SummaryThe Manager, Information Security leads Jewelers Mutual's security engineering and operations function, overseeing information security engineers and analysts, security tooling, vulnerability management, and incident response readiness. This hands-on leader partners with the CISO, CIO, IT infrastructure, DevOps, cloud engineering, application teams, and GRC to strengthen security controls, mature operational processes, and align security work to business risk priorities. The role balances team leadership with technical execution, vendor oversight, metrics reporting, and continuous improvement of the information security program.
What You'll Do- Lead, coach, and develop a team of information security engineers and analysts; set expectations, conduct regular one-on-ones, support career growth, and manage performance.
- Own security operations and vulnerability management, including security tooling, managed services relationships, daily incident triage, response coordination, and continuous improvement.
- Serve as a technical lead for security architecture within the security operations and engineering domain; provide input to enterprise security architecture in partnership with the CISO.
- Partner with IT infrastructure, cloud engineering, DevOps, application teams, and business stakeholders to embed security controls and requirements into systems and delivery pipelines.
- Oversee vulnerability management operations, including scanning cadence, remediation service-level expectations, remediation coordination, reporting, and escalation.
- Manage MSSP/SOC relationships, including escalation workflows, service-level accountability, operating procedures, and alignment with JM's incident response practices.
- Define, track, and report security operations KPIs and KRIs that connect technical findings to business risk; present updates to information security leadership and other leaders as needed.
- Support budgeting, vendor evaluations, renewals, and contract negotiations for security operations tools and services in partnership with procurement and legal.
- Develop and maintain security operations procedures, runbooks, and playbooks to support consistent, measurable, and repeatable operations.
- Support the CISO in advancing the information security program maturity roadmap aligned to NIST CSF and applicable regulatory requirements.
- Collaborate with GRC on audit readiness, control evidence collection, and gap remediation for SOC 2, NYDFS Part 500, and other applicable frameworks.
- Participate in off-hours escalation rotation for critical security incidents as needed.
Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Leadership Responsibilities Directly supervise Information Security Engineers and Analysts. Responsible for hiring, onboarding, performance management, coaching, and professional development of direct reports. Provides functional direction to managed service providers within the security operations scope.
Minimum Qualifications - Bachelor's degree in computer science, Information Security, Information Technology, or a related field, or equivalent work experience.
- 7+ years of progressive, hands-on technical experience in information security roles.
- 2+ years of experience managing or leading a security team, including direct supervision of technical staff.
- Demonstrated experience managing or directly supervising a security engineering or security operations team, including performance management and employee development.
- Deep hands-on background as a security engineer or analyst; able to engage technically with team members, review work products, and troubleshoot at the platform level.
- Strong cloud security experience across Azure and/or AWS environments, including native security tooling, identity governance, and workload protection.
- Working knowledge of enterprise security tooling such as SIEM, EDR, PAM, CASB/DLP, vulnerability management, email security, and threat intelligence tools.
- Experience working with MSSPs or other managed security services, including SLA management, escalation, and operational accountability.
- Proficiency establishing and reporting operational security metrics for technical and executive audiences.
- Strong understanding of DevSecOps practices, including secure SDLC, source-code security controls, and CI/CD pipeline security.
- Excellent verbal and written communication skills, with the ability to translate complex security topics for non-technical business stakeholders.
- Ability to manage competing priorities, exercise sound risk judgment, and make timely decisions with incomplete information.
Preferred Qualifications - Experience in the insurance or financial services sector; familiarity with insurance regulatory environments such as NYDFS and NAIC.
- Working knowledge of NIST CSF 2.0, SOC 2 Type II, NYDFS Part 500, and/or NAIC Model #668.
- Experience with GRC and compliance automation platforms, such as Vanta.
- Hands-on experience with the Microsoft security ecosystem, including Defender XDR, Sentinel, Entra ID Protection, Purview, and Intune.
- Familiarity with AI security considerations, including governance of AI tools, prompt injection risks, and LLM-integrated application security.
- Professional certification such as CISSP, CISM, CCSP, or equivalent; additional technical certifications such as CEH, GSEC, or GCIH are a plus.
What We Offer You- Community & Giving: Benefit from 50% charitable gift matching and paid volunteer time to support nonprofit causes.
- Great Place to Work® Certified: Join a team recognized for an environment of innovation and growth.
- Collaborative Culture: Work alongside talented, passionate peers who value ownership and continuous learning.
- Competitive Compensation & Benefits: Includes performance bonuses, generous paid time off, and a top-tier retirement program with 401(k) matching and additional company contributions.
Accessibility and AccommodationsWe are committed to providing an inclusive and accessible recruitment process. If you require accommodation at any stage of the application or interview process, please let us know by contacting
[email protected].