibility requirements and respective terms of each) that includes comprehensive health and wellness benefits, retirement plans, educational assistance and training programs, income replacement for qualified employees with disabilities, paid maternity and parental bonding leave, and paid vacation, sick days, and holidays. For more information on our Total Rewards package, please click the link below.

MUFG Benefits Summary (

We will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws (including (i) the San Francisco Fair Chance Ordinance, (ii) the City of Los Angeles' Fair Chance Initiative for Hiring Ordinance, (iii) the Los Angeles County Fair Chance Ordinance, and (iv) the California Fair Chance Act) to the extent that (a) an applicant is not subject to a statutory disqualification pursuant to Section 3(a)(39) of the Securities and Exchange Act of 1934 or Section 8a(2) or 8a(3) of the Commodity Exchange Act, and (b) they do not conflict with the background screening requirements of the Financial Industry Regulatory Authority (FINRA) and the National Futures Association (NFA). The major responsibilities listed above are the material job duties of this role for which the Company reasonably believes that criminal history may have a direct, adverse and negative relationship potentially resulting in the withdrawal of conditional offer of employment, if any.

The above statements are intended to describe the general nature and level of work being performed. They are not intended to be construed as an exhaustive list of all responsibilities duties and skills required of personnel so classified.

We are proud to be an Equal Opportunity Employer and committed to leveraging the diverse backgrounds, perspectives and experience of our workforce to create opportunities for our colleagues and our business. We do not discriminate on the basis of race, color, national origin, religion, gender expression, gender identity, sex, age, ancestry, marital status, protected veteran and military status, disability, medical condition, sexual orientation, genetic information, or any other status of an individual or that individual's associates or relatives that is protected under applicable federal, state, or local law.

At MUFG, our colleagues are our greatest assets. Our Culture Principles provide a roadmap for how each of our colleagues must think and act to become more client-obsessed, inclusive and innovative. They reflect who we are, who we want to be and what we expect from one another. We are excited to see you take the next step in exploring a career with us and encourage you to spend more time reviewing them!

Our Culture Principles

  • Client Centric

  • People Focused

  • Listen Up. Speak Up.

