Associate Director of Information Security

NR Consulting LLC
New Haven, CT, United States
13 days ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$68,000.0 - $120,500.0
Working hours
Regular working hours

Tech stack

Control Objectives for Information and Related Technology (COBIT) Cyber Security Cloud Services Information Technology

Job description

The Associate Director of Governance, Risk, and Compliance (GRC) is a resourceful and experienced information security leader responsible for managing, and continuously improving, the organization’s information security GRC program. This position provides strategic direction and operational oversight for the organization’s information security governance framework, including the development and maintenance of security policies, standards, and procedures; coordination of security audits and assessments; management of information security risks and exceptions; oversight of third-party security risk; and delivery of meaningful program reporting to leadership and governance committees. The Associate Director ensures that the organization’s information security governance practices remain aligned with applicable regulatory requirements, contractual obligations, industry standards, and organizational risk objectives. This individual reports to, and works closely with, the Deputy CISO and partners across the organization with Enterprise Risk Management, Internal Audit, Legal, Privacy, Compliance, Information Technology, and other business leaders to promote effective governance, strengthen risk management, and support the continuous improvement of the information security program. Core Responsibilities

  • Lead, develop, mentor, and retain a high-performing Information Security GRC team.
  • Establish team objectives, performance measures, responsibilities, and development plans.
  • Develop, maintain, and continuously improve the organization’s information security governance, risk, and compliance strategy, operating model, and multi-year roadmap.
  • Keep up with ongoing trends and changes within the GRC community and make sure that the organization is up-to-date with the latest relevant methods and practices.
  • Develop, maintain, and manage information security policies and standards.
  • Partner with colleges within Information Security, technology and other function areas to ensure security standards are practical, measurable, and aligned with organizational requirements.
  • Maintain the information security risk register and exception process to ensure security risks are appropriately documented, assigned, prioritized, tracked, and reported.
  • Partner with Enterprise Risk Management to align information security risk methodologies, reporting, and governance with the organization’s broader enterprise risk management framework.
  • Develop and maintain an information security control framework aligned with applicable regulatory requirements, contractual obligations, industry standards, and organizational risk priorities.
  • Oversee information security compliance activities related to applicable laws, regulations, standards, frameworks, and customer requirements, which may include NY-Client, COBIT, various NIST frameworks, amongst others.
  • Coordinate and manage information security audits, assessments, and examinations.
  • Serve as the primary Information Security liaison for Internal Audit, External Audit, and other regulatory examiners.
  • Establish key indicators, reports, dashboards, control metrics, and security maturity measures to assess the effectiveness of the information security program.
  • Develop, maintain, and manage information security third-party risk activities.
  • Establish governance processes to evaluate security risks associated with new technologies, major business initiatives, cloud services, significant system changes, and strategic projects.
  • Partner with Privacy, Legal, and Compliance to address overlapping security, privacy, regulatory, and contractual requirements.
  • Maintain awareness of changes to cybersecurity laws, regulations, standards, industry expectations, and emerging risk trends, and assess their potential impact on the organization., Overview The Associate Director of Network Engineering is a hands-on technical leader responsible for overseeing the design, implementation, and support of the enterprise-wide ne…
  • 1 day ago

Requirements

  • Extensive knowledge of Governance, Risk, and Compliance practices
  • Ability to process and understand complex information relevant to cyber security initiatives
  • Ability to create detailed documentation and workflow diagrams
  • Possess the ability to multi-task between projects
  • Exceptional written, oral, and interpersonal communication skills
  • Understanding of the NIST CSF framework and other associated cyber security standards
  • Ability to drive team outcomes through tight deadlines and prioritization of tasks
  • Extensive knowledge of legal and regulatory compliance standards and requirements such as NYDFS, GDPR, CCRA, and CCPA.

Preferred:

  • CISSP, CISM, CRISC, CISA, or other security management certifications

Education Required:

  • Five years of relevant experience within the Governance, Risk, and Compliance field.
  • Proven working experience performing the functions listed under the core responsibilities section.

Preferred:

  • Bachelor’s degree in information security, Cyber Security, Computer Science, or another related field
  • Insurance and financial services industry experience is a plus

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:41 min

Transitioning artificial intelligence infrastructure into scalable commodity cloud services

juarezjunior juarezjunior · World Congress 2024

42 sec

Energy forecasts and resource demands of information technology

Marjolein Pordon · LIVE

3:02 min

Navigating DORA compliance and executive liability in security

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

2:46 min

Missing equipment retrieval processes for departing employees

Jasmin Azemović Jasmin Azemović · World Congress 2026 Europe

47 sec

Advantages of edge inference over cloud API services

Sasha Denisov Sasha Denisov · World Congress 2026 Europe

Videos

See all

Related articles

See all