What We're Looking ForWe are seeking an experienced AVP, Information Security to collaborate across the organization and execute information security governance processes. This hands-on role serves as a subject-matter expert, guiding and monitoring compliance with industry best practices, regulatory guidance, infosec frameworks, and internal policies and standards. The ideal candidate is self-motivated, solutions-oriented, detail-focused, and an independent thinker.
Responsibilities:Support select IT assurance and infosec tasks, including:
- SDLC & Change Management
- Monitor and report adherence to SDLC and change management procedures
- Coordinate penetration test vulnerability and EOL asset ticket closure with Infrastructure, Engineering, and Internal Audit
- Business Continuity Management
- Maintain and improve Crisis Management, Business Continuity (BCP), and Disaster Recovery Plans (DRP) aligned with industry standards and regulations
- Conduct Business Impact Analysis (BIA) workshops to identify critical processes, systems,and quantify resilience metrics like RPOs, RTOs, and MTDs
- Identify, propose, defend, and support implementation of resilience strategies and solutions
- Design and execute a risk-based multi-year testing calendar
- IT Risk Monitoring & Reporting
- Monitor, assess, and report on the effectiveness of selected IT risk metrics
- Design and implement new risk metrics
- Privacy Request Fulfillment
- Execute data-subject rights requests following privacy laws including CCPA and CAN-SPAM
- IT Assurance
- Collaborate with cross-functional teams to create or maintain select standards, procedures, and documentation
- Provide training and awareness across the organization on policies and procedures
- Collect evidence across IT processes to support audits and examinations
- Maintain control mappings and perform gap analyses to drive continuous program improvement
Qualifications:Must Have:
- Exceptional written and verbal communication skills to present complex information clearly to diverse audiences
- Professional certifications: ISACA CISA or ISC2 CISSP
- 5+ years of experience in Information Security, IT Security, IT Audit, IT GRC, IT Compliance,IT Assurance, IT Risk, IT Business Analysis, or Business Continuity
- Strong knowledge of software development life cycle (SDLC), change management, business continuity management, and IT risk management
Preferred:
- Undergraduate or graduate degree in computer science, cybersecurity, information assurance, business administration, or a closely related field
- Familiarity with regulatory guidance, standards, and frameworks such as the FFIEC ITHandbook, SOC 1/2, PCI DSS, COBIT 2019, and ITIL
- Experience working in a highly regulated environment such as financial services, military, or healthcare
#LI-AC1 #LI-Hybrid
Salary Range: $150,000.00 - $170,000.00