  • Innovate & Simplify

  • Own & Execute

View Now

Cyber Security Technical Advisor (GRC) - AVP

33603 Tampa, Florida MUFG

Posted 2 days ago

Job Viewed

Tap Again To Close

Job Description

**Do you want your voice heard and your actions to count?**
Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world's leading financial groups. Across the globe, we're 120,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.
With a vision to be the world's most trusted financial group, it's part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.
Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.
The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details.
**Job Summary:**
This role is a member of the CISO of America's team and will provide control design guidance and conduct independent control assessments within the Cybersecurity GRC function. The primary focus will be on the design, implementation, and testing of security controls, ensuring that technical systems and information assets are appropriately protected within the Cloud and on-prem environments. The role also emphasizes comprehensive risk management, including the identification, assessment, and management of inherent, control, and residual risks.
**Primary Responsibilities:**
**Regulatory and Compliance**
+ Maintain a high degree of knowledge with current and proposed security changes impacting regulatory, privacy, and security industry best practice guidance, leveraging technological solutions to meet enterprise needs.
+ Evaluate the extent to which the first line of defense is aligned with internal and external control standards, as well as regulatory and audit requirements.
**Communication and Guidance**
+ Provide clear and consistent communications to lines of business related to cybersecurity topics. Guide the lines of business through assessments, translating the technology/security questions so that they can be understood by the business; then guide them as to how to gather the required information.
**Risk Management and Control**
+ Ensure that internal controls designed to mitigate technology and cyber risks are managed, mitigated, and commensurate with the business risk.
+ Support Information Security oversight and governance by ensuring the control environment is monitored through relevant KRI/KPIs.
+ Ensure gaps are addressed via remediation plans with timely resolution which address root cause of control failures.
**Reporting**
+ Compile and distribute program level reporting to relevant stakeholders.
**Implementation and Sustainability**
+ Drive implementation, sustainability, and maturity of the firm's Information Security control framework.
**Qualifications:**
+ **Experience:** Minimum of 5-7 years' experience in a combination of risk management, information security, and IT roles. Prior audit experience a plus. High technical knowledge across Cybersecurity domains such as Identity Access Management, Data Security, Configuration Management, Log Generation, Incident Response, security risk assessment/testing methodologies, Secure Software Development Lifecycle, evaluating the adequacy and efficiency of internal controls; and identifying issues resulting from internal and/or external compliance examinations especially in cloud environments.
+ **Cloud Security:** In-depth knowledge of cloud security practices and technologies for major providers.
+ **Documentation:** Experience in writing process documentation and designing/executing control test scripts.
+ **Regulatory Knowledge:** Knowledge of domestic and international banking regulations (Reg W, Basel II, FFIEC, GDPR, etc.) and experience with enforcement agencies oversight activities (regulatory examinations, matters requiring attention (MRAs), consent orders, etc.) within a global systemically important financial institution's information technology and information security environments.
+ **Technical Understanding:** Understanding of the regulatory environment and regulations related to technology risk, and Office of the Comptroller of the Currency (OCC) and Federal Reserve Board (FRB) expectations.
+ **Certifications:** Professional certifications such as CCAK, CISA, CRISC, CISM, CGEIT, CSX, CISSP.
+ **Collaboration:** Ability to constructively work both independently and in collaborative environments involving all levels of management and employees.
+ **Multitasking:** Ability to manage multiple priorities concurrently, prioritize, and efficiently complete responsibilities while maintaining the highest quality.
+ **Education:** Bachelor's degree in related IT or Information Security disciplines.
+ **Skills:** Excellent analytical, organizational, and conceptual skills. Excellent oral and written communication skills.
**Education & Certifications:**
+ Bachelor's degree in Information Security or a closely related discipline, or equivalent related experience
The typical base pay range for this role is between $110K - $135K depending on job-related knowledge, skills, experience and location. This role may also be eligible for certain discretionary performance-based bonus and/or incentive compensation. Additionally, our Total Rewards program provides colleagues with a competitive benefits package (in accordance with the eligibility requirements and respective terms of each) that includes comprehensive health and wellness benefits, retirement plans, educational assistance and training programs, income replacement for qualified employees with disabilities, paid maternity and parental bonding leave, and paid vacation, sick days, and holidays. For more information on our Total Rewards package, please click the link below.
MUFG Benefits Summary ( will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws (including (i) the San Francisco Fair Chance Ordinance, (ii) the City of Los Angeles' Fair Chance Initiative for Hiring Ordinance, (iii) the Los Angeles County Fair Chance Ordinance, and (iv) the California Fair Chance Act) to the extent that (a) an applicant is not subject to a statutory disqualification pursuant to Section 3(a)(39) of the Securities and Exchange Act of 1934 or Section 8a(2) or 8a(3) of the Commodity Exchange Act, and (b) they do not conflict with the background screening requirements of the Financial Industry Regulatory Authority (FINRA) and the National Futures Association (NFA). The major responsibilities listed above are the material job duties of this role for which the Company reasonably believes that criminal history may have a direct, adverse and negative relationship potentially resulting in the withdrawal of conditional offer of employment, if any.
The above statements are intended to describe the general nature and level of work being performed. They are not intended to be construed as an exhaustive list of all responsibilities duties and skills required of personnel so classified.
We are proud to be an Equal Opportunity Employer and committed to leveraging the diverse backgrounds, perspectives and experience of our workforce to create opportunities for our colleagues and our business. We do not discriminate on the basis of race, color, national origin, religion, gender expression, gender identity, sex, age, ancestry, marital status, protected veteran and military status, disability, medical condition, sexual orientation, genetic information, or any other status of an individual or that individual's associates or relatives that is protected under applicable federal, state, or local law.
At MUFG, our colleagues are our greatest assets. Our Culture Principles provide a roadmap for how each of our colleagues must think and act to become more client-obsessed, inclusive and innovative. They reflect who we are, who we want to be and what we expect from one another. We are excited to see you take the next step in exploring a career with us and encourage you to spend more time reviewing them!
**Our Culture Principles**
+ Client Centric
+ People Focused
+ Listen Up. Speak Up.
+ Innovate & Simplify
+ Own & Execute
View Now
Be The First To Know

About the latest Avp security Jobs in United States !

