Information Security Lead

SCOR Group

Charlotte (NC)

Hybrid

USD 150,000 - 230,000

Full time

6 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical coverage
401k plan
Defined contribution retirement
Life insurance
Disability insurance
Parental leave
Volunteer time
Summer Fridays
Learning & development resources
Wellness tools
Gym membership discounts

Job summary

SCOR Group seeks an Information Security Lead for Velogica US in Charlotte, NC, to own the security and compliance program. You will partner with global security teams to align local execution with the SDS roadmap, combining hands-on security with GRC leadership across SOC 2, ISO 27001, and client assurance.

You’ll manage cross-functional stakeholders, drive evidence collection, and ensure audit-ready controls while supporting DevSecOps, cloud security, and incident response.

Qualifications

  • Bachelor’s degree in computer science or related field; equivalent experience considered.
  • Master’s degree in cybersecurity or related discipline is advantageous but not required.
  • Certifications such as CISSP/CISM/CRISC/CCSP or ISO 27001 Lead Implementer are preferred.
  • Additional cloud security or DevSecOps training is a plus.
  • 7+ years of progressive information security, engineering, or operations experience.
  • Experience with SOC 2, ISO 27001/27002, NIST CSF, CIS Controls, COBIT or equivalent.
  • Hands-on security across Azure and GCP; experience harmonizing controls and assurance.
  • Ability to translate security requirements into practical operating controls.
  • Experience managing client-facing assurance activities and audits.

Responsibilities

  • Act as local lead for Velogica US security and compliance, coordinating with global teams.
  • Develop and maintain Velogica security and compliance policies and controls.
  • Lead SOC 2 Type II and ISO 27001 alignment efforts and audit readiness.
  • Harmonize security practices across SDS and Velogica US with common baselines.
  • Provide hands-on security guidance across cloud, DevSecOps, and secure SDLC.
  • Collaborate with engineering, data, product, legal, and vendor management teams to embed security in delivery.
  • Manage client security questionnaires, due diligence, and assurance discussions.
  • Coordinate penetration tests, remediation planning, and status reporting.
  • Support incident response planning, investigations, and post-incident actions.
  • Maintain audit-ready documentation, control evidence, risk registers, and action logs.

Skills

Information security
GRC management
SOC 2
ISO 27001
Cloud security (Azure/GCP)
DevSecOps
Vulnerability management
Risk management
Audit readiness
Stakeholder management

Education

Bachelor’s degree in CS/IS/Engineering or related field
Master’s degree in Cybersecurity/IS (advantageous)
Professional security certifications (CISSP/CISM/CRISC/CCSP)

Tools

Azure
GCP

Job description

Charlotte, North Carolina, United States

Job Description

The Information Security Lead is responsible for managing the security and compliance function for Velogica US, ensuring that data, systems, cloud environments, development practices, vendors, and assurance activities are protected, controlled, and audit ready. The role will operate as the local senior security and compliance lead for Velogica US, partnering closely with the SDS Global Security and Compliance team to align local execution with the broader SDS security and assurance teams’ roadmap. The position combines hands‑on technical security knowledge with strong GRC capability, including SOC 2, ISO 27001 compliance, risk management, vulnerability management, third‑party assurance, client security reviews, evidence management, and policy/control lifecycle management. The role will also help standardize and harmonize controls, evidence practices, tooling, and assurance processes between SDS and Velogica US, while maintaining effective local support for Velogica stakeholders and clients.

