Senior Security Engineer, Endpoint
Corebridge FinancialAbout the role
Who We Are
At Corebridge Financial, we believe action is everything. That’s why every day we partner with financial professionals and institutions to make it possible for more people to take action in their financial lives, for today and tomorrow.
We align to a set of Values that are the core pillars that define our culture and help bring our brand purpose to life:
• We are stronger as one: We collaborate across the enterprise, scale what works and act decisively for our customers and partners
• We deliver on commitments: We are accountable, empower each other and go above and beyond for our stakeholders
• We learn, improve and innovate: We get better each day by challenging the status quo and equipping ourselves for the future
• We are inclusive: We embrace different perspectives, enabling our colleagues to make an impact and bring their whole selves to work
About the role
The AVP II, GRC Policy and Controls serves a critical role in securing Corebridge Financial from potential weaknesses in the information security control environments of its third parties. The role is responsible for operating existing processes to manage information security third-party risk as well as building new capabilities that enhance the security posture of the organization. The role works closely with members of the Information Security Office, Enterprise Risk Management, Third-Party Risk Management Governance, and contract owners across the organization to identify and mitigate third-party information security risk.
We want to hear from you today if you can:
- Conduct third-party security assessments.
- Review and validate third-party responses to questionnaires pertaining to their security control environment.
- Identify, rate, communicate and track assessment findings, risk treatments, and drive for results.
- Conduct continuous monitoring third parties and initiate cyber event investigations.
- Coordinate third-party cyber events.
- Fulfill third-party risk reporting requirements.
- Collaborate effectively with partner teams.
- Contribute to standard operating procedure documentation.
- Assess and enhance the control environment by identifying gaps and recommending improvements.
- Support internal and external audits by coordinating evidence of control effectiveness and policy adherence.
Please note: The job can only be performed in the State locations listed: Houston, TX and Raleigh, NC
What we are looking for:
- Bachelor’s degree in information security, computer science, or related discipline, or equivalent work experience.
- 5+ years of third-party IT/Cyber Security assessment experience.
- Proven experience in third-party security solutions including due diligence and continuous monitoring.
- Experience with third-party security strategies, plan development, and operational maintenance.
- Experience with assessing the information security control environments of third parties.
- Experience with enterprise-oriented third-party risk management platforms.
- Experience in evaluating third-party security solutions and processes, identifying gaps, and implementing plans to mature a third-party risk management program.
- Experience utilizing industry standard third-party questionnaires such as Shared Assessments SIG and Cloud Security Alliance CAIQ.
- In-depth understanding of the third-party lifecycle.
- Ability to document tactical and strategic approaches for third-party security enhancements.
- Ability to manage multiple priorities, escalate when needed, do the right thing, and build relationships.
- Experience with regulatory compliance requirements (e.g., GDPR, NYDFS, SOX) and industry frameworks (e.g., NIST, PCI-DSS, ISO 27001).
- Excellent written and verbal communication skills with the ability to articulate complex concepts to diverse audiences.
- Strong analytical and problem-solving skills with a focus on continuous improvement.
- Ability to collaborate across departments and influence stakeholders at all levels.
For position based in Jersey City, NJ, the base salary range is $130,000 - $150,000 and the position is eligible for a bonus in accordance with the terms of the applicable incentive plan. In addition, we're proud to offer a range of competitive benefits.
#LI-SAFG #LI-CW1 #LI-Hybrid
This role is deemed a “covered associate” under SEC Rule 206(4)-5, 17 CFR § 275.206(4)-5, Political contributions by certain investment advisers, and other federal and state pay-to-play rules. Candidates for the role must not have made any politi
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s