Security Risk Management Specialist

Posted 2 Days Ago
Be an Early Applicant
Hiring Remotely in Illinois, USA
Remote
78K-111K Annually
Junior
Insurance
The Role
Conducts enterprise, vendor, and cloud security risk assessments; analyzes policy and configuration exceptions; recommends risk mitigation and contractual controls; tracks remediation; advises projects through secure SDLC risk gates; performs threat modeling; and communicates security risks to technical and non-technical stakeholders.
Summary Generated by Built In

You desire impactful work.
 

You’re RGA ready

RGA is a purpose-driven organization working to solve today’s challenges through innovation and collaboration. A Fortune 200 Company and listed among its World’s Most Admired Companies, we’re the only global reinsurance company to focus primarily on life- and health-related solutions. Join our multinational team of intelligent, motivated, and collaborative people, and help us make financial protection accessible to all.

The Security Risk Management Specialist will be responsible for identifying, assessing, reporting, and monitoring security risks across RGA’s enterprise security and business functions. This role involves collaborating with various departments to ensure compliance with security policies and standards, while additionally recommending security measures to protect RGA’s assets from potential threats.


Principal Duties


  • Conduct comprehensive security risk assessments of enterprise systems and processes, as well as provide recommendations for risk mitigation.
  • Review, analyze, and provide recommendations for policy, standard, and baseline configuration exceptions.
  • Perform vendor risk assessments to include inherent & residual risk identification, analysis, and mitigation, and additionally track risk remediation to completion.
  • Provide recommendations for vendor contractual requirements stemming from vendor risk assessment outcomes.
  • Serve as a project security advisor including risk analysis gate checks in the secure SDLC process.
  • Conduct thorough threat modeling exercises to identify potential security vulnerabilities and risks.
  • Stay current on security trends, threats, and best practices to continuously improve the organization's security posture. 
  • Perform other duties as assigned.

Education


  • Required: Bachelor’s degree or equivalent experience
  • Preferred: Master’s degree and/or LOMA certification

Required Experience, Skills, and Abilities


  • 2+ years IT security, privacy, audit, controls and regulatory compliance, or related experience.
  • Experience conducting risk assessments aligned with industry standard frameworks & standards.
  • Intermediate understanding of IT domains: infrastructure, networking, storage, databases, operating systems, cloud, applications, etc.
  • Strong understanding of security technologies and domains, including: SSO, IAM, DLP, EDR, SIEM, firewalls, gateways, IDS/IPS, CASB, antivirus, SSDLC, cryptography, PKI, etc.
  • Knowledge of risk and control frameworks/standards (e.g., NIST CSF, NIST 800-53, ISO/IEC 27001, NIST 800-30, ISO/IEC 27005, etc.).
  • Oral and written communication skills, demonstrating the ability to convey complex technical and security concepts and terminology to non-technical stakeholders.
  • Ability to manage multiple projects/tasks simultaneously, including the ability to delegate key areas of responsibility.
  • Ability to successfully liaise with individuals across a wide variety of operational, functional, and technical disciplines.
  • Excellent analytical, problem-solving, and critical-thinking skills.

Preferred Experience


  • 2+ years leadership role experience
  • Insurance/Reinsurance industry knowledge/experience
  • Information security, compliance, risk, or audit professional certifications, such as: CISSP, CISA, CISM, CGEIT, CRISC, CPA, OSCP, CCSP, CCSK
  • Project management skills/experience

Preferred Technical Experience


  • Cloud assessment experience (AWS, Azure, Google Cloud, etc.)
  • Cyber Risk Quantification (CRQ) experience (e.g., FAIR)
  • Automation experience: Python, REST API, PowerShell, etc.
  • Previous experience as a Systems Administrator, IT Auditor, Developer, Security Engineer, Penetration Tester, Cloud Engineer

#LI-CW1

#LI-Remote

What you can expect from RGA:

  • Gain valuable knowledge from and experience with diverse, caring colleagues around the world.

  • Enjoy a respectful, welcoming environment that fosters individuality and encourages pioneering thought.

  • Join the bright and creative minds of RGA, and experience vast, endless career potential.

