Anticipated End Date:
2026-07-31
Position Title:
Information Security Senior Advisor
Job Description:
Information Security Senior Advisor
Location: This role requires associates to be in-office 1-2 days per week, fostering collaboration and connectivity, while providing flexibility to support productivity and work-life balance. This approach combines structured office engagement with the autonomy of virtual work, promoting a dynamic and adaptable workplace. Alternate locations may be considered if candidates reside within a commuting distance from an office.
Please note that per our policy on hybrid/virtual work, candidates not within a reasonable commuting distance from the posting location(s) will not be considered for employment, unless an accommodation is granted as required by law.
The Information Security Senior Advisor is responsible for the selection and delivery of strategic network security, access control and secure transaction/messaging solutions, strategic business continuity, risk management, crisis management, operational and technology-ai resilience, and TPRM controls and solutions. Develops, recommends, and implements enterprise information security including global business resilience and vendor resilience policies, technical standards, guidelines, procedures, and other elements of an infrastructure necessary to support information security, risk management and global business resilience, operational and technology-ai resilience, and vendor resilience programs, in compliance with established company policies, regulatory requirements, industry standards, best practices, and generally accepted information security, business continuity and third party risk management (TPRM) controls.
How you will make an impact:
- Leads development and execution of risk assessment methodologies to fit business, TPRM, regulatory, and technical environment considerations;
- Leads the development of requirements, system architecture, and software design of security and risk management products and services; leads the development of strategies for discovery, evaluation and response to new networking attacks; develops security, crisis response, and TPRM incident response plans and strategies.
- Provides trouble resolution and serves as point of technical and TPRM escalation on complex problems.
- Creates presentations and seeks IT management approval and acceptance of significant resilience programs, projects and replacements or reconfigurations of major security systems serving the Enterprise.
- Sets and/or supports operational, business and vendor resilience strategy and direction.
- May be assigned to project teams for technical and subject matter expert (SME) consultation to business partners, stakeholders, vendors and developers.
- Designs & engineers comprehensive access management and network security technical solutions, resilience-related tools for plans development, execution, and customer facing, based on business requirements and defined technology standards;
- works with architecture to update technology direction & strategy.
- Develops reports supporting strategy and direction for management.
- Capable of serving as the technical merger & acquisition lead.
- Acts as a subject matter expert among peers, with manager and senior management.
- Ability to communicate effectively both verbally and in writing with associates, team members, stakeholders, regulators, customers and vendors.
- Must be capable of providing top-tier support for 5 or more of the information security technology common body of knowledge skill sets: 1) Access Control, 2) Application Security, 3) Business Continuity and Disaster Recovery Planning, 4) Cryptography, 5) Information Security and Risk Management 6) Legal, Regulations, 7) Compliance and Investigations, 8) Operations Security, 9) Physical (Environmental) Security, 10) Security Architecture and Design, 11) Telecommunications and Network Security, 12)Vendor Resilience and 12)Technology Resilience.
Minimum Requirements:
Requires BS/BA in information Technology, Business Administration, or related field of study and
a minimum of 8 years’ experience in business continuity management, TPRM, systems administration and security aspects of information systems, access management and network security technologies, network communications, computer networking, telecommunications, systems development and management, hardware, software, data, and people; experience with multiple technical and business disciplines required; or any combination of education and experience, which would provide an equivalent background.
Preferred Skills, Capabilities, and Experiences:
- Certifications: CBCP, MBCP, CISSP and other advanced technical security certifications (e.g. Information Systems Security Architecture Professional, Information Security Engineering Professional, Certification and Accreditation Professional, or equivalent certifications) strongly preferred.
- Experience planning, designing, building, implementing or maturing third party risk management programs, business continuity programs, global business resilience programs or highly complex systems is strongly preferred.
- Experience in Healthcare sector is preferred.
Job Level:
Non-Management Exempt
Workshift:
Job Family:
IFT > IT Security & Compliance