Director, Information Security Risk and Operations
AllianceBernsteinAbout the role
Who We Are:
As a leading global investment management firm, AB fosters diverse perspectives and embraces innovation to help our clients navigate the uncertainty of capital markets. Through high-quality research and diversified investment services, we serve institutions, individuals, and private wealth clients in major markets worldwide. Our ambition is simple: to be our clients’ most valued asset-management partner.
With over 4,400 employees across 51 locations in 25 countries, our people are our advantage. We foster a culture of intellectual curiosity and collaboration to create an environment where everyone can thrive and do their best work. Whether you're producing thought-provoking research, identifying compelling investment opportunities, infusing new technologies into our business, or providing thoughtful advice to clients, we’re looking for unique voices to help lead us forward. If you’re ready to challenge your limits and build your future, join us.
Who You'll Work With:
We are seeking a Nashville based Director of Information Security Risk and Operations to join our Infrastructure Risk Management team in Global Technology & Operations reporting directly to the Chief Information Security Officer.
Team/Group Description
The Infrastructure Risk Management (IRM) is a department within Global Technology and Operations (GTO) that operates an enterprise-wide integrated infrastructure risk management program which employs a holistic approach to manage cybersecurity, information security, data privacy, physical security and business continuity led by the Chief Security Officer.
What You'll Do:
The Director of Information Security Risk and Operations is a key enterprise role, reporting directly to the Chief Information Security Officer, for AllianceBernstein helping advance the overall cybersecurity program for the firm, responsible for identifying, evaluating and reporting on information security risks, overseeing cyber operations, threat & vulnerability management, and 3rd party security evaluations. The position will have direct reports.
Applications and business or enterprise functions the role supports
The Director of Information Security Risk and Operations will work with corporate IT, infrastructure services, identity access operations, business continuity management, data privacy and other business units.
Key job responsibilities include, but are not limited to
Oversee the company’s Threat & Vulnerability, Cyber Security Operations, Threat Hunting, Incident Response and Infrastructure Risk functions.
Manage the organizations 3rd party cyber risk exposer by overseeing 3rd party vendor security assessment function.
Lead security experts and manage technology to support a secure infrastructure; lead strategic security planning with technology and risk management teams and users across the company.
Coordinate use of external resources involved in the information security program including, but not limited to, interviewing, negotiating contracts and fees, and resource allocation.
Ensure the completion of annual information security risk assessments.
Implement a process for regularly validating security requirements for internally developed applications.
Coordinate information security projects with staff from the technology organization and business unit teams. Ensure the execution and review of internal and external network and systems vulnerability assessments, pen tests and Red Team assessments.
Provide security guidance for IT projects, including evaluation and adjustment of technical controls.
Support business functions with client due diligence questionnaire responses and attend client due-diligence reviews as needed.
Support external and internal audit assessment activities.
Develop, track, and report threat intelligence metrics and KPIs (Key Performance Indicators) to senior leadership.
Lead incident management and defense coordination against emerging cyber threats and critical vulnerabilities
Evaluate any new security services, software and technology for the functional areas of responsibility.
Ensure timely renewals of service contracts for areas of responsibility.
Maintain expertise in the area of Information and Cyber Security, including industry trends, strategies, new vulnerabilities and threats to ensure the company’s assets are effectively and appropriately secured.
Develop and maintain relationships with key stakeholders, including IT teams, business units, and external partners.
Monitor and analyze cyber security threats and trends and develop strategies to enhance the services mit
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s