Associate Director of Information Security
Indexed description
Associate Director of Information Security
Location: New Haven, CT / Hybrid
Overview:
Lead and continuously improve the organization’s Information Security Governance, Risk & Compliance (GRC) program. Manage security governance, policies, risk management, compliance, audits, third-party risk, and executive reporting while partnering with IT, Legal, Privacy, Compliance, Internal Audit, and Enterprise Risk Management.
Key Responsibilities:
- Lead, mentor, and develop the Information Security GRC team.
- Develop and maintain security policies, standards, controls, and GRC roadmap.
- Manage security risk registers, exceptions, assessments, and third-party risk.
- Oversee security audits, regulatory examinations, and compliance activities.
- Align controls with NIST, NYDFS, COBIT, GDPR, CCPA, CCRA, and contractual requirements.
- Develop KPIs, dashboards, metrics, and security maturity reporting for leadership.
- Assess security risks related to cloud, new technologies, and strategic initiatives.
- Partner with Legal, Privacy, Compliance, IT, and Enterprise Risk Management.
Requirements:
- 5+ years of GRC / Information Security experience.
- Strong knowledge of NIST CSF and cybersecurity standards.
- Excellent communication, documentation, analytical, and project-management skills.
- CISSP, CISM, CRISC, or CISA preferred.
- Bachelor’s degree in Cybersecurity, Information Security, Computer Science, or related field preferred.
- Insurance/financial services experience is a plus.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search