Job Description:Security, Risk and Technology
Strong knowledge of financial services and insurance industry regulations around security and privacy including the Gramm-Leach-Bliley Act, State Privacy Laws, Health Insurance Portability and Accountability Act (HIPAA), Fair Credit Reporting Act, SEC Rules 17a-3 and 17a-4, and state security breach disclosure notification laws. Ability to relate these regulations back to security controls.
Understanding and application of information security standards and best practices including NIST Cybersecurity Framework, ISO 27001-4, CoBIT, Cloud Security Alliance, etc.
Ability to identify risks, quantify them, and help recommend and design mitigations.
Broad knowledge of Unix, Linux, Windows and mainframe server environments. Knowledge of various database platforms.
Strong knowledge of best practice processes and technologies across security domains especially related to identity and access management, network security, logging and monitoring.
Knowledge of at least one cloud services platform (Amazon Web Services, Microsoft Azure, Google
Cloud or Oracle Cloud)
Education / Experience:
Security, compliance, audit or risk covering a wide area of technologies and security domains including those previously mentioned.
Financial industry or highly regulated industry background (Insurance, Banking, etc.)
Project work experience with a recognized security, audit, or risk consulting firm a plus
CISSP, CISA, CISM or other security/control certifications a plus.
Bachelor’s degree or higher – preferably in Computer Science, Engineering, or a related scientific fields
Communication
Excellent verbal and written communication skills
Ability to develop and QA/oversee development of high quality project artifacts
Ability to collaborate, influence and communicate successfully in different ways concisely to different audiences (i.e., in business terms to business people, in technical terms to technical people)
Able to develop and present dashboards
Engagement
Proven ability to engage with customers (IT and Business) and consultants in a highly professional and competent manner.
Understanding and experience with project life cycles using proven methodologies – from analysis through implementation with hands-on deliverable development.
Ability to work in a matrix reporting environment
A practiced ability to influence peers, customers and project teams to make security minded decisions and changes
Ability to scope projects, developing project charters, requirements, documenting issues and work plans, vendor selection, product/process design and implementation, change management/communication a plus.Qualifications:
Security, Risk and Technology
- Strong knowledge of financial services and insurance industry regulations around security and privacy including the Gramm-Leach-Bliley Act, State Privacy Laws, Health Insurance Portability and Accountability Act (HIPAA), Fair Credit Reporting Act, SEC Rules 17a-3 and 17a-4, and state security breach disclosure notification laws. Ability to relate these regulations back to security controls.
- Understanding and application of information security standards and best practices including NIST Cybersecurity Framework, ISO 27001-4, CoBIT, Cloud Security Alliance, etc.
- Ability to identify risks, quantify them, and help recommend and design mitigations.
- Broad knowledge of Unix, Linux, Windows and mainframe server environments. Knowledge of various database platforms.
- Strong knowledge of best practice processes and technologies across security domains especially related to identity and access management, network security, logging and monitoring.
- Knowledge of at least one cloud services platform (Amazon Web Services, Microsoft Azure, Google
- Cloud or Oracle Cloud)
Education / Experience:
- Security, compliance, audit or risk covering a wide area of technologies and security domains including those previously mentioned.
- Financial industry or highly regulated industry background (Insurance, Banking, etc.)
- Project work experience with a recognized security, audit, or risk consulting firm a plus
- CISSP, CISA, CISM or other security/control certifications a plus.
- Bachelor’s degree or higher – preferably in Computer Science, Engineering, or a related scientific fields
Communication
- Excellent verbal and written communication skills
- Ability to develop and QA/oversee development of high quality project artifacts
- Ability to collaborate, influence and communicate successfully in different ways concisely to different audiences (i.e., in business terms to business people, in technical terms to technical people)
- Able to develop and present dashboards
Engagement
- Proven ability to engage with customers (IT and Business) and consultants in a highly professional and competent manner.
- Understanding and experience with project life cycles using proven methodologies – from analysis through implementation with hands-on deliverable development.
- Ability to work in a matrix reporting environment
- A practiced ability to influence peers, customers and project teams to make security minded decisions and changes
- Ability to scope projects, developing project charters, requirements, documenting issues and work plans, vendor selection, product/process design and implementation, change management/communication a plus.
Location:
This position can be based in any of the following locations:
Chennai, Gurgaon
Current Guardian Colleagues: Please apply through the internal Jobs Hub in Workday
Top Skills
What We Do
Who we are
Guardian makes a difference in the lives of people when they need us most. With over 160 years of stability and fiscal integrity, we are a trusted resource to generations of families and business owners, inspiring well-being and helping build financial confidence.
Today, we stand behind 29 million consumers, helping them prepare and plan for a bright future for themselves and their families. We help business owners care for their employees. And we help people recover and thrive in times of unexpected loss.
As a modern mutual insurance company, we believe in driving value beyond dividends. We invest in our colleagues and are building a progressive, innovative and inclusive culture. We uplift individuals and communities through thoughtful social and environmental programs.
What we stand for
In 1860, a community of immigrants joined together to insure and protect their businesses and families. They were guided by powerful ideals that we’ve continued to stand behind and evolved throughout the years: we do the right thing, we believe people count, we courageously shape the future together, and we go above and beyond for the people we serve.
Guardian employees embrace and live by these values every day. They remind us to put people at the heart of all we do so that we can help protect what matters most to you. Want to help bring these values to life? Join us for a rewarding career and the opportunity to shape the future.
Disclosures:
Financial information concerning Guardian as of December 31, 2022, on a statutory basis: Admitted assets = $76.0 billion; liabilities = $67.2 billion (including $55.0 billion of reserves); and surplus = $8.8 billion. Dividends are not guaranteed. They are declared annually by Guardian’s Board of Directors.
Guardian® is a registered trademark of The Guardian Life Insurance Company of America. © Copyright 2023 The Guardian Life Insurance Company of America 2023-156184 Exp. 5/25