Director, Business Information Security Officer

2 weeks ago


New York, New York, United States Pagaya Technologies Ltd. Full time
About the Role

The Director, Business Information Security Officer will lead the US affiliate, Pagaya Investments US LLC's, efforts to successfully implement and provide ongoing management and oversight of all relevant information security controls/solutions. The BISD will work closely with our Israeli Office of the CISO, and its security architectural team to evaluate and implement cyber security solutions in the domains of Cloud, IAM, DLP, mobile and endpoint security, security monitoring, security training and more to protect Pagaya's core assets, data and IP.

Responsibilities
  • You will be responsible for our security solutions technology stack for the US throughout the project lifecycle (including evaluation, implementation, management and ongoing operations, including reporting/metrics). Ensure all security solutions meet the localized business, regulatory and technical needs of the US affiliate, and report upstream to the Office of the CISO and Global CISO.
  • Work closely with Pagaya's Global Security Engineering team, architecture and SecOps team members within the Office of the CISO to ensure consistent cross-company implementation of controls.
  • Drive the secure deployment of a global security solution stack focused on cloud (IaaS and SaaS), mobile and endpoint related controls.
  • Assist the Global CISO in the development, implementation and maintenance of up-to-date information security procedures, standards and guidelines and oversee the localized approval, training, and dissemination of security policies and practices.
  • Manage a defense in depth approach that addresses all cross-department security requirements.
  • Share and communicate end-to-end security solutions and the enterprise security posture (both orally and written) to executives, business sponsors, and customers and partners in a clear and concise manner that is in the vernacular of each group.
  • Create and manage information security and risk management awareness training programs for all US employees, contractors and approved system users.
  • Work directly with the other business units to facilitate IT risk assessment and risk management processes, and work with stakeholders throughout the enterprise on identifying acceptable levels of residual risk.
  • Facilitate the information security risk assessment process, as well as support audit programs such as internal security audits, ISO 27001, SOC2 and SOX audits, including the gathering of audit evidence, reporting and oversight of treatment efforts to address any negative findings/gaps.
  • Manage business unit security incidents and events to protect corporate IT assets, including intellectual property, regulated data and the company's reputation.
  • Monitor business unit metrics and reporting framework to measure the efficiency and effectiveness of the program, facilitate appropriate resource allocation, and increase the maturity of the security.
  • Manage outsourced US vendors that provide information security functions for compliance with contracted service-level agreements.
  • Manage and coordinate operational components of US-based incident management, including detection, response and reporting.
  • Work with various stakeholders to identify information asset owners to classify data and systems as part of a control framework implementation.
  • Manage the day-to-day activities of threat and vulnerability management, identify risk tolerances, recommend treatment plans and communicate information to the Global CISO about residual risk.
  • Ensure localized audit trails, system logs and other monitoring data sources are reviewed periodically and comply with policies and audit requirements.
  • Develop and oversee effective disaster recovery policies and procedures to align with the enterprise business continuity management program goals. Coordinate the development and testing of business unit specific plans and procedures to ensure that business-critical services are recovered in the event of a security event. Provide direction, support and in-house consulting in these areas.
  • Create and support POC/demos and present security solutions relevant to the business unit to the company relevant stakeholders.
Requirements
  • 7+ years of proven InfoSec management experience including hands-on information Security experience with key technologies such as endpoint security, email security, DLP, mobile device management, and SIEM.
  • In-depth knowledge of a comprehensive stack of layered security controls and the technical aspects of their deployment and management.
  • Experience with Cloud delivered solutions (IaaS, PaaS, SaaS AWS)
  • Knowledge in the majority of security domains such as: IAM, Cloud access broker (CAB), DLP, Endpoint Protection and Cloud native security solutions (focused on AWS), as well as security incident and event monitoring.
  • 6+ years of proven experience in defining security requirements and deployment of solutions.
  • Experience in leading cross-domain solutions
  • In-depth knowledge of information security concepts, design/architecture, and methodologies
  • Security-related certifications (CCSP, CISSP, CISM, CISA, etc.) are a plus.
  • Experience supporting both internal and external security and compliance audits of an enterprise within a regulated industry such as financial services.
  • Continuous learner with flexible mindset who has demonstrated the ability to be a nimble and creative thinker within an ever-evolving and dynamic organization.
  • A self-starter with a solutions and consultative oriented mindset and strong attention to detail
  • Exceptional communication, presentation, and stakeholder management skills, proven ability to partner across diverse stakeholders.


  • New York, New York, United States Point72 Full time

    Job TitleBusiness Information Security Officer, EquitiesJob SummaryWe are seeking a seasoned Business Information Security Officer to join our Global Information Security team and act as a trusted security advisor for our Equities business. The ideal candidate possesses a deep understanding of both the financial services industry and systematic trading...


  • New York, New York, United States Point72 Full time

    {"title": "Business Information Security Officer, Equities", "content": "Job SummaryWe are seeking a seasoned Business Information Security Officer (BISO) to join our Global Information Security team and act as a trusted security advisor for our Equities business.The ideal candidate possesses a deep understanding of both the financial services industry and...


  • New York, New York, United States McCann Worldgroup Shanghai Full time

    Job Title: VP Business Information Security OfficerThe VP Business Information Security Officer will lead a team responsible for all aspects of information security within McCann Worldgroup. This includes security operations, incident response, architecture and review, tooling evaluations, documentation, GRC, and other relevant areas or disciplines.Key...


  • New York, New York, United States Open Systems Technologies Full time

    Director of Information SecurityA leading non-profit organization in New York is seeking a seasoned Director of Information Security to spearhead their enterprise-level information security program. Compensation: $160-170kKey Responsibilities:Develop, implement, and manage the organization's information security programConduct risk assessments and develop...


