AVP, Incident Response
CNA InsuranceAbout the role
You have a clear vision of where your career can go. And we have the leadership to help you get there. At CNA, we strive to create a culture in which people know they matter and are part of something important, ensuring the abilities of all employees are used to their fullest potential.
CNA seeks to offer a comprehensive and competitive benefits package to our employees that helps them — and their family members — achieve their physical, financial, emotional and social wellbeing goals.
For a detailed look at CNA’s benefits, check out our Candidate Guide.
JOB DESCRIPTION:
Essential Duties & Responsibilities
Performs a combination of duties in accordance with departmental guidelines:
Establishes and governs the Hybrid Security Operations Center (SOC) and technologies supporting it (including but not limited to SIEM, SOC Management, NDR, Case Management, Detection Management tools, and etc.).
Develops and manage leadership team for managing SOC and supporting groups.
Manages MSSP relationship end-to-end
Leads and Manages Computer Security Incident Response Team (CSIRT/IR)
Serves as the subject matter expert for all information security incident responses for the enterprise globally (including data, Third-Party, and other incidents).
Provides governance for and leads the information security response process.
Directs the response to escalated security events and drives the security incident response process on a local, national, and global level, as necessary.
Participates in and leads the Incident Response Committee.
Partners with CNA leadership on response strategies for enterprise-wide information security incidents.
Leads the evaluation, development, and implementation of Incident Response Plan, information security standards, procedures, and guidelines across diverse system platforms, application environments.
Ensures proactive compliance with security standards across the enterprise and global regulatory compliances (SEC, GDPR, OSFI, and etc.)
Works with senior Technology, Legal, and business leaders on potential data breaches.
Collaborates with and supports Technology, Human Resources, Legal, TPRM, and other key stakeholders.
Provides end-to-end problem management and root cause analysis for security incidents across the enterprise.
Leads post-incident debriefings to identify system environment, process, and/or security standard improvements.
Performs and/or directs independent analysis of complex problems and threats, providing clear and decisive mitigation strategies.
Conducts external investigations and research in partnership with Threat Intel team on sponsored actors in other countries to develop strategies and tactics for security responses.
Actively communicates with CNA leadership team and key IT and business stakeholders on metrics, measures, and potential new threats.
Works with technology Leadership to proactively develop and monitor information security strategies to protect the enterprise from existing and future threats.
Stays up to date on current attack risks, trends, and breaches across industries through independent and collaborative research.
Utilizes state-of-the-art tools and analyses from leading government and information security firms to continually enhance the organization’s information security readiness.
May perform additional duties as assigned.
Reporting Relationship
Typically reports to VP or above.
Skills, Knowledge & Abilities
In-depth understanding of SOC, SIEM, MSSP, DLP and the CSIRT process.
Proven experience with industry-standard security technologies, such as NDR, Threat Detecti
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s