Director, Information Security - Privileged Access Management
USAAAbout the role
Why USAA?
At USAA, our mission is to empower our members to achieve financial security through highly competitive products, exceptional service and trusted advice. We seek to be the #1 choice for the military community and their families.
Embrace a fulfilling career at USAA, where our core values – honesty, integrity, loyalty and service – define how we treat each other and our members. Be part of what truly makes us special and impactful.
We are proud to support active-duty military spouses. USAA roles may offer remote or hybrid flexibility for active-duty military spouses consistent with applicable policy and business needs.
The Opportunity
As a dedicated Information Security Director, you will lead USAA’s enterprise Privileged Access Management program and play a critical role in protecting the organization from risks associated with privileged and elevated access. The role owns the PAM strategy and roadmap while driving the implementation and ongoing effectiveness of privileged account governance, credential management, session management, and least-privilege capabilities across the enterprise.
As the senior product owner and PAM subject matter expert, this leader will work closely with cybersecurity, engineering, audit, risk, compliance, legal, and business stakeholders to prioritize investments, deliver security solutions, and meet regulatory commitments. The Director will provide strategic and operational leadership, oversee vendor relationships, manage remediation efforts, and report program performance and risk to senior leadership. Success will require strong PAM expertise, executive presence, cross-functional influence, and experience delivering enterprise security programs within a highly regulated organization.
We offer a flexible work environment that requires an individual to be in the office 4 days per week. This position can be based in one of the following locations: San Antonio, TX, or Plano, TX. Relocation assistance is not available for this position.
What you'll do:
- Responsible for strategic ownership of critical security domains or capabilities, develops multi-year roadmaps and/or a leader of Manager Seniors.
- Establishes and ensures compliant execution of their information security domain's short- and long-term strategic vision, strategy, goals, and metrics and governs the overall policies, standards, and procedures for their assigned information security domain.
- Directs and ensures effective operation of an enterprise information security domain including capacity, resilience and dependability capabilities and how changes in conditions, operations, or the environment will affect the system's operation.
- Develops, reviews and communicates information security risk management policies and procedures in partnership with the Chief Information Security Officer (CISO) and other senior leaders to ensure appropriateness and adequacy versus industry best practices and regulatory requirements.
- Interfaces with external regulators to represent USAA in discussions regarding their specific information security domain.
- Oversees the continuous monitoring of cybersecurity activities and alerts senior management to potential risks, compliance issues, and operational inefficiencies.
- Develops, designs, and delivers a sustainable governance and assurance model across multiple domains and the Enterprise.
- Identifies, monitors and evaluates operational solutions to reduce information security risk, meet compliance requirements and increase enterprise workforce efficiency, business agility and workforce scalability.
- Promotes information security awareness across the enterprise and with the external security community.
- Serves as financial steward for the organization and manages manpower and budgets to ensure they cost-effectively meet the needs of the organization.
- Builds and oversees a team of employees for assigned functional area through ongoing execution of recruiting, development, retention, coaching and support, performance management, and managerial activities.
- Ensures risks associated with business activities are effectively identified, measured, monitored, and controlled in accordance with risk and compliance policies and procedures.
What you have:
- Bachelor's degree in Information Security, Information Technology, Computer Science, Business Administration, Information Systems/Management, or related field; OR 4 years of relevant education and/or experience.
- 8 years of related information security experience in one or more domains, e.g.: Cyber Security, Identity and Access Management, Information Assurance and Governance, Operational Risk Management and/or Information Technology to include significant accountability for projects
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s
Similar roles
Director, Product Services & Management - Epic Revenue Cycle Modules
Northwell Health
Senior Director, Marketplace Performance and Strategy(Must Live In Massachusetts And Preferred Experience In Duals Plans & Medical Equipment)
CareSource
$237,400/yr
Director, Business Analysis & Process Improvement (Enrollment) - REMOTE
Molina Healthcare