JOB DESCRIPTION
Insight Global is seeking a Head of Information Security and Compliance to join a leading financial technology organization in a net new position. This individual will report to the CIO and serve as a senior security leader responsible for establishing, maturing, and operationalizing the organization's security program. The initial focus will be supporting a major TSA (Transition Services Agreement) separation, ensuring security capabilities have clear ownership, governance, and operational readiness. This is a highly hands-on, role that partners closely with infrastructure, cloud, DevOps, application development, and business leaders to drive security strategy, risk management, operational security, and compliance initiatives. The ideal candidate will be comfortable remaining technical while building toward a future security function, with a focus on practical security rather than heavy governance or committee-driven leadership.
Day to Day:
- Lead the security workstream associated with TSA separation activities, ensuring all security capabilities have documented ownership and transition plans.
- Develop and maintain security policies, standards, controls, and exception management processes that align with business objectives and regulatory requirements.
- Own security risk governance including risk registers, remediation tracking, executive reporting, and risk treatment plans.
- Establish and oversee security operations and incident response processes across internal teams and external partners.
- Drive vulnerability management programs, including prioritization, remediation tracking, risk acceptance processes, and security posture reporting.
- Provide security guidance for cloud, application, and data initiatives, ensuring security requirements are incorporated into architecture and design decisions.
- Partner closely with cloud infrastructure and DevOps teams to maintain secure AWS environments and strengthen cloud security controls.
- Support secure software development practices by implementing security scanning, assessing vulnerabilities within development workflows, and promoting secure coding standards.
- Evaluate and recommend security tools, including static analysis and application security solutions, to improve overall security posture.
- Support client, lender, audit, compliance, and regulatory requests by maintaining accurate security evidence, documentation, and due diligence responses.
Assess and manage third-party security risks for vendors, cloud providers, and technology partners.
Review security assessments and reports, providing actionable recommendations to reduce risk and improve operational effectiveness.
Develop security awareness programs and partner with technical teams to strengthen security culture across the organization.
Create and execute a long-term enterprise security roadmap supporting business growth, technology modernization initiatives, and future expansion across affiliated organizations.
REQUIRED SKILLS AND EXPERIENCE
- 7+ years of progressive information security experience, including leadership responsibilities.
- Experience building, maturing, or significantly transforming security programs within mid-sized organizations.
- Strong knowledge of security governance, risk management, compliance frameworks, incident response, vulnerability management, and security operations.
- Experience working across cloud, infrastructure, application security, identity and access management, and security operations domains.
- Hands-on experience supporting secure application development, security scanning, vulnerability remediation, and secure SDLC practices.
- Experience reviewing security assessments, risk reports, and customer due diligence questionnaires.
- Background supporting audits, customer due diligence, regulatory compliance, and security assessments.
- Strong understanding of security architecture, cloud security principles, and risk management methodologies.
- Excellent stakeholder management and executive communication skills.
- Ability to operate in a hands-on, player-coach leadership environment with little to no direct management responsibility.
- Comfort working in fast-paced environments where security must enable business growth and product delivery.
NICE TO HAVE SKILLS AND EXPERIENCE
- Experience leading security initiatives during TSA separations, mergers, acquisitions, or large-scale organizational transitions.
- Financial services, fintech, mortgage lending, or other regulated industry experience.
Experience working with AWS environments and cloud-native security controls.
- Experience partnering with DevOps teams and implementing DevSecOps practices.
- Experience evaluating or implementing static application security testing (SAST) and code-scanning tools.
- CISSP, CISM, CRISC, or equivalent security certifications.
As part of our recruitment process, AI-assisted tools may be used to support candidate screening, resume review, interview note-taking, and application evaluation. These tools are intended to help improve efficiency and consistency throughout the hiring process. All hiring decisions remain subject to human review, and candidates are assessed based on their qualifications, skills, experience, and alignment with the requirements of the position.