Principal - Cyber Security
Indexed description
Work Schedule: Ally designates roles as (1) fully on-site, (2) hybrid, or (3) fully remote. Hybrid roles are generally expected to be in the office a certain number of days per week as indicated by your manager. Your hiring manager will discuss this role's specific work requirements with you during the hiring process. All work requirements are subject to change at any time based on leader discretion and/or business need.
The Opportunity
The Principal of Cyber Security position at Ally is a member of the Information Protection and Risk Management team and works closely with other members of the IPRM program to develop and implement a comprehensive approach to the management of security risks at Ally. The Principal of Cyber Security role requires an individual with a strong technical background as well as an ability to work with the IT organization and business management to align priorities and plans with key business objectives. Responsible for providing technical guidance to staff as they work to accomplish company objectives. This is a mid-level to senior-level highly technical role.
The Work Itself
- Work with the Director of Security Operations to ensure the security program addresses identified risks and business requirements.
- Manage the process of gathering, analyzing and assessing the current and future threat landscape, as well as providing the Director of Security Operations with a realistic overview of risks and threats in the enterprise environment
- Identify process improvement opportunities and develop subsequent plans of action to resolve gaps with minimal management intervention.
- Monitor and report on compliance with security policies and standards, as well as the enforcement of policies within the IT department
- Propose changes to existing policies and procedures to ensure operating efficiency and regulatory compliance.
- Assist resource owners and IT staff in understanding and responding to security audit failures reported by auditors and regulatory bodies.
- Provide security communication, awareness and training for audiences which may range from senior leaders to field staff.
- Work as a liaison with vendors and the legal and purchasing departments to establish mutually acceptable contracts and service level agreements.
- Manage production issues and incidents and participate in problem and change management forums.
- Manage and coordinate operational components of incident management, including detection, response and reporting.
- Manage the day-to-day activities of threat and vulnerability management, identify risk tolerances, recommend treatment plans and communicate information about residual risk.
- Manage security projects and provide expert guidance on security matters for other IT projects.
- Ensure audit trails, system logs and other monitoring data sources are reviewed periodically and are in compliance with policies and audit requirements.
- Design, coordinate and oversee security testing procedures to verify the security of systems, networks and applications, and manage the remediation of identified risks
- Bachelor's degree in information systems or relevant field of study preferred
- 5+ years of IT experience with at least 3 years of focus in Information Security
- CISSP preferred
- Demonstrated experience in the identification, plan for resolution and execution of action plans for complex problems in a regulated environment.
- Familiarity with the principles of cryptography and cryptanalysis
- Extensive experience in application technology security testing
- Extensive experience in system technology security testing
Time Away: Program starts at 20 paid time off days in addition to 11 paid holidays and 8 hours of volunteer time off yearly (time off days are prorated based on start date and program varies based on full or part-time status and management level).
Planning for the Future: plan for the near and long term with an industry-leading 401K retirement savings plan with matching and company contributions, student loan pay downs and 529 educational save up assistance programs, tuition reimbursement, employee stock purchase plan, and financial learning center and financial coach access.
Supporting your Health & Well-being: flexible health and insurance options including medical, dental and vision, employee, spouse and child life insurance, short- and long-term disability, pre-tax Health Savings Account with employer contributions, Healthcare FSA, critical illness, accident & hospital indemnity insurance, and a total well-being program that helps you and your family stay on track physically, socially, emotionally, and financially.
Building a Family: adoption, surrogacy and fertility assistance as well as paid parental and caregiver leave, Dependent Day Care FSA back-up child and adult/elder care days and childcare discounts.
Work-Life Integration: other benefits including Mentally Fit Employee Assistance Program, subsidized and discounted Weight Watchers® program and other employee discount programs.
Other Compensations: depending on the role for which you are considered, you may be eligible for travel allowances, relocation assistance, a signing bonus and/or equity.
To view more detailed information about Ally’s Total Rewards, please visit this link: https://www.ally.com/content/dam/pdf/corporate/ally-total-rewards-snapshot.pdf
Who We Are
Ally Financial is a customer-centric, leading digital financial services company with passionate customer service and innovative financial solutions. We are relentlessly focused on "Doing it Right" and being a trusted financial-services provider to our consumer, commercial, and corporate customers. For more information, visit www.ally.com.
Ally is an equal opportunity employer committed to diversity and inclusion in the workplace. All qualified applicants will receive consideration for employment without regard to age, race, color, sex, religion, national origin, disability, sexual orientation, gender identity or expression, pregnancy status, marital status, military or veteran status, genetic disposition or any other reason protected by law.
In accordance with the Americans with Disabilities Act, if after review of the position expectations, you believe that you may need a medical accommodation to fulfill the duties of this role, please email [email protected] with details of your accommodation request.
Base Pay Range
$110,000.00 - $180,000.00
An individual's position in the range is determined by the specific role, the scope and responsibilities of the role, work experience, education, certification(s), training, and additional qualifications. We review internal pay, the competitive market, and business environment prior to extending an offer.
Incentive Compensation
This position is eligible to participate in our annual incentive plan.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search