Manager, Information Security Assurance Services

Posted 2 Days Ago
Be an Early Applicant
Hiring Remotely in United States
Remote
146K-198K Annually
Expert/Leader
Insurance • Software
The Role
Leads and matures the information security assurance program across governance, control frameworks, audits, regulatory response, PCI DSS, third-party risk, policy governance, security awareness, automation, and executive reporting. Manages a multidisciplinary team, oversees GRC platform operations, improves control testing and evidence collection, and partners with business, technology, regulators, auditors, and senior leadership to strengthen security posture and compliance.
Summary Generated by Built In

      

The Manager, Information Security Assurance Services is responsible for leading the design, build, and continuous maturation of the program. This role requires a proven track record of establishing and scaling information security assurance capabilities, including control frameworks, regulatory compliance, and audit readiness, information security awareness, policy governance, third-party risk management, and Payment Card Industry Data Security Standards (PCI DSS).
This leader will oversee a team accountable for executing and evolving assurance processes, with a clear mandate to drive automation, standardization, and gain operational efficiency across all Assurance Services products and services. The role partners closely with business, technology, and regulatory stakeholders to ensure controls are effectively implemented, measured, and aligned to organizational risk tolerance and regulatory requirements.
The ideal candidate brings demonstrated experience building GRC programs from the ground up and advancing them to a mature, technology-enabled function, leveraging automation, integrated tooling, and data-driven insights to reduce manual effort, improve control effectiveness, and enhance transparency. This role will be responsible for executing the strategic direction, establish scalable processes, and ensure the team delivers consistent, high-quality outcomes that strengthen the organization’s overall security posture and resilience.

         

          

Job Duties and Responsibilities

  • Program leadership across assurance domains —Lead and continuously mature governance, controls design and testing, audit and regulatory response, security awareness, policy governance, third-party/vendor risk management (TPRM), and the PCI DSS program, with full accountability for adherence to established controls, policies, and regulatory requirements.
  • Hands-on subject matter expertise — Serve as the team's go-to expert across information security assurance disciplines. Step in as an active contributor on control narratives, audit walkthroughs, regulator engagements, and remediation plans when program needs demand it.
  • Control framework ownership — Build, maintain, and continuously improve the control framework, ensuring alignment with NYDFS Part 500, NIST Cybersecurity Framework, CIS Controls, HIPAA, FDIC, PCI DSS v4.x, and other applicable standards. Maintain control libraries, control-to-framework mappings, and a defensible evidence model.
  • Audit and regulatory response — Direct the end-to-end response to internal audits, external audits, regulatory examinations, and PCI engagements. Personally review high-risk responses, evidence packages, and management responses prior to submission.
  • PCI DSS program oversight — Provide senior oversight and governance of the PCI DSS v4.x program, including scope validation, strategy, control implementation, ISA coordination, AOC/ROC readiness, compensating controls, and establish a clear multi-year roadmap to support enterprise goals.
  • Third-party risk management — Mature the TPRM program including inherent risk tiering, due diligence depth-of-review, contractual security requirements, ongoing monitoring, fourth-party visibility, and concentration risk reporting.
  • Policy governance — Own the enterprise information security policy governance (policies, standards, procedures, guidelines), including a defined lifecycle, exception management, ownership accountability, and executive committee approval cadence.
  • Security awareness — Direct the strategy, content, and measurement of the enterprise information security awareness program, including annual training, role-based training, phishing simulations, and Cybersecurity Awareness Month (CSAM) campaigns and activities.
  • Executive translation and stakeholder partnership — Translate strategic priorities, regulatory expectations, and informal executive conversations into structured roadmaps, OKRs, deliverables, sprint commitments, and team execution plans. Partner with business, technology, regulatory stakeholders, and third parties to communicate complex issues, drive alignment on contentious topics, and advocate for business-aligned outcomes.
  • People leadership and talent development — Manage, coach, and develop a multi-disciplinary team of assurance professionals. Set clear expectations, establish accountability, conduct performance management, and build a high-performing and high-trust team.
  • Continuous improvement and automation — Drive process maturity, automation of evidence collection and control testing, improved reporting routines, reduced manual effort, and effective use and management of GRC/IRM platforms (e.g., ServiceNow IRM) to scale the program and sustain operations.
  • Metrics and reporting — Define and operationalize KPIs/KRIs across each assurance domain. Deliver board-ready and executive-ready dashboards, and narrative reporting that articulate program health and remediation trajectory.
  • Decision-making and influence — Make and own operational and strategic decisions with significant impact to program effectiveness, and guide senior leaders through informed recommendations, best practices, and trade-off discussions.


