Director of Information Security

externalpmacompanies

Pennsylvania

On-site

USD 150,000 - 230,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

External PMA Companies seeks a Director of Information Security, a senior, hands-on leader responsible for designing, implementing, and operating a comprehensive information security program across three affiliated companies. The role blends technical leadership, risk management, and GRC oversight.

The ideal candidate is a player-coach who leads a small team while remaining deeply involved in day-to-day security operations, architecture, and advisory work for leadership and clients.

Qualifications

  • Bachelor's degree in Information Security, Computer Science, Information Systems, or related field.
  • 8+ years of progressive experience in information security, including leadership or senior technical roles.
  • Proven experience managing and mentoring small security teams.
  • Hands-on technical expertise in Okta, Zscaler, Azure, Microsoft 365.
  • Experience with Proofpoint, CrowdStrike, Splunk.
  • Strong governance, risk, and compliance background including IT general controls and audit support.

Responsibilities

  • Lead and manage a small, highly technical information security team with mentorship and hands-on support.

Skills

Security leadership
Risk management
GRC
Executive communication
Mentoring
Okta
Azure AD
Zscaler
Microsoft 365
Proofpoint
CrowdStrike
Splunk
ITGCs
Audit support

Education

Bachelor's degree in Information Security

Tools

Okta
Zscaler
Azure
Microsoft 365
Proofpoint
CrowdStrike
Splunk

Job description

The Director of Information Security is a senior, hands‑on leader responsible for designing, implementing, and operating a comprehensive information security program across three affiliated companies. This role combines technical security leadership, risk management, and governance, risk, and compliance (GRC) oversight.

The ideal candidate is a player‑coach who can lead a small team while remaining deeply engaged in day‑to‑day security operations and architecture. This individual will serve as a trusted advisor to business leaders, management, and external clients, translating complex security risks into clear, actionable business terms.

  • Lead and manage a small, highly technical information security team, providing mentorship, direction, and hands‑on support.
  • Design, implement, and maintain security controls across identity, endpoint, network, cloud, and SaaS environments.
  • Provide direct technical oversight and escalation support for security incidents, investigations, and response activities.
  • Ensure consistent security posture and standards across three separate companies while accommodating business‑specific needs.
  • Act as a subject matter expert and hands‑on contributor for core security platforms, including:
    • Identity & Access Management: Okta, Azure AD
    • Network & Cloud Security: Zscaler, Azure
    • Productivity & SaaS Security: Microsoft 365
    • Email Security: Proofpoint
    • Endpoint Protection: CrowdStrike
    • Security Monitoring & SIEM: Splunk
  • Partner with IT and engineering teams to securely design and deploy cloud and hybrid environments.
  • Continuously evaluate and enhance security tooling, configurations, and detection capabilities.
  • Lead enterprise security risk assessments to identify, analyze, prioritize, and document information security risks.
  • Clearly communicate risk exposure and mitigation strategies to non‑technical business users, executive management, and clients.
  • Drive risk remediation efforts, tracking progress and ensuring accountability.
  • Integrate security risk management into broader enterprise risk management processes.
  • Own and operate the information security governance program, including policies, standards, procedures, and metrics.
  • Ensure the design and effectiveness of IT General Controls (ITGCs).
  • Support internal and external audits, including planning, evidence collection, remediation, and ongoing control improvements.
  • Maintain compliance with applicable regulatory and contractual requirements, with emphasis on:
    • State Department of Insurance (DOI) data security regulations
    • New York Department of Financial Services (NYDFS) 23 NYCRR 500
  • Partner with Legal, Compliance, and Audit teams to ensure alignment between security, regulatory, and business objectives.
  • Serve as a key security liaison for:
    • Non‑technical business staff
    • Executive and senior management
    • External clients, partners, and auditors
  • Translate technical security concepts into clear, business‑focused language appropriate for each audience.
  • Prepare and deliver security briefings, risk summaries, and compliance updates to leadership.
  • Demonstrate commitment to Company's Code of Business Conduct and Ethics, and apply knowledge of compliance policies and procedures, standards and laws applicable to job responsibilities in the performance of work.
Preferred Qualifications
  • Bachelor's degree in Information Security, Computer Science, Information Systems, or a related field (or equivalent experience).
  • 8+ years of progressive experience in information security, including leadership or senior technical roles.
  • Proven experience managing and mentoring small security teams.
  • Strong hands‑on technical expertise in:
    • Okta, Zscaler, Azure, Microsoft 365
    • Proofpoint, CrowdStrike, Splunk
  • Demonstrated experience leading security risk assessments and remediation initiatives.
  • Strong background in governance, risk, and compliance, including IT general controls and audit support.
  • Experience working in regulated environments, preferably financial services or insurance.
Key Competencies & Attributes
  • Hands‑on, pragmatic security leader with a strong bias toward execution.
  • Excellent verbal and written communication skills.
  • Ability to balance security rigor with business enablement.
  • Strong organizational and prioritization skills across multiple companies and stakeholders.
  • High integrity, sound judgment, and comfort operating with limited oversight.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Director of Information Security
Director of Information Security

PMA Companies • Center Square (PA)

On-site
USD 150,000 - 230,000
Senior Director, Cybersecurity Operations & Compliance
Senior Director, Cybersecurity Operations & Compliance

Ddn • Santa Clara (CA)

On-site
USD 150,000 - 210,000
IT Security Team Lead
IT Security Team Lead

Creative Capsule • United States

On-site
USD 140,000 - 180,000
Director | Information Security
Director | Information Security

hire.ventures • San Jose (CA)

On-site
USD 150,000 - 200,000
Senior Manager of Information Security
Senior Manager of Information Security

Plume • United States

On-site
USD 180,000 - 240,000
Group Director, Cyber Risk & Security Engineering
Group Director, Cyber Risk & Security Engineering

Brobston Group LLC • New York (NY)

On-site
USD 180,000 - 240,000
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000
Director, Cybersecurity
Director, Cybersecurity

Cybersecurity Jobs • Atlanta (GA)

On-site
USD 180,000 - 230,000
Director of Cyber Defense
Director of Cyber Defense

Career Techniques • Dallas (TX)

Hybrid
USD 180,000 - 280,000
Director IT Security
Director IT Security

84 Lumber • Eighty Four (PA)

On-site
USD 90,000 - 150,000