Chief Information Security Officer (CISO) — Insurance & Investments
TheHiveCareers · Anywhere · Full-time · Other
Remote
Posted 11h ago · Expires 10/30/2026
Role description
Hiring company: TheHiveCareers
Source: LinkedIn
Job Summary
The Chief Information Security Officer (CISO) is the executive responsible for protecting the organization's information, technology infrastructure, applications, data, and digital services from cyber threats and security risks.
Within Insurance & Investments, the CISO leads enterprise cybersecurity, information security governance, cyber risk management, security architecture, incident response, regulatory compliance, identity and access management, third-party security, and business continuity/cyber resilience.
Key Responsibilities
Develop and execute the enterprise cybersecurity and information security strategy.
Establish information security policies, standards, controls, and governance frameworks.
Lead enterprise-wide cybersecurity risk management.
Protect sensitive customer, financial, investment, policyholder, employee, and corporate data.
Oversee:
Security Operations (SOC)
Threat Detection & Response
Incident Response
Security Architecture
Vulnerability Management
Penetration Testing
Identity & Access Management
Endpoint Security
Network Security
Cloud Security
Application Security
Data Security
Establish and manage cyber incident response and crisis-management processes.
Lead security monitoring, threat intelligence, vulnerability assessment, and security testing.
Develop cybersecurity controls across cloud, on-premise, applications, APIs, and digital platforms.
Implement and maintain Identity & Access Management (IAM), privileged access, MFA, and least-privilege controls.
Oversee third-party/vendor cybersecurity risk and technology due diligence.
Ensure security requirements are embedded into digital transformation and technology projects.
Lead security awareness, phishing prevention, and employee cybersecurity training.
Ensure compliance with applicable financial-services, privacy, cybersecurity, and regulatory requirements.
Manage security audits, risk assessments, control testing, and remediation programs.
Develop and test Business Continuity, Disaster Recovery, and Cyber Resilience plans.
Establish cybersecurity KPIs, KRIs, dashboards, and executive reporting.
Manage cybersecurity budgets, vendors, managed security providers, and strategic technology partners.
Lead and develop information-security and cybersecurity teams.
Advise the CEO, Board, Risk Committee, Audit Committee, and senior leadership on cyber risk.
Ensure cybersecurity risks are integrated into the organization's overall enterprise risk-management framework.
Insurance & Investments Security Focus
Particularly relevant experience includes protecting:
Insurance
Policyholder/customer data
Claims systems
Underwriting platforms
Actuarial systems
Payment systems
Customer portals
Insurance APIs
Fraud and identity data
Investments / Asset Management
Portfolio and investment systems
Trading platforms
Market and financial data
Investment research
Client/investor information
Custody and transaction systems
Wealth-management platforms
Third-party investment technology
Ideal Candidate Profile
15+ years of IT, cybersecurity, information security, technology risk, or related experience.
7+ years in senior cybersecurity/security leadership.
Previous experience as:
CISO
Group CISO
Chief Information Security Officer
Chief Cybersecurity Officer
Head of Information Security
Head of Cybersecurity
Director of Information Security
Director of Cybersecurity
VP Information Security
VP Cybersecurity
Strong background in Insurance, Banking, Investment Management, Asset Management, Wealth Management, or Financial Services.
Strong expertise in:
Cybersecurity strategy
Information security governance
Cyber risk management
Security architecture
SOC/SIEM
Incident response
Threat intelligence
Vulnerability management
IAM/PAM
Cloud security
Application security
Network security
Data security
Third-party risk
Business continuity/cyber resilience
Experience with recognized security frameworks and standards such as NIST, ISO 27001, CIS Controls, COBIT, or equivalent.
Strong understanding of financial-services cybersecurity and regulatory requirements.
Demonstrated experience presenting cyber risk to Board/C-suite stakeholders.
Strong leadership, crisis management, risk communication, and stakeholder-management skills.
Relevant bachelor's degree; Master's degree and certifications such as CISSP, CISM, CRISC, CISA, CCSP or equivalent are advantageous.