Required Job Qualifications

Required Experience:

  • Minimum 10 years of progressive experience across GRC, information security, technology risk, internal/external audit, controls, cybersecurity assurance, or closely related disciplines.
  • Minimum 5 years of direct people leadership experience, including coaching, performance management, workforce planning, and talent development.
  • Demonstrated experience operating within or directly supporting PCI DSS environments, including scope definition, control design, testing, remediation, evidence management, and QSA/ISA interaction.
  • Strong working knowledge of governance and control frameworks including NYDFS Part 500, NIST Cybersecurity Framework, CIS Controls, and PCI DSS, with the ability to design and defend control rationale to auditors and regulators.
  • Demonstrated experience designing, testing, and remediating IT general controls (ITGCs) and application-level controls.
  • Proven ability to communicate complex risk and control topics clearly to executive audiences, audit committees, regulators, and cross-functional stakeholders.
  • Ability to operate independently under limited direction, prioritize competing demands, and consistently deliver results in ambiguous, fast-moving environments.
  • Bachelor's degree in Information Security, Computer Science, Information Systems, related discipline, or equivalent professional experience.

Preferred Experience:

  • Experience implementing or operating ServiceNow Integrated Risk Management (IRM) or comparable GRC platforms (e.g., Archer, AuditBoard, OneTrust, MetricStream).
  • Experience operating within a Product Operating Model, including roadmap planning, backlog grooming, sprint-based delivery, feature commitment management, and metrics-driven execution.
  • Experience in financial services, banking, or other highly regulated industries, including direct interaction with regulators such as state banking authorities, the OCC, FDIC, or NYDFS.
  • Industry certifications such as CISSP, CISA, CISM, CRISC, CGEIT, or CIA.
  • Demonstrated success improving control automation, continuous control monitoring, assurance testing efficiency, audit-readiness practices, and evidence-as-code approaches.

Other Critical Factors

Skills:

  • Strategic ownership — Sets multi-year vision for the assurance portfolio; does not wait for direction to identify gaps or propose roadmaps.
  • Executive presence — Comfortable engaging directly with the CISO, CIO, General Counsel, Chief Risk Officer, business unit leaders, audit committee members, and external regulators. Presents findings with confidence and influences decisions without escalation dependence.
  • Decision ownership — Makes defensible decisions on control design, risk acceptance recommendations, exception treatment, and resource allocation. Documents rationale and owns outcomes.
  • Talent multiplier — Develops individual contributors into the next generation of assurance leaders through structured coaching, stretch assignments, and clear feedback.
  • Outcome bias — Holds the team accountable to measurable outcomes (audit results, exemption rates, control coverage, completion velocity), not activity.
  • Hands-on when needed — Models the way. Willing to personally write the control narrative, sit through the examiner walkthrough, or draft the board bullet when the situation requires senior-level execution.

              

Pay Transparency


 

Thrivent’s long-term growth depends on attracting, rewarding, and retaining people who are committed to helping others thrive with purpose. We accomplish this by offering a wide variety of market competitive compensation programs to attract, reward, and retain top talent. The applicable salary or hourly wage range for this full-time role is $146,428.00 - $198,108.00 per year, which factors in various geographic regions. The base pay actually offered will be determined by a variety of factors including, but not limited to, location, relevant experience, skills, and knowledge, business needs, market demand, and other factors Thrivent deems important.


 

Thrivent is unique in our commitment to helping people to be wise with money and live balanced and generous lives. That extends to our benefits.


 

The following benefits may be offered: various bonuses (including, for example, annual or long-term incentives); medical, dental, and vision insurance; health savings account; flexible spending account; 401k; pension; life and accidental death and dismemberment insurance; disability insurance; supplemental protection insurance; 20 days of Paid Time Off each year; Sick and Safe Time; 10 paid company holidays; Volunteer Time Off; paid parental leave; EAP; well-being benefits, and other employee benefits. Eligibility for receipt of these benefits is subject to the applicable plan/policy documents. Thrivent’s plans/policies are subject to change at any time at Thrivent’s discretion.


