IT Risk & Security Manager
TravelersAbout the role
Who Are We?
Taking care of our customers, our communities and each other. That’s the Travelers Promise. By honoring this commitment, we have maintained our reputation as one of the best property casualty insurers in the industry for over 160 years. Join us to discover a culture that is rooted in innovation and thrives on collaboration. Imagine loving what you do and where you do it.
Job Category
TechnologyCompensation Overview
The annual base salary range provided for this position is a nationwide market range and represents a broad range of salaries for this role across the country. The actual salary for this position will be determined by a number of factors, including the scope, complexity and location of the role; the skills, education, training, credentials and experience of the candidate; and other conditions of employment. As part of our comprehensive compensation and benefits program, employees are also eligible for performance-based cash incentive awards.
Salary Range
$111,600.00 - $184,200.00Target Openings
1What Is the Opportunity?
At Travelers, Our Risk & Security Officers assess internal and external cyber and technology risks and design, test, and monitor the operational effectiveness of cyber and technology controls at Travelers and key third parties. They identify opportunities to improve cyber and technology posture, assist in recommending and prioritizing risk-based remediations, and monitor and report completion. This includes supporting and driving the cybersecurity strategy throughout the enterprise. Risk & Security Officers provide assurance and guidance over internal governance practices and training and awareness of cyber and technology policies. You will build and maintain strong partnerships with business customers, CIOs, Cyber, Corporate Legal and Corporate Audit.As a Manager, Risk & Security, you are the subject matter expert across disciplines for one or more assigned business areas and/or enterprise functions that identifies and analyzes multiple complex process for cyber risks. You will assess and monitor the associated controls for design and operational effectiveness. This is an individual contributor role.
What Will You Do?
- Function as a subject matter expert and consult across the enterprise to monitor risks, facilitate, and consult risk discussions, and support all compliance activities, including coordination of corporate audits.
- Drive the cybersecurity strategy into assigned business areas and/or enterprise functions including, but not limited to, vulnerability, access, and security management initiatives.
- Identify trends and recommend areas of improvement across the enterprise.
- Leverage deep understanding of controls and risk outcomes to manage risk and proactively identify areas of non-compliance, educate and influence business partners on risks and compliance concepts.
- Influence process improvement within assigned lines of business and begin to implement them.
- Strategically lead risk discussions across portfolio and drive standardized cyber and technology control processes and procedures.
- Recommend cyber and technology controls across multiple third-party platforms (i.e., cloud, network, and endpoint control fundamentals) to create a solution that assures risk mitigation. Coordinate efforts to enable solution across lines of business for enterprise benefit.
- Perform other duties as assigned.
What Will Our Ideal Candidate Have?
- Degree in Computer Science, Technology Auditing, or related field.
- 7 years’ experience in a risk management, audit, computer networking, network security or related role.
- COMPTIA, Security+, CRISC, CISSP, CISM, CISM or related cyber certifications.
- Knowledge of compliance concepts (i.e., PII, GDPR, PIPIDA, PCI DSS, FTC) to apply them to real world problems and identify gaps.
- Advanced technical knowledge of key security frameworks and assessments (SIG, SANS, NIST, PCI, SOC2, COBIT, SOX, ISO2700) and security principles and methods.
- In-depth understanding of Cloud, Network, Endpoint (etc.) controls and how the controls inter-play within a control environment.
- Excellent communication skills with the ability to interact with management.
- Ability to manage and lead multiple projects simultaneously and follow through to ensure timely completion.
What is a Must Have?
- Three years of Technology experience required.
- One year of IT Risk Management experience required.
What Is in It for You?
- Health Insurance: Employees and their eligible family members – including spouses, domestic partners, and children – are eligible for coverage from the fir
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s