Jobs and Careers
SC

Systems & Security Engineer

SCOR
United Statesfull_timeVerifiedPosted 9 Jun 2025
πŸ’° $125,000/yr($102,000/yr – $125,000/yr)

About the role

Accountable for Confidentiality, Integrity, and Availability of the Velogica data, systems and cloud computing environment, ensuring policy and control frameworks are current, appropriate, respected, and evidenced for audit.Β  Additionally, facilitate audits, especially SOC 2 Type II, customer inquiries related to these areas, and support collaborative security/compliance efforts with the larger SCOR community.Β  This is a technical security role with a mix of security design, operations, and local policy setting in addition to supporting SOC 2 audits and client requirements.

  • Develop, maintain, implement, and enforce Information Security policies, standards, procedures, guidelines, controls, best practices, and technical solutions for the Velogica department, including, but not limited to:
  • Lead the Velogica SOC 2 Type II, ISO 27001 efforts.
  • Facilitation of SOC 2/ISO 27001 policy creation, review, and updates, and associated annual audits with third-party auditors and internal control owners.
  • Coordination of classification, labeling and control of SCOR Velogica information assets.
  • Internal Computer Incident Response Team (CIRT) planning to address security breaches.
  • Direction of business continuity and disaster recovery planning, including at least annual testing.
  • Champion DevSecOps principles by ensuring security measures are embedded by design in systems and products and facilitate adoption efforts for the Velogica US team.
  • Work with external clients to respond to client security assessments, review and negotiate security related contract language, and conduct ongoing periodic reviews as required.
  • Coordinate all security-related activities with IT functions, cloud, infrastructure, application development, data teams, Human Resources, Legal counsel, the SCOR global security office and the Velogica business unit.
  • Coordinate vulnerability assessments, security reviews, and investigations (Information Security Assessments), including annual due diligence for all technology and data vendors.
  • Develop remediation plans to address weaknesses identified from Information Security Assessments and regularly communicate status of plan to appropriate management.
  • Support action on critical alerts and develop incident response plans.
  • Work with the Global Security and Compliance team to support projects and requirements.
  • Function effectively as a self-directed, independent decision-maker.
  • Stay current with existing and emerging security technologies and develop strategic plans that meet company information security standards and lead to improved information security.
  • Participate in security industry user groups and conferences to ensure up to date knowledge of industry trends.
  • Create and maintain operational documentation as required.Β 
  • Adhere to Information Security policies and best practices, including security awareness training and other information protection initiatives.
  • On-call availability for emergency information security analysis or corrective action is a requirement of this job.
  • Other duties as required for the position.

Member of the following committees: e.g., Audit committee, Investment Committee etc.

  • Velogica US Steering Committee – approves policies and controls for the Velogica US organization relevant to security and compliance
  • Velogica Software Engineering Process Group (VSEPG) – approves changes relevant to SDLC
  • BS degree in Computer Science, Information Security, Engineering, Mathematics or equivalent experience
  • At least 6 years in an information security role, or related IT role with understanding of information security principles, and information security-related technologies and productsΒ 
  • Strong background in Information Security and security vulnerability identification and remediation, with a preference for cloud-based security strategies (and AWS experience in particular).
  • Relevant certifications, preferred.
  • Knowledge AICPA SOC 2 framework and ISO 27001 Standards, preferred.
  • Insurance or Reinsurance experience, preferred.
  • Influence, management, presentation, risk assessment and facilitation skills
  • Effective interpersonal communication skills and ability to direct colleagues
  • Vendor management experience
  • Software development knowl

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights β€” in under 60 seconds.

Apply Now β†’Generate Application Kit

Free account required β€” sign up in 30s

Company

SCOR

View company profile β†’