 

Thrivent provides Equal Employment Opportunity (EEO) without regard to race, religion, color, sex, gender identity, sexual orientation, pregnancy, national origin, age, disability, marital status, citizenship status, military or veteran status, genetic information, or any other status protected by applicable local, state, or federal law. This policy applies to all employees and job applicants.

Thrivent is committed to providing reasonable accommodation to individuals with disabilities. If you need a reasonable accommodation, please let us know by sending an email to [email protected] or call 800-847-4836 and request Human Resources.

#Remote

Skills Required

  • At least 10 years of progressive experience in GRC, information security, technology risk, internal or external audit, controls, cybersecurity assurance, or related disciplines
  • At least 5 years of direct people leadership experience, including coaching, performance management, workforce planning, and talent development
  • Experience operating within or directly supporting PCI DSS environments, including scope definition, control design, testing, remediation, evidence management, and QSA or ISA interaction
  • Strong knowledge of NYDFS Part 500, NIST Cybersecurity Framework, CIS Controls, and PCI DSS
  • Experience designing, testing, and remediating IT general controls and application-level controls
  • Ability to communicate complex risk and control topics to executives, audit committees, regulators, and cross-functional stakeholders
  • Ability to operate independently, prioritize competing demands, and deliver results in ambiguous, fast-moving environments
  • Bachelor's degree in Information Security, Computer Science, Information Systems, a related discipline, or equivalent professional experience
  • Experience implementing or operating ServiceNow IRM or comparable GRC platforms such as Archer, AuditBoard, OneTrust, or MetricStream
  • Experience operating within a Product Operating Model, including roadmap planning, backlog grooming, sprint-based delivery, feature commitment management, and metrics-driven execution
  • Experience in financial services, banking, or other highly regulated industries, including interaction with state banking authorities, OCC, FDIC, or NYDFS
  • Industry certification such as CISSP, CISA, CISM, CRISC, CGEIT, or CIA
  • Experience improving control automation, continuous control monitoring, assurance testing efficiency, audit readiness, and evidence-as-code practices

Thrivent Financial Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Thrivent Financial and has not been reviewed or approved by Thrivent Financial.

  • Retirement Support Retirement programs featuring both a 401(k) and a pension are highlighted as a standout element that strengthens total rewards. These offerings are perceived to enhance long-term security across many roles.
  • Leave & Time Off Breadth Time off provisions including PTO, company holidays, volunteer time, and paid parental leave are frequently called out as robust. These elements support work–life balance and overall satisfaction.
  • Healthcare Strength Medical, dental, vision, and wellbeing resources are consistently described as comprehensive. Plan options, including high-deductible and traditional choices, offer flexibility to fit different needs.

Thrivent Financial Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Minneapolis, MN
7,504 Employees
Year Founded: 1902

What We Do

At Thrivent, we do work that matters—and we're reimagining financial services in ways that help individuals and communities thrive. With the belief that money is a tool, not a goal, we help over 2 million clients make the most of all they’ve been given through financial advice, insurance, investments, banking and generosity programs.  As a Fortune 500 company with a 100-year legacy, Thrivent is committed to helping people build their financial futures and live more generous lives in their communities and beyond. For more information, visit thrivent.com. You can also find us on Facebook, Twitter and Instagram. See our social media privacy policy and page guidelines at thrivent.com/privacyandsocial.

Similar Jobs

Liberty Mutual Insurance Logo Liberty Mutual Insurance

Inside Sales Representative

Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Remote or Hybrid
13 Locations
40000 Employees
45K-85K Annually

Boeing Logo Boeing

Trade Compliance Specialist 4 - Remote

Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
In-Office or Remote
Bingen, WA, USA
170000 Employees
99K-135K Annually
Remote or Hybrid
Chatsworth Lake Manor, CA, USA
205000 Employees
37K-66K Hourly

Comcast Logo Comcast

Senior Measurement & Attribution Analyst - Comcast Advertising

Digital Media • Information Technology • News + Entertainment
Remote or Hybrid
Virginia, USA
115000 Employees
78K-117K Annually

Similar Companies Hiring

Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account