  • New York, New York, United States Child Mind Institute Full time

    Job Title: Director of Information SecurityChild Mind Institute is seeking a highly skilled and experienced Director of Information Security to join our team. The successful candidate will be responsible for developing, implementing, and managing the Information Security program at an enterprise level.Key Responsibilities:Define and implement the...


  • New York, New York, United States Michael Page Full time

    Job Title: Business Information Security OfficerMichael Page is seeking a highly skilled Business Information Security Officer to join our client, a leading financial services firm in Manhattan, New York.About Our ClientOur client is a well-established financial services company in New York City, committed to delivering exceptional services to its...


  • New York, New York, United States Michael Page Full time

    About the RoleWe are seeking a highly skilled Business Information Security Officer to join our team at a leading financial services firm in Manhattan, New York. This is a full-time permanent opportunity that offers a competitive base salary and a chance to work with a dynamic and established company.Key ResponsibilitiesConduct thorough risk assessments and...


  • New York, New York, United States VISTRADA Full time

    Job Title: Chief Information Security OfficerVistrada is seeking a seasoned Chief Information Security Officer to lead our cybersecurity programs and provide strategic guidance to our clients. As a key member of our team, you will be responsible for developing and implementing information security programs, assessing and mitigating risks, and providing...

  • Security Officer

    7 days ago


    New York, New York, United States Arrow Security Full time

    Job Title: Security OfficerArrow Security is seeking a highly skilled and experienced Security Officer to join our team in Midtown Manhattan. As a Security Officer, you will be responsible for providing watch and protection of assigned patrol and designated perimeter.Key Responsibilities:Provide watch and protection of assigned patrol and designated...


  • New York, New York, United States Macatawa Bank Full time

    Job Title: Information Security OfficerMacatawa Bank is seeking a highly skilled Information Security Officer to join our team. As an Information Security Officer, you will be responsible for providing independent oversight of the information security posture of Macatawa Bank to support alignment with risk appetite as well as banking and privacy/data...


  • New York, New York, United States Citigroup Inc Full time

    Job Title: Senior Information Security OfficerCitigroup Inc. is seeking a highly skilled Senior Information Security Officer to join our team. As a key member of our Information Security team, you will be responsible for driving efforts to prevent, monitor, and respond to information/data breaches and cyber-attacks.Key Responsibilities:Work directly with...


  • New York, New York, United States Stack Overflow Full time

    About the RoleWe are seeking a seasoned Senior Director of Information Security and Compliance to join our team at Stack Overflow. As a key member of our leadership team, you will be responsible for evolving, implementing, and ensuring alignment with our established information security strategy and compliance programs.This is a unique opportunity to make a...

  • Security Officer

    2 weeks ago


    New York, New York, United States Arrow Security Full time

    Job SummaryWe are seeking a highly organized and detail-oriented individual to join our team as a Quartermaster at Arrow Security. As a Quartermaster, you will be responsible for ensuring that our Security Officers have the necessary uniforms and equipment to perform their duties effectively.Key ResponsibilitiesProperly fit and issue uniforms to Security...


  • New York, New York, United States Pagaya Technologies Ltd. Full time

    Head of Business Information Securityat Pagaya Technologies Ltd.About Pagaya Technologies Ltd.Transforming the Financial LandscapePagaya Technologies Ltd. is a pioneering financial technology firm dedicated to revolutionizing the lending ecosystem for investors through advanced machine learning, extensive data analytics, and sophisticated AI-driven risk...


  • New York, New York, United States Citigroup Inc Full time

    About the RoleCitigroup Inc. is seeking a highly skilled and experienced Information Security Officer to join our team. As a key member of our Enterprise Operations & Technology team, you will play a critical role in driving efforts to prevent, monitor, and respond to information/data breaches and cyber-attacks.Key ResponsibilitiesWork directly with...


  • New Brunswick, New Jersey, United States SECURITY OFFICER SERVICES INC Full time

    Job SummaryWe are seeking a highly skilled and experienced Security Officer to join our team at SECURITY OFFICER SERVICES INC. As a Security Officer, you will be responsible for providing security services at assigned locations, observing and reporting suspicious activities, and enforcing post orders and site rules.Key ResponsibilitiesMonitor and report all...


  • New York, New York, United States Citigroup Inc Full time

    About the RoleCitigroup Inc. is seeking a highly skilled Senior Information Security Officer to join our team. As a key member of our Enterprise Operations & Technology team, you will play a critical role in driving efforts to prevent, monitor, and respond to information/data breaches and cyber-attacks.Key ResponsibilitiesWork directly with business,...

  • Security Officer

    2 weeks ago


    New York, New York, United States Security Guards of America Full time

    Job Title: Security Guard OfficerLocation: New YorkCategory: SecurityJob SummaryWe are seeking a highly skilled and experienced Security Guard Officer to join our team at Security Guards of America. As a Security Guard Officer, you will be responsible for ensuring the safety and security of our premises and personnel.Responsibilities and DutiesSecuring...


  • New York, New York, United States Citigroup Inc Full time

    About the RoleCitigroup Inc. is seeking a highly skilled and experienced Information Security Officer to join our team. As a key member of our Enterprise Operations & Technology team, you will play a critical role in driving efforts to prevent, monitor, and respond to information/data breaches and cyber-attacks.Key ResponsibilitiesWork directly with...

  • Security Officer

    7 days ago


    New York, New York, United States Arrow Security Full time

    Job Title: Security OfficerArrow Security is seeking a highly skilled and dedicated Security Officer to join our team. As a Security Officer, you will be responsible for providing onsite watch and protection of assigned posts and designated perimeters.Key Responsibilities:Observe and report any security breaches or incidentsSupport client expectations and...