Cyber Security Technical Advisor (GRC) - AVP

85282 Tempe, Arizona MUFG

Posted 2 days ago

Job Viewed

Tap Again To Close

Job Description

**Do you want your voice heard and your actions to count?**
Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world's leading financial groups. Across the globe, we're 120,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.
With a vision to be the world's most trusted financial group, it's part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.
Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.
The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details.
**Job Summary:**
This role is a member of the CISO of America's team and will provide control design guidance and conduct independent control assessments within the Cybersecurity GRC function. The primary focus will be on the design, implementation, and testing of security controls, ensuring that technical systems and information assets are appropriately protected within the Cloud and on-prem environments. The role also emphasizes comprehensive risk management, including the identification, assessment, and management of inherent, control, and residual risks.
**Primary Responsibilities:**
**Regulatory and Compliance**
+ Maintain a high degree of knowledge with current and proposed security changes impacting regulatory, privacy, and security industry best practice guidance, leveraging technological solutions to meet enterprise needs.
+ Evaluate the extent to which the first line of defense is aligned with internal and external control standards, as well as regulatory and audit requirements.
**Communication and Guidance**
+ Provide clear and consistent communications to lines of business related to cybersecurity topics. Guide the lines of business through assessments, translating the technology/security questions so that they can be understood by the business; then guide them as to how to gather the required information.
**Risk Management and Control**
+ Ensure that internal controls designed to mitigate technology and cyber risks are managed, mitigated, and commensurate with the business risk.
+ Support Information Security oversight and governance by ensuring the control environment is monitored through relevant KRI/KPIs.
+ Ensure gaps are addressed via remediation plans with timely resolution which address root cause of control failures.
**Reporting**
+ Compile and distribute program level reporting to relevant stakeholders.
**Implementation and Sustainability**
+ Drive implementation, sustainability, and maturity of the firm's Information Security control framework.
**Qualifications:**
+ **Experience:** Minimum of 5-7 years' experience in a combination of risk management, information security, and IT roles. Prior audit experience a plus. High technical knowledge across Cybersecurity domains such as Identity Access Management, Data Security, Configuration Management, Log Generation, Incident Response, security risk assessment/testing methodologies, Secure Software Development Lifecycle, evaluating the adequacy and efficiency of internal controls; and identifying issues resulting from internal and/or external compliance examinations especially in cloud environments.
+ **Cloud Security:** In-depth knowledge of cloud security practices and technologies for major providers.
+ **Documentation:** Experience in writing process documentation and designing/executing control test scripts.
+ **Regulatory Knowledge:** Knowledge of domestic and international banking regulations (Reg W, Basel II, FFIEC, GDPR, etc.) and experience with enforcement agencies oversight activities (regulatory examinations, matters requiring attention (MRAs), consent orders, etc.) within a global systemically important financial institution's information technology and information security environments.
+ **Technical Understanding:** Understanding of the regulatory environment and regulations related to technology risk, and Office of the Comptroller of the Currency (OCC) and Federal Reserve Board (FRB) expectations.
+ **Certifications:** Professional certifications such as CCAK, CISA, CRISC, CISM, CGEIT, CSX, CISSP.
+ **Collaboration:** Ability to constructively work both independently and in collaborative environments involving all levels of management and employees.
+ **Multitasking:** Ability to manage multiple priorities concurrently, prioritize, and efficiently complete responsibilities while maintaining the highest quality.
+ **Education:** Bachelor's degree in related IT or Information Security disciplines.
+ **Skills:** Excellent analytical, organizational, and conceptual skills. Excellent oral and written communication skills.
**Education & Certifications:**
+ Bachelor's degree in Information Security or a closely related discipline, or equivalent related experience
The typical base pay range for this role is between $110K - $135K depending on job-related knowledge, skills, experience and location. This role may also be eligible for certain discretionary performance-based bonus and/or incentive compensation. Additionally, our Total Rewards program provides colleagues with a competitive benefits package (in accordance with the eligibility requirements and respective terms of each) that includes comprehensive health and wellness benefits, retirement plans, educational assistance and training programs, income replacement for qualified employees with disabilities, paid maternity and parental bonding leave, and paid vacation, sick days, and holidays. For more information on our Total Rewards package, please click the link below.
MUFG Benefits Summary ( will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws (including (i) the San Francisco Fair Chance Ordinance, (ii) the City of Los Angeles' Fair Chance Initiative for Hiring Ordinance, (iii) the Los Angeles County Fair Chance Ordinance, and (iv) the California Fair Chance Act) to the extent that (a) an applicant is not subject to a statutory disqualification pursuant to Section 3(a)(39) of the Securities and Exchange Act of 1934 or Section 8a(2) or 8a(3) of the Commodity Exchange Act, and (b) they do not conflict with the background screening requirements of the Financial Industry Regulatory Authority (FINRA) and the National Futures Association (NFA). The major responsibilities listed above are the material job duties of this role for which the Company reasonably believes that criminal history may have a direct, adverse and negative relationship potentially resulting in the withdrawal of conditional offer of employment, if any.
The above statements are intended to describe the general nature and level of work being performed. They are not intended to be construed as an exhaustive list of all responsibilities duties and skills required of personnel so classified.
We are proud to be an Equal Opportunity Employer and committed to leveraging the diverse backgrounds, perspectives and experience of our workforce to create opportunities for our colleagues and our business. We do not discriminate on the basis of race, color, national origin, religion, gender expression, gender identity, sex, age, ancestry, marital status, protected veteran and military status, disability, medical condition, sexual orientation, genetic information, or any other status of an individual or that individual's associates or relatives that is protected under applicable federal, state, or local law.
At MUFG, our colleagues are our greatest assets. Our Culture Principles provide a roadmap for how each of our colleagues must think and act to become more client-obsessed, inclusive and innovative. They reflect who we are, who we want to be and what we expect from one another. We are excited to see you take the next step in exploring a career with us and encourage you to spend more time reviewing them!
**Our Culture Principles**
+ Client Centric
+ People Focused
+ Listen Up. Speak Up.
+ Innovate & Simplify
+ Own & Execute
View Now