Responsibilities
  • Operate as the local lead for Velogica US security and compliance activities, managing day‑to‑day priorities independently while maintaining close alignment with the SDS Global Security and Compliance team.
  • Develop, maintain, implement, and improve Velogica security and compliance policies, standards, procedures, guidelines, controls, technical safeguards, and evidence practices in alignment with SDS Global Security and Compliance team‑defined control baselines.
  • Lead and coordinate Velogica US assurance activities, including SOC 2 Type II, ISO 27001 alignment, audit preparation, evidence collection, control owner coordination, audit remediation, and ongoing control monitoring.
  • Harmonize IT security and assurance practices between SDS and Velogica US by implementing common control baselines, repeatable processes, shared tooling, consistent evidence standards, and aligned reporting.
  • Provide hands‑on technical security guidance across cloud environments, application security, DevSecOps, AI/LLM risk management, vulnerability management, access control, logging/monitoring, incident response, business continuity, and secure SDLC practices.
  • Work with engineering, cloud, infrastructure, data, product, legal, HR, vendor management, privacy, and business stakeholders to ensure security and compliance requirements are embedded into operating practices and delivery processes.
  • Manage client‑facing security and compliance activities, including client security questionnaires, due diligence requests, evidence requests, periodic reviews, and assurance discussions.
  • Coordinate penetration tests, security reviews, remediation plans, and status reporting in a risk‑based and audit‑defensible manner.
  • Support critical incident response planning, investigation coordination, lessons learned, and corrective actions, including on‑call availability for emergency information security analysis or corrective action when required.
  • Maintain operational documentation, control evidence, decision records, risk registers, issue logs, and management reporting to an audit‑ready standard.
Qualifications
  • Bachelor’s degree in computer science, Information Security, Cybersecurity, Information Systems, Engineering, Risk Management, Mathematics, Business Technology, or a related field; equivalent practical experience may be considered.
  • Master’s degree in Cybersecurity, Information Systems, Risk Management, Business Administration, or a related discipline is advantageous but not required.
  • One or more relevant professional certifications is strongly preferred, such as CISSP, CISM, CRISC, CCSP, ISO 27001 Lead Implementer, GIAC security management certifications, or equivalent recognized security, cloud, or risk management certification.
  • Additional certifications or training in cloud security, business continuity, security management, AI/LLM security, secure software development, DevSecOps, or control testing are considered a plus.
  • At least 7 years of progressive experience across information security, security engineering & operations or a closely related discipline; candidates with slightly fewer years may be considered where they demonstrate strong hands‑on technical depth.
  • Demonstrated experience with recognized security and assurance frameworks such as SOC 2 Type II, ISO 27001/27002, NIST CSF, CIS Controls, COBIT, or equivalent control frameworks, including practical control design, implementation, evidence collection, and remediation tracking.
  • Hands‑on technical security experience across cloud platforms (Azure, GCP) · Experience supporting control harmonization, security integration, assurance standardization, operating model alignment, or related Security M&A/post‑integration activities across entities, offices, regions, or business units, preferred.
  • Experience working closely with multiple stakeholders to translate security and compliance requirements into practical operating controls.
  • Experience managing client‑facing assurance activities, including security questionnaires, due diligence requests, audit evidence requests, contractual security requirements, recurring client reviews, and customer assurance discussions.
  • Strong ability to operate independently as a senior individual contributor, manage competing priorities, influence stakeholders without direct authority, make risk‑based recommendations, and elevate material decisions appropriately.
  • Experience in insurance, reinsurance, regulated financial services, SaaS, underwriting technology, health/medical data environments, or other client‑assurance‑heavy sectors, preferred.

You may not meet every requirement listed in the job description. If you bring broad expertise and alignment to the role and resonate with our core values, we encourage you to apply.

Relocation assistance within the U.S. is available for this position. Candidates must have valid authorization to work in the U.S. without the need for employer sponsorship now or in the future.

Hybrid Work Policy:

SCOR is committed to an “in‑office” culture where people can collaborate, exchange ideas, and establish stronger working relationships while ll providing flexibility. To support employee work‑life balance and increase opportunities for employees to excel every day, SCOR operates with a hybrid working arrangement. SCOR employees work 3 days per week in an office with the flexibility to work 2 days per week remotely.

At SCOR, we CARE about clients, people, and societies, and we are committed to placing them at the center of everything we do. Providing great benefit choices to you and your family is just one of the ways we support the physical, financial, and emotional well‑being of the people who make our company successful – you.

