Provide strategic and operational leadership to a team (both internal and vendor provided) that establishes, supports and continuously improves enterprise information security technology, policies, practices and standards. Drive information security strategy to ensure best in class security processes and solutions that are cost effective (on budget), keep Ameriprise applications and infrastructure safe and secure from vulnerabilities, and are compliant with external regulatory requirements. Key Responsibilities Major Areas of Accountability: People Leadership ~ Strategy & Solution Delivery ~ Security Monitoring & Incident Response ~ Process Ownership ~ Information Security Governance ~ Maintain Knowledge & Relationships ~ Financial Accountability - Direct Expense $1-4MM Provide strategic direction and day-to-day leadership to an information security team. Develop and maintain an effective organization with appropriate skills, structure, and direction to meet current and future business needs. Develop a team of high performing people through effective hiring, coaching and rigorous performance/talent management processes. Foster an innovative, collaborative, success-oriented team environment where resources are empowered and accountable. Work with the business and across technology to ensure a solid understanding of information security requirements, identify current and/or potential security risks and develop, implement and drive security strategies, solutions, methodologies and/or policies to strengthen the effectiveness of the Information Security Management organization. Collaborate with leadership and technology to prioritize information security initiatives based on business need and cost/benefit/risk analysis. Initiate regular, application security health checks and ensure strategy addresses identified issues/needs. Collaborate with stakeholders to determine current and future level of enterprise investment required to sustain compliant and robust security standards. Provide cost, feasibility and risk analysis to support and gain initiative approval. Ensure solution design and delivery meet requirements and expectations regarding cost, schedule and scope. Effectively oversee multiple projects/initiatives simultaneously. Oversee the design, implementation and management of monitoring tools and processes to identify security concerns, risks and incidents. Oversee security incidents to ensure prompt and effective remediation. Track and communicate status to senior leadership as appropriate. Ensure action plans are in place to address recurring or ongoing information security incidents. Ensure escalation and effective hand-off of issues to other technology groups as required. Develop, maintain and champion ISM requirements, policies, procedures and methodologies across the business and technology. Regularly review and lead change to drive continuous improvement. Execute and/or oversee the design and implementation of mechanisms for education and governance to ensure organizational compliance with policies and procedures. Act as a subject matter expert for security issues. Manage response to customer and regulatory requests with regard to information security services, mechanisms and safeguards, including regular communications with regulatory, privacy and legal stakeholders. Lead internal and external risk assessment activities, risk analysis and application or system-level vulnerability testing and reviews. Ensure compliance with security regulations such as PCI, GLBA, FFIEC, etc.. Ensure vendor compliance with Ameriprise security requirements. Maintain up-to-date business domain knowledge and expert technical skills in information security technology and methodology. Provide expertise in the selection and implementation of information security tools and best practices, as well as recommendations on priority of initiatives and asset investments. Establish and maintain effective working relationships across business, operations and technology teams to credibly and collaboratively drive information security strategy and initiatives.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Director