Cyber Security Technical Advisor (GRC) - AVP

07308 Jersey City, New Jersey MUFG

Posted 16 days ago

Job Viewed

Tap Again To Close

Job Description

**Do you want your voice heard and your actions to count?**
Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world's leading financial groups. Across the globe, we're 120,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.
With a vision to be the world's most trusted financial group, it's part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.
Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.
The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details.
**Job Summary:**
This role is a member of the CISO of America's team and will provide control design guidance and conduct independent control assessments within the Cybersecurity GRC function. The primary focus will be on the design, implementation, and testing of security controls, ensuring that technical systems and information assets are appropriately protected within the Cloud and on-prem environments. The role also emphasizes comprehensive risk management, including the identification, assessment, and management of inherent, control, and residual risks.
**Primary Responsibilities:**
**Regulatory and Compliance**
+ Maintain a high degree of knowledge with current and proposed security changes impacting regulatory, privacy, and security industry best practice guidance, leveraging technological solutions to meet enterprise needs.
+ Evaluate the extent to which the first line of defense is aligned with internal and external control standards, as well as regulatory and audit requirements.
**Communication and Guidance**
+ Provide clear and consistent communications to lines of business related to cybersecurity topics. Guide the lines of business through assessments, translating the technology/security questions so that they can be understood by the business; then guide them as to how to gather the required information.
**Risk Management and Control**
+ Ensure that internal controls designed to mitigate technology and cyber risks are managed, mitigated, and commensurate with the business risk.
+ Support Information Security oversight and governance by ensuring the control environment is monitored through relevant KRI/KPIs.
+ Ensure gaps are addressed via remediation plans with timely resolution which address root cause of control failures.
**Reporting**
+ Compile and distribute program level reporting to relevant stakeholders.
**Implementation and Sustainability**
+ Drive implementation, sustainability, and maturity of the firm's Information Security control framework.
**Qualifications:**
+ **Experience:** Minimum of 5-7 years' experience in a combination of risk management, information security, and IT roles. Prior audit experience a plus. High technical knowledge across Cybersecurity domains such as Identity Access Management, Data Security, Configuration Management, Log Generation, Incident Response, security risk assessment/testing methodologies, Secure Software Development Lifecycle, evaluating the adequacy and efficiency of internal controls; and identifying issues resulting from internal and/or external compliance examinations especially in cloud environments.
+ **Cloud Security:** In-depth knowledge of cloud security practices and technologies for major providers.
+ **Documentation:** Experience in writing process documentation and designing/executing control test scripts.
+ **Regulatory Knowledge:** Knowledge of domestic and international banking regulations (Reg W, Basel II, FFIEC, GDPR, etc.) and experience with enforcement agencies oversight activities (regulatory examinations, matters requiring attention (MRAs), consent orders, etc.) within a global systemically important financial institution's information technology and information security environments.
+ **Technical Understanding:** Understanding of the regulatory environment and regulations related to technology risk, and Office of the Comptroller of the Currency (OCC) and Federal Reserve Board (FRB) expectations.
+ **Certifications:** Professional certifications such as CCAK, CISA, CRISC, CISM, CGEIT, CSX, CISSP.
+ **Collaboration:** Ability to constructively work both independently and in collaborative environments involving all levels of management and employees.
+ **Multitasking:** Ability to manage multiple priorities concurrently, prioritize, and efficiently complete responsibilities while maintaining the highest quality.
+ **Education:** Bachelor's degree in related IT or Information Security disciplines.
+ **Skills:** Excellent analytical, organizational, and conceptual skills. Excellent oral and written communication skills.
**Education & Certifications:**
+ Bachelor's degree in Information Security or a closely related discipline, or equivalent related experience
The typical base pay range for this role is between $110K - $135K depending on job-related knowledge, skills, experience and location. This role may also be eligible for certain discretionary performance-based bonus and/or incentive compensation. Additionally, our Total Rewards program provides colleagues with a competitive benefits package (in accordance with the eligibility requirements and respective terms of each) that includes comprehensive health and wellness benefits, retirement plans, educational assistance and training programs, income replacement for qualified employees with disabilities, paid maternity and parental bonding leave, and paid vacation, sick days, and holidays. For more information on our Total Rewards package, please click the link below.
MUFG Benefits Summary ( will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws (including (i) the San Francisco Fair Chance Ordinance, (ii) the City of Los Angeles' Fair Chance Initiative for Hiring Ordinance, (iii) the Los Angeles County Fair Chance Ordinance, and (iv) the California Fair Chance Act) to the extent that (a) an applicant is not subject to a statutory disqualification pursuant to Section 3(a)(39) of the Securities and Exchange Act of 1934 or Section 8a(2) or 8a(3) of the Commodity Exchange Act, and (b) they do not conflict with the background screening requirements of the Financial Industry Regulatory Authority (FINRA) and the National Futures Association (NFA). The major responsibilities listed above are the material job duties of this role for which the Company reasonably believes that criminal history may have a direct, adverse and negative relationship potentially resulting in the withdrawal of conditional offer of employment, if any.
The above statements are intended to describe the general nature and level of work being performed. They are not intended to be construed as an exhaustive list of all responsibilities duties and skills required of personnel so classified.
We are proud to be an Equal Opportunity Employer and committed to leveraging the diverse backgrounds, perspectives and experience of our workforce to create opportunities for our colleagues and our business. We do not discriminate on the basis of race, color, national origin, religion, gender expression, gender identity, sex, age, ancestry, marital status, protected veteran and military status, disability, medical condition, sexual orientation, genetic information, or any other status of an individual or that individual's associates or relatives that is protected under applicable federal, state, or local law.
At MUFG, our colleagues are our greatest assets. Our Culture Principles provide a roadmap for how each of our colleagues must think and act to become more client-obsessed, inclusive and innovative. They reflect who we are, who we want to be and what we expect from one another. We are excited to see you take the next step in exploring a career with us and encourage you to spend more time reviewing them!
**Our Culture Principles**
+ Client Centric
+ People Focused
+ Listen Up. Speak Up.
+ Innovate & Simplify
+ Own & Execute
View Now

