Jobs and Careers
SO

Information Security Officer

Sompo
Purchase, NY, United States, United Statesfull_timeVerifiedPosted 6 Aug 2026
💰 $225,000/yr($180,000/yr$225,000/yr)

About the role

Job Description

Sompo has a unique opportunity for an Information Security Officer to join our Information Security team.

This role will manage and continuously modernize our Information Security program for global operations, while maintaining alignment with external and corporate requirements.   The Information Security Officer will manage more than 7,000 users, hundreds of developers and IT staff working in a range of technologies, more than 10,000 network devices and 75+ physical and cloud locations.

Location: This position can be based out of any of our US offices such as Purchase, NY / New York City / Morristown, NJ / Conshohocken, PA / Charlotte, NC or our UK office . We strive for collaboration which is why we offer a work environment where our employees thrive and develop long lasting careers.

Our business, your impact, our opportunity:

What you’ll be doing:

  • Maintaining an effective set of technical security controls across all systems and processes.  Controls must have documented designs and real-time instrumentation.   Core domains include:

    • malicious activity prevention and detection

    • encryption

    • data loss prevention and detection

    • activity/audit logging, especially for privileged identities and access

    • adversarial simulation

  • Detecting, reporting, and escalating vulnerabilities to the operational teams that support those vulnerable systems or processes.    Maintaining org-wide vulnerability data for both periodic and threat-drive real time reporting

  • Operating an efficient, instrumented, and effective security alerting function that is continuously evolving to match Sompo’s threat environment

  • Maintaining an efficient and tested incident response procedure capable of handling events of any scale

  • Participating in the systems development lifecycle to ensure alignment with our information security program

  • Establishing a communications program to keep all Sompo users aware of emerging threats, upcoming policy changes, recent achievements, and general security recommendations.

What you’ll bring:

  • Minimum of 15 years of experience in a combination of technical, security, and risk management roles

  • Minimum of 7 years in a senior management role within an information security function.

  • Technical familiarity with security patterns, operations and controls for traditional (Windows), cloud, and SaaS environments Systematic thinking – understanding the place of security controls within the larger operating environment, anticipating issues and engaging colleagues to minimize disruption (or the potential for it).  

  • Structure projects and programs in risk-prioritized manner.

  • Experience integrating regulatory requirements, corporate policies, and industry standards into operating procedures and designs Experience maintaining and communicating security strategy and technical architecture.

  • Ability to translate operational metrics into meaningful KPIs and risk quantifiers.

  • Excellent written, verbal and interpersonal communications with a range of audiences, including non-technical leaders, customers, regulators, and technical colleagues.

  • Experience maintaining a fast-changing security program with continuous improvement driven by changes in: threat intelligence and adversary tactics operational metrics company priorities Leadership experience managing a hybrid team of: direct reports (including ongoing professional development) matrix reports managed services and specialist contractors.

  • Bachelor’s degree in computer science, information security, or a related field.

  • Recognized information security certification (CISSP, CISM, etc.).

Preferred Qualifications:

  • Prior experience with adoption of FAIR Threat modeling within the SDLC Familiarity with DevSecOps processes, tooling, and controls Experience gaining and maintaining certifications like ISO 270xx, SOC 2, etc.

  • Knowledge of regional security data privacy regulations related to Minimization Encryption Cross-border data access

Salary Range: $180,000 – $225,000 Actual compensation for this role will depend on several factors including the cost of living associated with your work location, your qualifications, skills, competencies, and relevant experience.

 

At Sompo, we recognize that the talent, skills, and commitment of our employees drive our success. This is why we offer competitive, high-quality compensation and benefit programs to eli

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Sompo

View company profile →