Director of Information Security

PMA Companies

Center Square (PA)

On-site

USD 150,000 - 230,000

Full time

19 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

PMA Companies seeks a Director of Information Security to design, implement, and operate a comprehensive security program across three affiliated entities. The role blends technical leadership with risk governance and compliance oversight, serving as a trusted advisor to executives and clients.

The candidate will lead a small team, stay hands-on in security operations, and partner with IT and engineering to secure cloud and hybrid environments while driving risk remediation and meaningful risk

Qualifications

  • Bachelor’s degree in Information Security, Computer Science, Information Systems, or related field, or equivalent experience.
  • 8+ years of progressive information security experience with leadership or senior technical roles.
  • Proven experience mentoring small security teams and leading risk assessments.

Responsibilities

  • Lead and mentor a small, highly technical information security team with hands-on support.
  • Design, implement, and maintain security controls across identity, endpoint, network, cloud, and SaaS environments.
  • Oversee security incidents, investigations, and response activities with clear escalation paths.
  • Represent security in governance across three affiliated companies and align with business goals.
  • Deliver risk assessments and communicate risk exposure to non-technical stakeholders.
  • Drive ITGCs, audits, and regulatory/commercial requirements (DOI, NYDFS 23 NYCRR 500).

Skills

Security leadership
Risk management
GRC oversight
Hands-on operations
Mentorship
Identity & Access Management
Cloud security
Security incident response
Regulatory compliance
Communication to executives

Education

Bachelor's degree in Information Security/CS/IS

Tools

Okta
Azure AD
Microsoft 365
Proofpoint
Splunk
CrowdStrike

Job description

The Director of Information Security is a senior, hands‑on leader responsible for designing, implementing, and operating a comprehensive information security program across three affiliated companies. This role combines technical security leadership, risk management, and governance, risk, and compliance (GRC) oversight.

The ideal candidate is a player‑coach who can lead a small team while remaining deeply engaged in day‑to‑day security operations and architecture. This individual will serve as a trusted advisor to business leaders, management, and external clients, translating complex security risks into clear, actionable business terms.

  • Lead and manage a small, highly technical information security team, providing mentorship, direction, and hands‑on support.
  • Design, implement, and maintain security controls across identity, endpoint, network, cloud, and SaaS environments.
  • Provide direct technical oversight and escalation support for security incidents, investigations, and response activities.
  • Ensure consistent security posture and standards across three separate companies while accommodating business‑specific needs.
  • Act as a subject matter expert and hands‑on contributor for core security platforms, including:
  • Identity & Access Management: Okta, Azure AD
  • Productivity & SaaS Security: Microsoft 365
  • Email Security: Proofpoint
  • Security Monitoring & SIEM: Splunk
  • Partner with IT and engineering teams to securely design and deploy cloud and hybrid environments.
  • Continuously evaluate and enhance security tooling, configurations, and detection capabilities.
  • Lead enterprise security risk assessments to identify, analyze, prioritize, and document information security risks.
  • Clearly communicate risk exposure and mitigation strategies to non‑technical business users, executive management, and clients.
  • Drive risk remediation efforts, tracking progress and ensuring accountability.
  • Integrate security risk management into broader enterprise risk management processes.
  • Own and operate the information security governance program, including policies, standards, procedures, and metrics.
  • Ensure the design and effectiveness of IT General Controls (ITGCs).
  • Support internal and external audits, including planning, evidence collection, remediation, and ongoing control improvements.
  • Maintain compliance with applicable regulatory and contractual requirements, with emphasis on:
  • State Department of Insurance (DOI) data security regulations
  • New York Department of Financial Services (NYDFS) 23 NYCRR 500
  • Partner with Legal, Compliance, and Audit teams to ensure alignment between security, regulatory, and business objectives.
  • Serve as a key security liaison for:
  • Executive and senior management
  • External clients, partners, and auditors
  • Translate technical security concepts into clear, business‑focused language appropriate for each audience.
  • Prepare and deliver security briefings, risk summaries, and compliance updates to leadership.
  • Demonstrate commitment to Company's Code of Business Conduct and Ethics, and apply knowledge of compliance policies and procedures, standards and laws applicable to job responsibilities in the performance of work.
Requirements
  • Bachelor's degree in Information Security, Computer Science, Information Systems, or a related field (or equivalent experience).
  • 8+ years of progressive experience in information security, including leadership or senior technical roles.
  • Proven experience managing and mentoring small security teams.
  • Strong hands‑on technical expertise in:
  • Proofpoint, CrowdStrike, Splunk
  • Demonstrated experience leading security risk assessments and remediation initiatives.
  • Strong background in governance, risk, and compliance, including IT general controls and audit support.
  • Experience working in regulated environments, preferably financial services or insurance.
Preferred Qualifications
  • Prior experience supporting State Department of Insurance data security regulations.
  • Direct experience with NYDFS 23 NYCRR 500 compliance.
  • Audit background (internal audit, external audit, or security assurance).
  • Relevant certifications such as CISSP, CISM, CRISC, CGEIT, or similar.
  • Hands‑on, pragmatic security leader with a strong bias toward execution.
  • Excellent verbal and written communication skills.
  • Ability to balance security rigor with business enablement.
  • Strong organizational and prioritization skills across multiple companies and stakeholders.
  • High integrity, sound judgment, and comfort operating with limited oversight.
Alternate Location(s)

Philadelphia , Pennsylvania , United States

This Company is an Equal Opportunity Employer, and does not discriminate on the basis of race, gender, ethnicity, religion, national origin, age, disability, veteran status, or on any other basis prohibited by law. Information on race, gender and national origin will only be used for statistical and recordkeeping purposes, and will not be used in making any employment decisions. All information provided will be kept separate from your expression of interest. Providing this information is strictly voluntary, and you will not be subjected to any adverse action or treatment if you choose not to provide this information. If you do not choose to answer these questions, we ask that you select "Decline to Identify" for each question. Thank you for your voluntary cooperation.

Get your free, confidential resume review.

or drag and drop your file here.