Information Security Management System Lead

80238 Denver, Colorado Generac Power Systems

Posted 2 days ago

Job Viewed

Tap Again To Close

Job Description

**We are Generac, a leading energy technology company committed to powering a smarter world.**
Over the 60 plus years of Generac's history, we've been dedicated to energy innovation. From creating the home standby generator market category, to our current evolution into an energy technology solutions company, we continue to push new boundaries.
The ISMS Lead coordinates and maintains the daily operations of the Information Security Management System (ISMS) Program, ensuring compliance with ISO27001 and alignment with Generac's broader cybersecurity and compliance frameworks. The ISMS lead is the central point of contact for cross-functional control owners, capability teams, and audit stakeholders-supporting evidence collection, risk and control tracking, and the orchestration of ISMS-related deliverables across both internal ISMS assessments and external ISO27001 audits.
The ISMS Lead drives operational excellence through governance coordination, audit readiness, and performance monitoring. This includes facilitating working groups, tracking the Statement of Applicability (SoA), risk register updates, and corrective action plans. The role supports both corporate and subsidiary teams in implementing and sustaining ISMS requirements, helping to foster a culture of compliance and continuous improvement across the organization.
**Major Responsibilities**
+ Coordinates the day-to-day operations of the Information Security Management System (ISMS), ensuring alignment with ISO27001 and Generac's unified governance and compliance frameworks
+ Maintains the GRC platform, supporting timely delivery of compliance activities across policy owners, control implementers, and evidence contributors
+ Facilitates internal ISMS assessments, committee meetings, and working group sessions by preparing agendas, tracking action items, and reporting compliance progress
+ Supports capability teams, subsidiaries, and control owners by clarifying implementation expectations, audit documentation needs, and evidence quality standards
+ Tracks and manages the lifecycle of risks, controls, and corrective actions, including updates to the risk register and the Statement of Applicability (SoA)
+ Coordinate ISMS readiness efforts in preparation for external ISO27001 audits or other applicable certification assessments
+ Develops and refines ISMS-related documentation, including procedures, guidelines, control narratives, and support materials
+ Maintains dashboards and performance metrics related to audit readiness, non-conformity closure, and risk treatment activities
+ Identifies bottlenecks, overdue tasks, and control misalignments, escalating as needed to the IT GRC Capability Manager or Director of InfoSec
+ Ensures consistent version control, evidence traceability, and document quality across all submissions in support of audits or assessments
+ Collaborates with Capability Teams and subsidiaries to ensure control implementation aligns with policy and framework expectations
+ Monitors developments in ISO27001:2022, privacy regulations, and industry best practices to continuously improve the ISMS model and processes
+ Supports onboarding and enablement of new ISMS participants, including training on stakeholder roles, tool usage, and evidence responsibilities
+ Coordinates internal evidence gathering for ISMS assessments and external audits, including document requests, stakeholder interviews, and audit walkthrough preparation
**Minimum Job Requirements**
**Education**
+ Bachelor's Degree with Information Technology focus, or equivalent experience
**Work Experience**
+ 5 years experience in Information Security Management Systems or Cyber Security.
+ Proven experience supporting or coordinating ISO27001 compliance or certification efforts.
