InfoSec Program Requirements, Tools and Processes Advisor Lead
USAAAbout the role
Why USAA?
At USAA, our mission is to empower our members to achieve financial security through highly competitive products, exceptional service and trusted advice. We seek to be the #1 choice for the military community and their families.
Embrace a fulfilling career at USAA, where our core values – honesty, integrity, loyalty and service – define how we treat each other and our members. Be part of what truly makes us special and impactful.
The Opportunity
As a dedicated InfoSec Program Requirements, Tools and Processes Advisor Lead, you will provide information assurance capabilities through technical consultation and guidance to the business for the interpretation and assessment of information security risk for projects, technologies, and environments. You will aim to identify and manage existing and emerging risks and integrate risk management strategies and educate risk owners across the enterprise on information security requirements and best practices. You will also ensure risks associated with business activities are effectively identified, measured, monitored and controlled and administer and implements systems, policies and processes which serve to enhance the mitigation, reporting, and analysis of Information Security risk.
We offer a flexible work environment that requires an individual to be in the office 4 days per week. This position can be based in one of the following locations: San Antonio, TX, Plano, TX, Phoenix, AZ, Colorado Springs, CO, Charlotte, NC, Chesapeake, VA or Tampa, FL. Relocation assistance is available for this position.
What you'll do:
- Influences and leads team efforts across the Information Security department and enterprise as a subject matter expert in their domain.
- Develops, publishes, maintains and/or interprets highly complex Information Security governance requirements (e.g. policies and standards).
- Collaborates with business operations to resolve Information Security governance conflicts.
- Leads in the optimization, execution, and maintenance of repeatable methods and measurements for the Information Security risk management program in alignment with business objectives.
- Leads, performs and reviews security risk assessments of complex projects, new technologies, business partners and third parties.
- Collaborates on Information Security risk management strategies with senior executive risk owners to enable risk-based decisions; educates and recommends risk treatment best practices in alignment with business objectives.
- Provides oversight on consulting (advice, guidance and assistance) to the enterprise, focusing on Information Security risk, to guide the strategic security direction of USAA.
- Responds both verbally and in writing to complex inquiries and periodic exams from both internal control partners (e.g. legal, compliance, audit, risk) and external control partners (e.g. regulators, external auditors, third parties).
- Contributes to the optimization and execution of methods to improve future inquiry responses.
- Provides oversight and peer-review of responses.
- Leads and provides guidance to team for identification, development, and testing of Information Security controls for risk mitigation effectiveness.
- Maintains expert level knowledge of USAA Information Security standards as well as industry information security best practices, frameworks, laws and regulations.
- Ensures risks associated with business activities are effectively identified, measured, monitored, and controlled in accordance with risk and compliance policies and procedures.
What you have:
- Bachelor’s degree; OR 4 years of related experience (in addition to the minimum years of experience required) may be substituted in lieu of degree.
- 8 years of work experience in three or more of the eight areas Security and Risk Management, Asset Security, Security Architecture and Engineering, Communication and Network Security, Identity and Access Management (IAM), Security Assessment and Testing, Security Operations, and/or Software Development Security.
- 6 years of related experience in conducting risk assessments, recommending risk treatment options and/or developing program governance (e.g. policies and standards).
- Expert level of business acumen in the areas of business operations, risk management, industry practices and emerging trends.
- Advanced risk management experience in a complex institution and/or highly matrixed environment related to banking, insurance and/or financial services.
- Advanced knowledge of current IT risks and experience implementing security solutions.
- Knowledge of a wide range of security technologies, such as network security, database security, tokenization platforms, Data Leakage Preve
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s
Similar roles
Lead IT Cybersecurity Specialist (INFOSEC)
Patent and Trademark Office
$187,093/yr
IT SPECIALIST (INFOSEC)
Pension Benefit Guaranty Corporation
$187,903/yr
IT Program Manager (ENTARCH/INFOSEC)
Offices, Boards and Divisions
$197,200/yr