Senior Cybersecurity Specialist - IT Policy & Control
Liberty Mutual InsuranceAbout the role
Description
We deliver our customers peace of mind every day by helping them protect what they value most. Our passion for placing the customer at the center of everything we do is driving a transformational shift at Liberty Mutual. Operating as a tech startup within a Fortune 100 company, we are leading a digital disruption that will redefine how people experience insurance.
At Liberty, you'll thrive in a hybrid setting that fosters in-person collaboration, innovation and growth. This approach optimizes both remote and in-person interactions, enabling you to connect and ideate with your team and deepen valuable relationships across the company, while still enjoying the flexibility of remote work for focused tasks and projects.
This role has a hybrid work schedule (2 days onsite) and we are considering candidates based in Portsmouth, NH, Boston, MA, Plano, TX, Indianapolis, IN and Columbus, OH.
Job Introduction:
At Liberty Mutual Insurance, we believe progress happens when people feel secure. Our Cybersecurity Specialists form a diverse team of security professionals who are collectively responsible for improving the overall security posture of the organization. They evaluate and manage risks, test the effectiveness and completeness of security controls, and partner with teams across the company to optimize our security posture while ensuring the business is able to innovate. Cybersecurity specialists must continually adapt to stay ahead of a dynamic threat & regulatory landscape. We are expected to continually learn and grow. This is not a passive career opportunity, but rather one that requires a passion for security and rigor to protect our business.
About the Cybersecurity Governance, Risk, and Compliance (Cyber GRC) Team
Our Cyber GRC team oversees IT compliance and cybersecurity risk using integrated tools and services that cover the full assessment lifecycle. From designing and documenting controls to testing and consulting on remediation, we work with teams company-wide to align security practices with regulatory requirements, cybersecurity frameworks, and organizational risk.
As a Senior Cybersecurity Specialist, you will be part of an agile team responsible for the governance of cybersecurity risk and compliance management processes. Under limited supervision and general direction, you will execute existing and design new processes to support risk and compliance assurance programs by evaluating and reporting on cybersecurity regulatory and contractual requirements. Additionally, you will assist with the execution of NIST CSF and ISO compliance programs. And lastly, you will enable stakeholders across technology to manage risk, compliance and audit issues to closure.
About the job:
- Support the design and implementation of governance workflows for compliance and risk management specifically policies and controls.
- Evaluate and assess compliance with regulatory requirements, contractual obligations, and industry frameworks.
- Collaborate with stakeholders to align and harmonize policy and standard content.
- Provide advice on the impact of changes in people, processes, and technology, recommending appropriate solutions.
- Communicate technical and non-technical information effectively to diverse audiences.
Qualifications
- Bachelor's or Master's degree in technical discipline or equivalent experience, technical degree preferred.
- Minimum 5+ years of Cybersecurity experience with focus on IT Policy & Controls.
- Experience at a financial or insurance company or consulting firm preferred.
- Ability to assess technologies and processes to identify risks and align them with authoritative sources and frameworks.
- Experience with cybersecurity controls, IT auditing, risk and regulatory assessments, and frameworks such as NIST Cyber Security Framework, ISO 27K (27001, 27002) and CIS Controls.
- Experience with financial services or regulated industry compliance requirements.
- Strong collaboration skills and a proactive approach to improving service and engagement.
- Ability to connect business drivers with compliance requirements.
- Skilled in integrating control frameworks and regulatory requirements into enterprise controls and advising on control design to meet cybersecurity risk and compliance needs.
- Experience with Agile methodologies and working within scrum ban teams.
- Strong negotiation, facilitation, and consensus-building abilities.
- Excellent oral and written communication skills; comfortable presenting to senior leadership.
- Strategic thinker with holistic understanding.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s