+ Experience working within a multi-framework compliance program (e.g., ISO27001, NIST, SOC 2, PCI, GDPR).
+ Understanding of risk assessment methodologies, control mapping, and evidence management practices.
+ Experience with GRC platforms, able to apply prior learnings to new GRC tools.
+ Experience with cross functional coordination, providing guidance to teams across IT and business functions
**Knowledge / Skills / Abilities**
+ Familiarity with cloud service models and control responsibilities in SaaS/PaaS/IaaS environments
+ Strong coordination, documentation, and communication skills for multi-stakeholder collaboration
+ Familiarity with unified control framework initiatives or crosswalks across security and privacy standards
+ Understanding of how compliance maps to internal business processes and capability team structures
+ Ability to coordinate evidence requests, policy updates, and SoA changes in a dynamic environment
+ Experience maintaining compliance metrics, dashboards, or remediation tracking reports
+ Knowledge of key control areas such as access control, data protection, vulnerability management, and incident response
**Preferred Job Requirements**
**Certification / License**
+ Certifications preferred: ISO27001 Lead Implementer or Auditor, CISA, CISSP, CISM, or SCF Certified Practitioner
**Great Reasons to work for Generac**
+ Competitive Benefits: Health, Dental, Vision, 401k and many more
+ Pride! When a storm strikes, Generac employees always rise to the occasion. Each time a storm hits, many employees volunteer their time with the customer support team or on the production line, while others go right into storm-affected areas to repair generators
+ Make a positive impact. Generac has always been community-minded and dedicated to giving back. The company proudly offers a Volunteer Time Off program, inviting team members to participate in charitable volunteer opportunities on company time.
+ We're an inclusive company that celebrates differences and keeps equity and respect at the forefront.
**Compensation:** Generac is committed to fair and equitable compensation practices. The salary range for this role when based in Colorado or California is $120,000 to $150,000. This compensation will ultimately be in line with the location in which the position is filled. Final compensation for this role will be determined by various factors such as a candidate's relevant work experience, skills, certifications, and geographic location.
**Physical Demands** : While performing the duties of this job, the employee is regularly required to talk and hear; and use hands to manipulate objects or controls. The employee is regularly required to stand and walk. On occasion the incumbent may be required to stoop, bend or reach above the shoulders. The employee must occasionally lift up to 25 - 50 pounds. Specific conditions of this job are typical of frequent and continuous computer-based work requiring periods of sitting, close vision and ability to adjust focus. Occasional travel.
_"We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, national origin, disability status, protected veteran status, or any other characteristic protected by law."_
Over the 60 plus years of Generac's history, we've been dedicated to energy innovation. From creating the home standby generator market category, to our current evolution into an energy technology solutions company, we continue to push new boundaries.
As one of the leaders and largest suppliers of power generation equipment and technology, the work we do touches millions of lives. Employees at Generac are encouraged to be innovative and are valued as an integral part of our global team. Our challenging goals develop knowledgeable employees dedicated to helping continue Generac's success. Generac provides individuals the opportunity to work in a fast-paced agile work environment where their work makes a difference in people's lives and their own.
View Now
 

