
Business Information Security Lead
Posted Aug 4

Posted Aug 4
This is a fully remote position, open to applicants in Alaska, +4 more states.
• Assist the Digital and Technology (DigiTech) value stream in executing initiatives.
• Direct the value stream to ensure adherence to security policies and best practices.
• Evaluate and confirm the effectiveness of the security program assurance.
• Track progress and ensure resolution of unresolved security issues.
• Provide consultation on critical business initiatives, identifying and managing risks comprehensively.
• Implement the security program with Value Stream partners by recognizing and addressing risks.
• Offer security expertise to support business decision-making and strategic planning.
• Communicate security requirements and potential impacts of regulatory or cyber threats to business partners.
• Act as the primary security contact and escalation point.
• Conduct audits, evaluate risks, and manage remediation stemming from security assessments, penetration testing, and internal investigations.
• Provide updates on security compliance status through metrics and vulnerability guidance.
• Deliver a monthly prioritized gap analysis, remediation strategies, and achievements to the Value Stream Lead.
• Mentor Product Teams on security tools and relevant information.
• Clearly express security implications in strategy and roadmap discussions.
• Collaborate with internal teams, auditors, vendors, and managed security service providers.
• Minimum of 5+ years of experience in information security.
• Comprehensive foundational knowledge across information and cybersecurity domains, particularly in security risk management and application security.
• Knowledge of PCI, HIPAA, SOX, NIST CSF, ISO 27001, and CIS standards.
• Proven ability to foster positive working relationships across diverse business areas.
• Capability to work independently and make decisions aligned with policies.
• Experience in measuring and monitoring cybersecurity risks, issues, and exceptions.
• Proficiency in presenting complex security topics to a variety of audiences, including senior technical leaders.
• Ability to advise, collaborate, and thrive in a team setting.
• Skill in influencing others without formal authority.
• Experience in executing security compliance plans, vulnerability management programs, risk management lifecycles, and/or security assessment/governance processes.
• Bachelor’s degree from an accredited institution or equivalent professional experience is required.
• Experience in developing, measuring, and tracking key performance indicators, ideally within a cybersecurity context.
• Highly organized, efficient, and detail-oriented.
• Proven track record of developing resources, mentoring, and providing career guidance.
• Strong written and verbal communication abilities.
• Proactive in self-development and aware of emerging threats, security trends, best practices, and regulatory requirements.
• SANS GSEC, GCIA, or related certifications, or CISSP are preferred but not mandatory.
• Annual incentive plan bonus.
• Health insurance.
• Pre-tax spending accounts.
• Retirement benefits.
• Paid time off.
• Short-term disability.
• Long-term disability.
• Employee stock purchase plan.
• Life insurance.
• Remote work options.
• Travel as required for business purposes.
Legacy Community Health
NeoGuardian
Fresh Consulting
CrowdStrike
Get handpicked remote jobs straight to your inbox weekly.