The Director of Information Security is a senior, hands-on leader responsible for designing, implementing, and operating a comprehensive information security program across three affiliated companies. This role combines
technical security leadership,
risk management, and
governance, risk, and compliance (GRC) oversight.
The ideal candidate is a
player-coach who can lead a small team while remaining deeply engaged in day-to-day security operations and architecture. This individual will serve as a trusted advisor to business leaders, management, and external clients, translating complex security risks into clear, actionable business terms.
- Lead and manage a small, highly technical information security team, providing mentorship, direction, and hands-on support.
- Design, implement, and maintain security controls across identity, endpoint, network, cloud, and SaaS environments.
- Provide direct technical oversight and escalation support for security incidents, investigations, and response activities.
- Ensure consistent security posture and standards across three separate companies while accommodating business-specific needs.
- Act as a subject matter expert and hands-on contributor for core security platforms, including:
- Identity & Access Management: Okta, Azure AD
- Network & Cloud Security: Zscaler, Azure
- Productivity & SaaS Security: Microsoft 365
- Email Security: Proofpoint
- Endpoint Protection: CrowdStrike
- Security Monitoring & SIEM: Splunk
- Partner with IT and engineering teams to securely design and deploy cloud and hybrid environments.
- Continuously evaluate and enhance security tooling, configurations, and detection capabilities.
- Lead enterprise security risk assessments to identify, analyze, prioritize, and document information security risks.
- Clearly communicate risk exposure and mitigation strategies to non-technical business users, executive management, and clients.
- Drive risk remediation efforts, tracking progress and ensuring accountability.
- Integrate security risk management into broader enterprise risk management processes.
- Own and operate the information security governance program, including policies, standards, procedures, and metrics.
- Ensure the design and effectiveness of IT General Controls (ITGCs).
- Support internal and external audits, including planning, evidence collection, remediation, and ongoing control improvements.
- Maintain compliance with applicable regulatory and contractual requirements, with emphasis on:
- State Department of Insurance (DOI) data security regulations
- New York Department of Financial Services (NYDFS) 23 NYCRR 500
- Partner with Legal, Compliance, and Audit teams to ensure alignment between security, regulatory, and business objectives.
- Serve as a key security liaison for:
- Non-technical business staff
- Executive and senior management
- External clients, partners, and auditors
- Translate technical security concepts into clear, business-focused language appropriate for each audience.
- Prepare and deliver security briefings, risk summaries, and compliance updates to leadership.
- Demonstrate commitment to Company's Code of Business Conduct and Ethics, and apply knowledge of compliance policies and procedures, standards and laws applicable to job responsibilities in the performance of work.
- Bachelor's degree in Information Security, Computer Science, Information Systems, or a related field (or equivalent experience).
- 8+ years of progressive experience in information security, including leadership or senior technical roles.
- Proven experience managing and mentoring small security teams.
- Strong hands-on technical expertise in:
- Okta, Zscaler, Azure, Microsoft 365
- Proofpoint, CrowdStrike, Splunk
- Demonstrated experience leading security risk assessments and remediation initiatives.
- Strong background in governance, risk, and compliance, including IT general controls and audit support.
- Experience working in regulated environments, preferably financial services or insurance.
Preferred Qualifications- Prior experience supporting State Department of Insurance data security regulations.
- Direct experience with NYDFS 23 NYCRR 500 compliance.
- Audit background (internal audit, external audit, or security assurance).
- Relevant certifications such as CISSP, CISM, CRISC, CGEIT, or similar.
Key Competencies & Attributes- Hands-on, pragmatic security leader with a strong bias toward execution.
- Excellent verbal and written communication skills.
- Ability to balance security rigor with business enablement.
- Strong organizational and prioritization skills across multiple companies and stakeholders.
- High integrity, sound judgment, and comfort operating with limited oversight.