We’re excited to get to know you and connect your unique skills with our global opportunities. To create a modern and seamless experience, we use artificial intelligence (AI) in parts of our preliminary screening process. This technology helps us personalize job recommendations, automate interview scheduling, evaluate candidates based solely on experience—without considering name, gender, or other personal details—and provide real-time answers through our chatbot. AI is used only during early screening and never makes hiring decisions. Your RGA recruiter will work closely with you every step of the way to ensure the process feels personal, thoughtful, and focused on you.

Compensation Range:

$78,080.00 - $110,860.00 Annual

Base pay varies depending on job-related knowledge, skills, experience and market location. In addition, RGA provides an annual bonus plan that includes all roles and some positions are eligible for participation in our long-term equity incentive plan. RGA also maintains a full range of health, retirement, and other employee benefits.

RGA is an equal opportunity employer. Qualified applicants will be considered without regard to race, color, age, gender identity or expression, sex, disability, veteran status, religion, national origin, or any other characteristic protected by applicable equal employment opportunity laws.

Skills Required

  • Bachelor's degree or equivalent experience
  • 2+ years of IT security, privacy, audit, controls and regulatory compliance, or related experience
  • Experience conducting risk assessments aligned with industry-standard frameworks and standards
  • Intermediate understanding of infrastructure, networking, storage, databases, operating systems, cloud, and applications
  • Strong understanding of security technologies and domains, including SSO, IAM, DLP, EDR, SIEM, firewalls, IDS/IPS, CASB, SSDLC, cryptography, and PKI
  • Knowledge of risk and control frameworks including NIST CSF, NIST 800-53, ISO/IEC 27001, NIST 800-30, and ISO/IEC 27005
  • Strong oral and written communication skills
  • Ability to manage multiple projects and tasks simultaneously
  • Ability to collaborate across operational, functional, and technical disciplines
  • Excellent analytical, problem-solving, and critical-thinking skills
  • Master's degree and/or LOMA certification
  • 2+ years of leadership role experience
  • Insurance or reinsurance industry knowledge or experience
  • Information security, compliance, risk, or audit certifications such as CISSP, CISA, CISM, CGEIT, CRISC, CPA, OSCP, CCSP, or CCSK
  • Project management skills or experience
  • Cloud assessment experience with AWS, Azure, or Google Cloud
  • Cyber Risk Quantification experience, such as FAIR
  • Automation experience with Python, REST API, or PowerShell
  • Previous experience as a Systems Administrator, IT Auditor, Developer, Security Engineer, Penetration Tester, or Cloud Engineer
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Chesterfield, MO
3,164 Employees
Year Founded: 1973

What We Do

Reinsurance Group of America, Incorporated (RGA), a Fortune 500 company, is among the leading global providers of life reinsurance and financial solutions, with approximately $3.5 trillion of life reinsurance in force and assets of $92.2 billion as of December 31, 2021. Founded in 1973, RGA today is recognized for its deep technical expertise in risk and capital management, innovative solutions, and commitment to serving its clients. With headquarters in St. Louis, Missouri, and operations around the world, RGA delivers expert solutions in individual life reinsurance, individual living benefits reinsurance, group reinsurance, health reinsurance, facultative underwriting, product development, and financial solutions. To learn more about RGA and its businesses, visit our website at www.rgare.com.

Similar Jobs

Flex Logo Flex

Director, New Vertical Sales (Auto Loans)

Fintech • Payments • Real Estate • Software • Financial Services
Remote
United States
419 Employees
272K-340K Annually

Circle (circle.so) Logo Circle (circle.so)

Social Media Lead

Artificial Intelligence • Consumer Web • Digital Media • Information Technology • Social Impact • Software
Remote
United States
250 Employees

Circle (circle.so) Logo Circle (circle.so)

Designer

Artificial Intelligence • Consumer Web • Digital Media • Information Technology • Social Impact • Software
Remote
12 Locations
250 Employees
100K-120K Annually

Circle (circle.so) Logo Circle (circle.so)

Lead Engineer, AI Platform

Artificial Intelligence • Consumer Web • Digital Media • Information Technology • Social Impact • Software
Remote
12 Locations
250 Employees

Similar Companies Hiring

MassMutual India Thumbnail
Big Data • Fintech • Information Technology • Insurance • Financial Services
Hyderabad, Telangana
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
65 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account