> Markdown version of [/jobs/ext/2437953-lead-information-security-grc-automation](https://www.wearedevelopers.com/jobs/ext/2437953-lead-information-security-grc-automation). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead, Information Security GRC Automation - **Company:** Prudential Financial, Inc. - **Location:** Newark, NJ, United States (Remote available) - **Experience:** Expert - **Salary:** $114,500.0 - $188,900.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), JIRA, Automation of Tests, Microsoft Azure, Cloud Computing, Configuration Management Databases, Cyber Security, Information Systems, Continuous Integration, Data Structures, DevOps, Github, Release Management, Software Engineering, Systems Integration, Strategies of Testing, Microsoft Power Automate, Information Technology, Jenkins, Servicenow - **Published:** August 13, 2026 - **Apply:** https://pru.wd5.myworkdayjobs.com/Careers/job/Newark-NJ-USA/Lead--Information-Security-GRC-Automation_R-124780-1 ## About the Role * Bachelor's degree or equivalent experience in Cybersecurity, Information Systems, Computer Science, Risk Management, related field or equivalent experience. * Experience implementing automated controls testing, continuous monitoring, evidence collection, or governance capabilities in a regulated environment. * Knowledge of security controls, testing methodologies, evidence management, and risk-based monitoring practices. * Understanding of technology delivery lifecycle including software development, DevOps, CI/CD, release management, and technology delivery processes. * Experience working with Governance, Risk, and Compliance (GRC) platforms, APIs, ServiceNow or asset inventory data, workflow automation, integrations, or control reporting capabilities. * Ability to translate control library requirements into automated test scripts, telemetry, metrics, evidence routines, and executive-ready reporting outputs. * Strong knowledge on Azure DevOps, Jira, GitHub, Jenkins, Power Automate, cloud platforms, or related technologies. * Strong analytical, communication, and stakeholder management skills, with the ability to lead working sessions and drive timely resolution across multiple workstreams. Preferred Qualifications * Experience with ServiceNow IRM or similar Governance, Risk, and Compliance (GRC) platforms. * Experience implementing continuous controls monitoring, automated evidence collection, or control-as-code approaches. * Experience integrating governance and compliance activities into technology delivery workflows. * Experience supporting financial services, regulatory, audit, or compliance programs such as NYDFS, SOX/JSOX, SWIFT, CCPA, JFSA, SOC 1/2, ISO 27001, or similar requirements. * Certifications such as CISSP, CISM, CRISC, CISA, or ServiceNow credentials. * Experience developing automation playbooks, operating routines, intake processes, dashboards, adoption materials, or training content for governance or control capabilities. #LI-Hybrid #LI-LR1 ## Description Are you interested in building capabilities that make Information Security easier to understand, adopt, and execute? As part of Prudential's Global Technology & Operations organization, the Information Security team is strengthening its governance capabilities to improve visibility into security risk, policy adoption, and program execution across the enterprise. As the Lead, Information Security GRC Automation, you will help build and scale Prudential's automated control testing, monitoring, telemetry, and evidence capabilities. Reporting to the Director of Information Security Governance, you'll work across Risk Management, Technology, Audit, and Information Security to modernize how controls are monitored and reported. This role offers the opportunity to help shape a more automated, data-driven governance function that reduces manual effort and improves risk visibility across the enterprise. This role is based in our office in Newark, NJ. Our organization follows a hybrid work structure where employees can work remotely and from the office, as needed, based on demands of specific tasks or personal work preferences. This position is hybrid and requires your on-site presence on a reoccurring weekly basis at least 3 days per week. Here is What You Can Expect on a Typical Day Build Automated Control Monitoring & Evidence Capabilities * Design and implement automated control testing, continuous monitoring, telemetry, and evidence collection capabilities that improve visibility into control effectiveness and reduce reliance on manual processes. * Translate control library requirements into scalable automation solutions, metrics, monitoring routines, and testing approaches that support risk-based governance and compliance objectives. * Identify opportunities to automate testing and evidence collection across the control environment, helping mature governance from periodic assessments to near real-time monitoring. * Ensure automated testing results, evidence, and supporting data to remain accurate, traceable, and audit-ready. Build Integrated Governance Data & Technology Solutions * Establish and maintain connections across governance, risk, asset, technology, CMDB, and evidence platforms to create a scalable and connected governance ecosystem. * Partner with technology teams and control owners to onboard new evidence sources, improve data quality, and enhance traceability across controls, assets, risks, and reporting. * Design sustainable automation frameworks that support control monitoring, reporting, remediation tracking, and executive visibility across Information Security Governance. * Help establish the foundational data structures, taxonomies, and integration patterns required to scale future automation initiatives Drive Governance Transformation & Operational Excellence * Partner closely with Library & Standards, Policy & Enablement, Business Intelligence, Risk Management, Internal Audit, and Technology teams to create an integrated governance capability that connects controls, standards, adoption, metrics, and executive reporting. * Lead continuous improvement of automation operating models, including intake, prioritization, testing, evidence collection, reporting, and governance workflows. * Develop scalable playbooks, standards, and operational routines that improve consistency, accelerate adoption, and enhance the effectiveness of automated control monitoring. * Influence cross-functional stakeholders to modernize governance practices, reduce manual effort, and drive a more data-driven approach to risk and control management across the enterprise ## Related Videos - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)