> Markdown version of [/jobs/ext/2043067-lead-information-security-library-standards](https://www.wearedevelopers.com/jobs/ext/2043067-lead-information-security-library-standards). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead, Information Security Library & Standards - **Company:** Prudential Financial, Inc. - **Location:** Newark, NJ, United States (Remote available) - **Experience:** Expert - **Salary:** $114,500.0 - $188,900.0 - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, Cyber Security, Information Systems, Identity and Access Management, Software Vulnerability Management, Information Technology, RSA Archer Platform, Cyber Warfare - **Published:** August 13, 2026 - **Apply:** https://pru.wd5.myworkdayjobs.com/Careers/job/Newark-NJ-USA/Lead--Information-Security-Library---Standards_R-124781-1 ## About the Role * Bachelor's degree or equivalent experience in Cybersecurity, Computer Science, Information Security, Risk Management, Information Systems, Business, a related field or equivalent experience. * Experience building or maintaining security governance, control frameworks, compliance programs, or risk management initiatives. * Strong understanding of frameworks such as NIST, ISO 27001, FFIEC, NYDFS, SOC, or related standards. * Working knowledge of one or more security domains such as IAM, Cloud Security, Data Protection, Vulnerability Management, Attack Surface Management, or Cyber Defense. * Experience designing governance processes, operating models, ownership structures, quality gates, lifecycle processes and control documentation. * Strong communication, documentation, and stakeholder management skills. * Ability to collaborate effectively across security, risk, compliance, technology, business, and audit teams. Preferred Qualifications * Experience building or enhancing security control libraries, standards programs, workflow improvements or governance frameworks or Governance, Risk, and Compliance (GRC) tooling. * Experience supporting audits, examinations, compliance reviews, or risk assessments. * Familiarity with GRC platforms and governance tooling. * CISSP, CISM, CRISC, CISA, or similar certifications. #LI-Hybrid #LI-LR1 ## Description As the Lead, Information Security Library & Standards, you will help build the foundation that supports Information Security governance across Prudential. This is a unique opportunity to help build and shape a growing Information Security Governance capability, with visibility across senior leadership and the ability to influence how security, risk, and governance are executed across the enterprise. Reporting to the Director of Information Security Governance, you'll partner closely with Risk Management and Information Security leaders to establish a scalable control library, mature security standards, and create the governance processes needed to support a consistent, practical, and audit-ready security program. This role is based in our office in Newark, NJ. Our organization follows a hybrid work structure where employees can work remotely and from the office, as needed, based on demands of specific tasks or personal work preferences. This position is hybrid and requires your on-site presence on a reoccurring weekly basis at least 3 days per week. Here is What You Can Expect on a Typical Day Build & Govern the Information Security Control Library * Lead the development, enhancement, and ongoing governance of Prudential's Information Security control library, ensuring consistency, traceability, and alignment with enterprise risk and compliance objectives. * Define and maintain control taxonomy, ownership models, framework mappings, evidence requirements, control narratives, and governance standards. * Establish traceability across security standards, controls, regulatory requirements, risks, testing activities, evidence repositories, and reporting processes. * Partner with Information Security domain leaders across Identity & Access Management (IAM), Attack Surface Management (ASM), Cyber Defense & Response (CDR), cloud security, data protection, vulnerability management, and other security control functions to ensure controls accurately reflect current risks, technologies, and operational requirements. Drive Standards Management, Governance & Regulatory Alignment * Coordinate the lifecycle management of Information Security standards, including creation, review, approval, publication, maintenance, and retirement. * Design and implement governance processes, operating models, quality controls, decision frameworks, and review routines that keep standards and controls current, consistent, and audit-ready. * Align standards and controls with leading frameworks and regulatory requirements, including NIST, ISO 27001, FFIEC, NYDFS, SOC, and related security and assurance standards. * Support audits, compliance reviews, risk assessments, and regulatory examinations through clear control mappings, standards documentation, evidence requirements, and governance reporting. * Drive continuous improvement of governance processes, workflows, and control management practices to improve efficiency, transparency, and usability across the organization. Enable Adoption, Security Alignment & Enterprise Partnership * Partner with Information Security, Risk Management, Compliance, Technology, Legal, Internal Audit, and business stakeholders to translate complex security requirements into practical and actionable guidance. * Work closely with Enablement and awareness teams to support adoption of security standards and controls through communications, implementation guidance, FAQs, and training content. * Establish governance of playbooks, templates, quality standards, and documentation practices that drive consistency across security domains and control owners. * Use stakeholder feedback, adoption trends, governance metrics, and quality reviews to continuously improve the effectiveness and usability of the control library and standards framework. * Build trusted partnerships across Information Security, Technology, Risk, Compliance, Audit, and business functions to help drive alignment and adoption of governance standards across the enterprise. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Enterprise-Cloud-Native - Fast-Paced Development & Deployment in a Highly Secure Banking Environment](https://www.wearedevelopers.com/videos/671-enterprise-cloud-native-fast-paced-development-deployment-in-a-highly-secure-banking-environment) - [Giving AI eyes: How to build a dashboard you can't see](https://www.wearedevelopers.com/videos/100193-giving-ai-eyes-how-to-build-a-dashboard-you-can-t-see) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)