Nearby Locations

Other Jobs Near Me

Industry

  1. request_quote Accounting
  2. work Administrative
  3. eco Agriculture Forestry
  4. smart_toy AI & Emerging Technologies
  5. school Apprenticeships & Trainee
  6. apartment Architecture
  7. palette Arts & Entertainment
  8. directions_car Automotive
  9. flight_takeoff Aviation
  10. account_balance Banking & Finance
  11. local_florist Beauty & Wellness
  12. restaurant Catering
  13. volunteer_activism Charity & Voluntary
  14. science Chemical Engineering
  15. child_friendly Childcare
  16. foundation Civil Engineering
  17. clean_hands Cleaning & Sanitation
  18. diversity_3 Community & Social Care
  19. construction Construction
  20. brush Creative & Digital
  21. currency_bitcoin Crypto & Blockchain
  22. support_agent Customer Service & Helpdesk
  23. medical_services Dental
  24. medical_services Driving & Transport
  25. medical_services E Commerce & Social Media
  26. school Education & Teaching
  27. electrical_services Electrical Engineering
  28. bolt Energy
  29. local_mall Fmcg
  30. gavel Government & Non Profit
  31. emoji_events Graduate
  32. health_and_safety Healthcare
  33. beach_access Hospitality & Tourism
  34. groups Human Resources
  35. precision_manufacturing Industrial Engineering
  36. security Information Security
  37. handyman Installation & Maintenance
  38. policy Insurance
  39. code IT & Software
  40. gavel Legal
  41. sports_soccer Leisure & Sports
  42. inventory_2 Logistics & Warehousing
  43. supervisor_account Management
  44. supervisor_account Management Consultancy
  45. supervisor_account Manufacturing & Production
  46. campaign Marketing
  47. build Mechanical Engineering
  48. perm_media Media & PR
  49. local_hospital Medical
  50. local_hospital Military & Public Safety
  51. local_hospital Mining
  52. medical_services Nursing
  53. local_gas_station Oil & Gas
  54. biotech Pharmaceutical
  55. checklist_rtl Project Management
  56. shopping_bag Purchasing
  57. home_work Real Estate
  58. person_search Recruitment Consultancy
  59. store Retail
  60. point_of_sale Sales
  61. science Scientific Research & Development
  62. wifi Telecoms
  63. psychology Therapy
  64. pets Veterinary
View All Avp Security Jobs