Security Risk Management Specialist
Posted 4hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Security risk specialist assessing enterprise, vendor, and technology risks for RGA, a global life and health reinsurance company. Recommending mitigations, controls, and secure SDLC improvements.
Responsibilities:
- Identify, assess, report, and monitor security risks across enterprise security and business functions
- Collaborate with departments to ensure compliance with security policies and standards
- Recommend security measures to protect organizational assets from potential threats
- Conduct comprehensive security risk assessments of enterprise systems and processes
- Provide recommendations for risk mitigation
- Review, analyze, and recommend actions for policy, standard, and baseline configuration exceptions
- Perform vendor risk assessments, including inherent and residual risk identification, analysis, and mitigation
- Track vendor risk remediation to completion
- Recommend vendor contractual requirements based on risk assessment outcomes
- Serve as a project security advisor, including risk analysis gate checks in the secure SDLC process
- Conduct threat modeling exercises to identify potential security vulnerabilities and risks
- Monitor security trends, threats, and best practices to improve the organization’s security posture
- Perform other duties as assigned
Requirements:
- Bachelor’s degree or equivalent experience
- 2+ years of IT security, privacy, audit, controls and regulatory compliance, or related experience
- Experience conducting risk assessments aligned with industry-standard frameworks and standards
- Intermediate understanding of infrastructure, networking, storage, databases, operating systems, cloud, applications, and related IT domains
- Strong understanding of SSO, IAM, DLP, EDR, SIEM, firewalls, gateways, IDS/IPS, CASB, antivirus, SSDLC, cryptography, PKI, and related security technologies
- Knowledge of risk and control frameworks such as NIST CSF, NIST 800-53, ISO/IEC 27001, NIST 800-30, and ISO/IEC 27005
- Strong oral and written communication skills
- Ability to manage multiple projects/tasks simultaneously and delegate key responsibilities
- Ability to liaise across operational, functional, and technical disciplines
- Excellent analytical, problem-solving, and critical-thinking skills
- Preferred: Master’s degree and/or LOMA certification
- Preferred: 2+ years leadership role experience
- Preferred: Insurance/Reinsurance industry knowledge or experience
- Preferred: Information security, compliance, risk, or audit certifications such as CISSP, CISA, CISM, CGEIT, CRISC, CPA, OSCP, CCSP, or CCSK
- Preferred: Project management skills/experience
- Preferred: Cloud assessment experience with AWS, Azure, or Google Cloud
- Preferred: Cyber Risk Quantification experience, such as FAIR
- Preferred: Automation experience with Python, REST API, or PowerShell
- Preferred: Previous experience as a Systems Administrator, IT Auditor, Developer, Security Engineer, Penetration Tester, or Cloud Engineer
Benefits:
- Annual bonus plan
- Long-term equity incentive plan eligibility for some positions
- Health benefits
- Retirement benefits
- Other employee benefits
- Diverse, caring colleagues around the world
- Respectful, welcoming work environment
- Career potential and global opportunities











