IT Security Technical Risk Advisor
Individual contributor providing the highest level of leadership in directing, evaluating, developing, implementing, communicating, operating, monitoring and maintaining information security technologies, security policies and procedures. Provides state-of-the-art technical expertise and support in identifying risks and recommending appropriate mitigation and effective risk management processes across all aspects of information technology projects.
Essential Duties & Responsibilities
Performs a combination of duties in accordance with departmental guidelines:
- Provides technical expertise and support to clients, IT management and staff in risk assessments and the implementation and operation of appropriate information security procedures and products.
- Designs, evaluates, tests and implements appropriate security methods and control techniques such as firewalls, intrusion detection software, data encryption, data backup and recovery.
- Understand cloud security solutions and review incoming cloud projects to provide guidance and support to technical cloud teams.
- Provide guidance on cloud security standards \ policies and advise on enabling cloud native controls to meet highest cyber security standards.
- Maintains an awareness of existing and proposed security standard setting groups, State and Federal legislation and regulations pertaining to information security and data privacy.
- Identifies regulatory changes that will affect information security policy, standards and procedures and recommends appropriate changes.
- Acts as an expert technical resource to client and development management and staff in all phases of the development and implementation process.
- Develops and implements security standards, procedures and guidelines for multiple platforms and diverse systems environments (e.g., firm-wide, distributed, client server systems, and e-applications).
- Identifies emergent vulnerabilities and evaluates associated risks and threats.
- Develops communications and related campaigns for information security awareness among all staff.
- Reviews the development, testing and implementation of security plans, products and control techniques.
- Assist in investigations as needed and recommends appropriate corrective actions for information security incidents.
May perform additional duties as assigned.
Reporting Relationship
Typically Director or above
Skills, Knowledge & Abilities
- Excellent understanding of security policy construction and publication.
- Excellent knowledge of regulations (i.e., SOX, privacy, etc.) and internal controls as they apply to IT.
- Working knowledge of any of the common cloud platforms (AWS, Azure and GCP)
- Ability to influence change in corporate understanding and adoption of information security concepts.
- Advanced analytical and problem solving skills.
- Excellent communications and interpersonal skills and the ability to work effectively with peers, IT management and staff, and internal/external business partners/clients.
- Ability to manage various technical projects to completion.
- Advanced computer skills including Microsoft Office suite and other business related software systems. Other technologies will apply dependent on business area supported.
- Preferred insurance industry knowledge.
Education & Experience
- Bachelor's degree in Computer Science, or related discipline, or equivalent work experience.
- Typically a minimum of eight years of technical experience in the security aspects of multiple platforms, operating systems, software, communications and network protocols or an equivalent combination.