Information Security Officer

Information Security Officer

Full-Time 136350 - 166650 £ / year (est.) Home office (partial)
S

At a Glance

  • Tasks: Lead and modernise our global Information Security programme while managing a vast user base.
  • Company: Join Sompo, a forward-thinking company prioritising collaboration and career growth.
  • Benefits: Enjoy competitive salary, comprehensive health plans, remote work options, and tuition reimbursement.
  • Other info: Diverse and inclusive workplace committed to your professional development.
  • Why this job: Make a real impact in cybersecurity while working with cutting-edge technologies.
  • Qualifications: 15+ years in security roles, with strong leadership and technical skills required.

The predicted salary is between 136350 - 166650 £ per year.

  • Sompo has a unique opportunity for an
  • Information Security Officer to join our

Information Security team.

This role will manage and continuously modernize our Information Security program for global operations, while maintaining alignment with external and corporate requirements.

The Information Security Officer will manage more than 7,000 users, hundreds of developers and IT staff working in a range of technologies, more than 10,000 network devices and 75+ physical and cloud locations.

Location: This position can be based out of any of our US offices such as Purchase, NY / New York City / Morristown, NJ / Conshohocken, PA / Charlotte, NC or our UK office.

We strive for collaboration which is why we offer a work environment where our employees thrive and develop long lasting careers.

Our Business, Your Impact, Our Opportunity

What you’ll be doing

  • Maintaining an effective set of technical security controls across all systems and processes.

Controls must have documented designs and real-time instrumentation.

Core domains include

  • malicious activity prevention and detection
  • encryption
  • data loss prevention and detection
  • activity/audit logging, especially for privileged identities and access
  • adversarial simulation
  • Detecting, reporting, and escalating vulnerabilities to the operational teams that support those vulnerable systems or processes.

Maintaining org-wide vulnerability data for both periodic and threat-drive real time reporting

  • Operating an efficient, instrumented, and effective security alerting function that is continuously evolving to match Sompo’s threat environment
  • Maintaining an efficient and tested incident response procedure capable of handling events of any scale
  • Participating in the systems development lifecycle to ensure alignment with our information security program
  • Establishing a communications program to keep all Sompo users aware of emerging threats, upcoming policy changes, recent achievements, and general security recommendations.
  • What You’ll Bring
  • Minimum of 15 years of experience in a combination of technical, security, and risk management roles
  • Minimum of 7 years in a senior management role within an information security function.
  • Technical familiarity with security patterns, operations and controls for traditional (Windows), cloud, and Saa S environments Systematic thinking – understanding the place of security controls within the larger operating environment, anticipating issues and engaging colleagues to minimize disruption (or the potential for it).
  • Structure projects and programs in risk-prioritized manner.
  • Experience integrating regulatory requirements, corporate policies, and industry standards into operating procedures and designs Experience maintaining and communicating security strategy and technical architecture.
  • Ability to translate operational metrics into meaningful KPIs and risk quantifiers.
  • Excellent written, verbal and interpersonal communications with a range of audiences, including non-technical leaders, customers, regulators, and technical colleagues.
  • Experience maintaining a fast-changing security program with continuous improvement driven by changes in: threat intelligence and adversary tactics operational metrics company priorities Leadership experience managing a hybrid team of: direct reports (including ongoing professional development) matrix reports managed services and specialist contractors.
  • Bachelor’s degree in computer science, information security, or a related field.
  • Recognized information security certification (CISSP, CISM, etc.).
  • Preferred Qualifications
  • Prior experience with adoption of FAIR Threat modeling within the SDLC Familiarity with Dev Sec Ops processes, tooling, and controls Experience gaining and maintaining certifications like ISO 270xx, SOC 2, etc.
  • Knowledge of regional security data privacy regulations related to Minimization Encryption Cross-border data access
  • Salary

Range: $180,000 – $225,000 Actual compensation for this role will depend on several factors including the cost of living associated with your work location, your qualifications, skills, competencies, and relevant experience.

At Sompo, we recognize that the talent, skills, and commitment of our employees drive our success.

This is why we offer competitive, high-quality compensation and benefit programs to eligible employees.

Our compensation program is built on a foundation that promotes a pay-for-performance culture, resulting in higher incentive awards, on average, when the Company does well and lower incentive awards when the Company underperforms.

The total compensation opportunity for all regular, full-time employees is a combination of base salary and incentives that gets adjusted upfront based on overall Company performance with final awards based on individual performance.

  • Summary
  • Two medical plans to choose from, including a Traditional PPO & a Consumer Driven Health Plan with a Health Savings account providing a competitive employer contribution
  • Pharmacy benefits with mail order options
  • Dental benefits including orthodontia benefits for adults and children
  • Vision benefits
  • Health Care & Dependent Care Flexible Spending Accounts
  • Company-paid Life & AD&DD benefits, including the option to purchase Supplemental life coverage for employee, spouse & children
  • Company-paid Disability benefits with very competitive salary continuation payments
  • 401(k) Retirement Savings Plan with competitive employer contributions
  • Competitive paid-time-off programs, including company-paid holidays
  • Competitive Parental Leave Benefits & Adoption Assistance program
  • Employee Assistance Program
  • Tax-Free Commuter Benefit
  • Tuition Reimbursement & Professional Qualification benefits

In today’s world, what do we stand for?

Ethics and integrity are the foundation of delivering on our commitment to you.

We believe that core values drive success, and that when relationships are held in the highest regard, there is nothing that cannot be accomplished.

At Sompo, our ring is more than a logo, it is a symbol of our promise.

Click here to learn more about life at Sompo.

Sompo is an equal opportunity employer and we intentionally value inclusion and diversity.

Above all, we want you to work in an environment that respects everyone's unique contributions – we are passionately committed to equal opportunities.

We do not discriminate based on race, color, religion, sex orientation, national origin, or age.

#J-18808-Ljbffr

Information Security Officer employer: Sompo

Sompo is an exceptional employer that fosters a collaborative and innovative work culture in the heart of London. With a strong focus on employee growth, we offer extensive professional development opportunities and a supportive environment that encourages creativity and strategic thinking. Join us to be part of a dynamic team dedicated to delivering outstanding client engagement services while enjoying the unique advantages of working in one of the world's most vibrant cities.

S

Contact Details:

Sompo Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Information Security Officer

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Sompo, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Sompo

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Sompo. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Information Security Officer

Information Security Management
Technical Security Controls
Vulnerability Management
Incident Response
Risk Management
Security Strategy Communication
Regulatory Compliance

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Sompo insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Sompo that you’re committed to staying ahead in the game.

How to prepare for a job interview at Sompo

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Sompo to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Sompo.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.