Jobs and Careers
DA

Group Information Security & Risk Manager

Davies North America
Remote, US | Home Based, US, United StatesRemotefull_timeVerifiedPosted 23 Jul 2024

About the role

About Us

At Davies, we get it... you are not just looking for a job, you are looking to build a life and a career. We believe in our people and realize that our success is a direct result of creating a learning atmosphere, leadership opportunities, and promoting from within. We believe that engaging in corporate social activities and working together as a team is a vital part of the Davies culture.

 

With a multinational global team, Davies Group is a specialist professional services and technology firm working in partnership with leading insurance, highly regulated, and global businesses.  At Davies Group, we help clients to manage risk, operate core business processes, and to transform and grow. We deliver operations, consulting and technology solutions across the risk and insurance value chain, including excellence in claims, underwriting, distribution, regulation, customer experience, human capital, transformation, and change management. 

 

Are you looking for a company that is Dynamic and Innovative where the employees are Connected and Succeed Together?  If so, Davies may just be the right choice for you.

 

Davies is a community of outstanding people. We welcome different perspectives, support each other’s ambitions and grow together. In a fast-changing business environment, we adapt and look ahead. We succeed because we are multi-talented: in the skills of our teams, specialisms, and sector expertise. Working together, we are greater than the sum of our parts.

 

Job Overview 

Davies North America is looking for an experienced Group Information Security Risk Manager to help drive our function through the next phase of our maturity.  Reporting to the CISO, you will ensure information security risks are identified and assessed throughout all Divisions of our Global business, making appropriate recommendations for risk management, and implementing robust reporting mechanisms to allow the CISO clear oversight of our Information Security Risk Posture.

 

To be successful in this role, utilizing our established ISO 27001(2022) framework and committed to increasing capability within the Risk Management space, you need to be a confident Information Security practitioner who can enable the business to achieve its objectives in a safe and secure manner within an appropriate and proportionate set of controls, policies and procedures. You will need to provide advice and guidance and be able to synthesize this information into directional risk-based monitoring and reporting.  You must have significant experience of implementing and maintaining Global Information Security/Cyber and Risk frameworks. (ISO 27001 family, NIST CSF, CIS, NYC500) with 10 Years plus working across Security domains in large organizations. You need to be able to demonstrate experience of assessing and managing risk, including 3rd party in addition to having Security Incident Response experience and preferably hold a professional certification (ISO 27001 Lead implementer/CISM/CISSP/CRISC).   

 

Additionally, you will have peers across Cyber, Data Governance, Data Privacy and Information Assurance and will work collaboratively across these areas and the wider Governance, Risk and Compliance (GRC) function to ensure a cohesive approach to Information Security Risk Management.  With Davies being a globally expanding business, this role currently has direct reports in the UK, US and India, although a home-based role there is the expectation to travel for business purposes on occasion both nationally and internationally.

 

Responsibilities and Duties

  • Develop, revise or implement the Information Security Governance processes, policies and standards to support complex decisions or emerging threats; also update to comply with legislation and regulation
  • Lead the Information Security training and awareness program, ensuring that colleagues understand how their work contributes to security of the department, organization, and business goals
  • Produce Information Security requirements for third parties and/or compliance processes; work with the wider GRC team to ensure risks are identified and managed
  • Develop Information Security risk management strategies and controls, considering business needs and risk assessments, and balancing technical, physical, procedural and personnel controls
  • Lead complex risk assessments, interfacing routinely with senior management
  • Create and mai

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Davies North America

View company profile →