Benefits We Offer
  • Medical, vision, and dental coverage
  • 401(k) Plan with a competitive match
  • Company‑funded Defined Contribution Retirement Program
  • Life and AD&D insurance
  • Long‑and Short‑Term Disability
  • Flexible Parental Leave
  • Unlimited Sick Days
  • Volunteer Time
  • Summer Fridays
  • Learning & Development Resources
  • Personal Wellness Tools and Rewards
  • Competitively priced gym memberships from a large nationwide network of gym brands and local fitness studios
  • And More!
About Us

As a leading global reinsurer, SCOR offers its clients a diversified and innovative range of reinsurance and insurance solutions and services to control and manage risk. Applying “The Art & Science of Risk,” SCOR uses its industry‑recognized expertise and cutting‑edge financial solutions to serve its clients and contribute to the welfare and resilience of society in around 160 countries worldwide.

Working at SCOR means engaging with some of the best minds in the industry – actuaries, data scientists, underwriters, risk modelers, engineers, and many others – as we work together to find solutions to pressing challenges facing societies.

As an international company, our common culture is defined by “The SCOR Way.” Serving both to build momentum that drives the Group forward and as a compass to guide our actions and choices, The SCOR Way is anchored by five core values, reflecting the input of employees at all levels of the Group. We care about clients, people, and societies. We perform with integrity. We act with courage. We encourage open minds. And we thrive through collaboration.

SCOR supports inclusion and the diversity of talents, and all positions are open to people with disabilities.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Lead
Information Security Lead

Scor • Charlotte (NC)

Hybrid
USD 140,000 - 210,000
Medical, vision, dental coverage
401(k) Plan with a competitive match
Company‑funded Defined Contribution
+6
Director, Sr Software Engineer - Velogica
Director, Sr Software Engineer - Velogica

SCOR UK Company Limited • Charlotte (NC), Northern (KY)

On-site
USD 120,000 - 160,000
Medical, vision, dental coverage
401(k) Plan with a competitive match
Life and AD&D insurance
+6
Director, Sr Software Engineer - Velogica
Director, Sr Software Engineer - Velogica

SCOR • Charlotte (NC)

On-site
USD 120,000 - 160,000
Medical benefits
401(k) Plan
Life & Disability Insurance
+4
IT Tech - Lead
IT Tech - Lead

Scor • Kansas City (MO)

On-site
USD 163,000 - 220,000
Medical coverage
401(k) matching
Life insurance
+2
IT Tech - Lead
IT Tech - Lead

SCOR Group • Kansas City (MO), Northern (KY)

Hybrid
USD 163,000 - 220,000
Medical, vision, and dental coverage
401(k) Plan with a competitive match
Long- and Short-Term Disability
+2
Manager, Regulatory Reporting
Manager, Regulatory Reporting

SCOR Group • New York (NY), Northern (KY)

Hybrid
USD 114,000 - 139,000
Medical, vision, and dental coverage
401(k) Plan with a competitive match
Life and AD&D insurance
+6
Manager, Regulatory Reporting
Manager, Regulatory Reporting

Scor • New York (NY)

Hybrid
USD 114,000 - 139,000
Medical coverage
Vision coverage
Dental coverage
+8
SVP, Head of Alternative Solutions, North America
SVP, Head of Alternative Solutions, North America

SCOR • New York (NY)

On-site
USD 305,000 - 445,000
Medical, vision, and dental coverage
401(k) with competitive match
Defined contribution retirement plan
+8
QA Automation Engineer
QA Automation Engineer

Scor • Kansas City (MO)

On-site
USD 118,000 - 144,000
Medical coverage
401(k) plan
Life insurance
+7
Senior Data & Analytics Engineer
Senior Data & Analytics Engineer

Scor • Charlotte (NC)

On-site
USD 131,000 - 160,000
Medical, vision, and dental coverage
401(k) Plan with a competitive match
Life and AD&D insurance
+7