Manager, IT Security & Risk

Sammons® Financial Group, Inc.
West Des Moines, IA, United States
3 months ago
Apply on indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$104,404.0 - $217,508.0
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Identity and Access Management Information Management Network Security Security Software Security Information and Event Management Software Vulnerability Management Software Security

Job description

Overview: Oversee and coordinate the solution design, project execution and implementation of various operational activities and production support of an IT Security and Risk Management team, as well as provide direction and support for IT solutions that enhance mission-critical business strategies and operations. Accountable for the management planning and rollout of processes, tools, and procedures. Establish and manage against goals across multiple teams/projects. Employ industry direction and technologies into process and product planning to establish well-aligned development strategies. Responsibilities: * Exercise leadership influence and direction for IT Security and Risk Management team. Effectively coach and lead to ensure a competent, technically proficient staff that grows their depth and breadth of skills. Invest time and expertise in providing team with examples for learning. Identify team and individual deficiencies, recommend and implement solutions. Complete annual performance reviews for all staff members in a timely manner. Responsible for training and developing individual team members. Responsible for Corrective Action, as appropriate.

  • Leverage information security and/or information risk management expertise to drive decrease in information security risk to acceptable levels and the increase the maturity level of the information security program to defined level of maturity. Mentor and develop individual team members to grow their technical skills.
  • Align team strategy and goals with departmental and organizational goals. Effectively plan work efforts, leverage staff time and expertise to meet departmental and organizational goals. Exemplify company values and mission in daily activities. Effectively communicate and collaborate with all levels of management across the department and organization.
  • Identify needs, develop requirements, implement and manage cybersecurity technologies, processes and procedures. Acts as a Subject Matter Expert and/or Business Sponsor for cybersecurity projects and initiatives.
  • Develop, implement and maintain appropriate security and risk controls to comply with internal policies and requirements, comply with legal and regulatory requirements, and demonstrate appropriate risk management.
  • Develop, maintain and report on departmental metrics.
  • Contribute to success of the overall technology transformation through committed quality delivery and continuous improvement.
  • Develop and maintain Model Audit Rule compliant procedures for all departmental processing; establish, maintain and ensure departmental compliance with Record Information Management (RIM) requirements.
  • Commitment to embrace Sammons Financial Group Companies shared values (Accountability, Connection, Openness, Respect and Integrity).
  • As stated within the Company Attendance and Punctuality policy, regular attendance is required and expected in order to meet the business service levels and workflow demands.
  • Participate in other initiatives and/or projects as necessary. Qualifications

Requirements

Do you have a valid CompTIA Advanced Security Practitioner certification?, Do you have experience in Security technology solutions implementations?, Do you have a Associate’s degree?, * Bachelor’s Degree in a technology field and 8+ years’ experience working in cybersecurity, an Associate’s Degree with 10+ years’ experience in cybersecurity or 12+ years’ experience in cybersecurity Required

  • Broad and deep knowledge of Information Security concepts and how these concepts apply to the business.
  • Has technical expertise in two or more areas of information security (incident response, security operations, vulnerability management, application security, systems security, network security, identity management, access control, risk management, etc.).
  • Experience applying cybersecurity and risk management methodologies in a complex and dynamic environment.
  • Experience identifying requirements, selecting vendors, and implementing and managing endpoint protection, vulnerability management, security and event monitoring (SIEM), IAM, and other cybersecurity tools.
  • Must demonstrate the ability to act independently within the context of corporate and divisional goals, using tact and good judgment.
  • Ability to effectively prioritize and execute tasks in a high-pressure environment.
  • Excellent written, oral, and interpersonal communication skills.
  • CASP, CISSP, CISM Preferred, Suitability Requirements: * Due to the financial nature and level of accountability of this position, a credit and criminal background check is required - The Fair Credit Reporting Act requires Sammons Financial Group Companies to notify you that, as a routine part of processing this application for employment, Sammons Financial Group may request a consumer report on you to verify all information contained in this application. Such report may include information about work-related behaviors, performance, character, general reputation, and personal characteristics, in addition to information about your previous employment, education, credit history and criminal records

Benefits & conditions

Pulled from the full job description

  • Tuition reimbursement
  • 401(k)
  • Health insurance
  • Paid time off
  • Vision insurance
  • Health savings account
  • Dental insurance, Pay Range: USD $104,404.00 - USD $217,508.00 /Yr. Pay Transparency Verbiage: Range includes data points from multiple labor markets. Specific range is dependent on the labor market where the incumbent will be hired to perform the position. Starting salary is dependent on candidate qualifications and experience. For a narrower salary range specific to your labor market, please inquire. Company Information: *Comprehensive health coverage for you and your family, including Medical, Dental, Vision, HSA & FSA options, and term life insurance.
  • Competitive compensation with a performance-based incentive program tied to clear goals and individual and/or company success.
  • Invest in your future with our 100% company-funded Employee Stock Ownership Plan (ESOP), plus automatic enrollment in our 401(k).
  • Work-life balance that means something. Friday afternoons off year-round, generous paid time off, and paid holidays.
  • Commit to your growth with paid development time, tuition reimbursement, and professional development opportunities across industry, individual, and leadership programs.
  • Make an impact beyond the workplace through volunteer time off, and our company nonprofit matching gift program, supporting the causes that matter most to you.
  • An ownership culture that inspires; join a connected, values-driven workplace where employees take accountability, support one another, and are empowered to do their best work-together shaping our future shared success.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:41 min

Exploring the structure of the OWASP SAMM framework

Mathias Tausig · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:16 min

Securing internal pod communication with network security policies

Marc Nimmerrichter · World Congress 2022

1:30 min

The universal and shared team responsibility of software security

Julia Wilson Julia Wilson +1 · World Congress 2025

5:25 min

Introduction to secure development and OWASP SAMM

Mathias Tausig · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all