North America Information Security Officer

Aon CorporationMannsville, OK

About The Position

The Information Security Officer (ISO) will support North America within the Regional Security Office (RSO), with a focused directive on advancing the cybersecurity posture of the NFP business, driving secure integration of mergers and acquisitions (M&A), and ensuring alignment with New York Department of Financial Services (NYDFS) regulatory requirements. This role works with the North America Regional Security Officer to manage regional cybersecurity risk within acceptable levels. It involves accomplishing targeted remediation programs and deploying Global Cybersecurity Services (GCS) controls. Serving as the main contact for cybersecurity across NFP and M&A activities, the ISO must understand security controls and regulatory expectations well. They also need to apply these effectively in complex, evolving environments. The role also demands strong collaborator engagement to drive adoption of security standards and ensure consistent, compliant execution across the portfolio. As an Information Security Officer, you will be accountable for cybersecurity service delivery across North America, with a focus on supporting the NFP business, M&A integration activities, and NYDFS-regulated entities. The role requires building strong relationships with senior leadership to enable achievement of business objectives while operating an effective security risk management program aligned to defined risk mitigation strategies and regulatory expectations. As a trusted security leader, you will represent the organization in engagements with business leaders, regulators, and clients as needed. Prior experience managing regulatory requirements—particularly within highly regulated environments such as NYDFS—is essential. This is a highly transparent role within Aon to be able to embed effective security controls at scale within the firm. We are looking for you to bring new ideas and dedication toward continual learning. You will stay effectively engaged with business leaders, IT executives and external clients.

Requirements

  • 8 or more years of broad Cybersecurity knowledge and experience of implementing and operating an effective control regime in a large, complex corporate environment.
  • Insurance or financial services is required.
  • Solid knowledge and understanding of Cybersecurity domains, including; application security, vulnerability management, network and cloud security, security operations (incident management), supplier risk management and cyber awareness.
  • Experience of effective Cyber Risk Management within a large corporate environment.
  • Encouraging positive relationships by influencing and building effective relations with individuals at various levels of seniority, up to and including C-level.
  • Outstanding communication to communicate to a wide range and seniority of contacts, including technical and non-technical audiences.
  • Demonstrable regulatory management experience.
  • Understanding and knowledge in delivering compliance standards, including; ISO27001, SOC 2, NYDFS

Nice To Haves

  • Experience of Compliance assurance and Audit practice is desirable.
  • Security certification (CISSP,CISM) is an advantage.

Responsibilities

  • Provide Cybersecurity reporting to leadership committees and Boards.
  • Represent Cybersecurity to appropriate Regulatory bodies.
  • Be responsible for the Cybersecurity strategy for the designated region, manage its delivery through the use of GCS capabilities and accelerate local control adoption.
  • Take charge of the colleague security culture program.
  • Represent the region / sub-region in the Security Incident Management process.
  • Remediation Management, e.g. Internal Audit findings, Cybersecurity Compliance and Conduct management.
  • Leading a Cybersecurity Risk committee to support cyber risk management.
  • Track remediation of Cybersecurity Audit and Compliance findings.
  • Review Cybersecurity Metrics and lead remediation programs within the area / sub-area.
  • Lead or Sponsor Cybersecurity initiatives within area of accountability.
  • In conjunction with Data Privacy ensure necessary security controls are in place.
  • Handle GCS Service delivery critical issues.
  • Support GCS project implementation within the assigned area of accountability.
  • Make valuable contributions to the ‘voice of the Business’ in development of GCS service improvements.
  • Cybersecurity Intake & Relationship Management, regulatory & compliance assessment support
  • Continuity and disaster recovery support along with data governance support.
  • Represent Cybersecurity on Client calls or critical issues.
  • Provide first line security advice, mentorship and Policy and Standard support to Client teams.
  • Support the engagement of GCS services via the correct process.

Benefits

  • a 401(k) savings plan with employer contributions
  • an employee stock purchase plan
  • consideration for long-term incentive awards at Aon’s discretion
  • medical, dental and vision insurance
  • various types of leaves of absence
  • paid time off, including 12 paid holidays throughout the calendar year
  • 15 days of paid vacation per year
  • paid sick leave as provided under state and local paid sick leave laws
  • short-term disability and optional long-term disability
  • health savings account
  • health care and dependent care reimbursement accounts
  • employee and dependent life insurance and supplemental life and AD&D insurance
  • optional personal insurance policies
  • adoption assistance
  • tuition assistance
  • commuter benefits
  • an employee assistance program that includes free counseling sessions
  • two “Global Wellbeing Days” each year
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service