Information Security Lead
Charlotte, NC - USA
Job Summary
The Information Security Lead is responsible for managing the security and compliance function for Velogica US ensuring that data systems cloud environments development practices vendors and assurance activities are protected controlled and audit ready. The role will operate as the local senior security and compliance lead for Velogica US partnering closely with the SDS Global Security and Compliance team to align local execution with the broader SDS security and assurance teams roadmap. The position combines hands-on technical security knowledge with strong GRC capability including SOC 2 ISO 27001 compliance risk management vulnerability management third-party assurance client security reviews evidence management and policy/control lifecycle management. The role will also help standardize and harmonize controls evidence practices tooling and assurance processes between SDS and Velogica US while maintaining effective local support for Velogica stakeholders and clients.
Responsibilities
- Operate as the local lead for Velogica US security and compliance activities managing day-to-day priorities independently while maintaining close alignment with the SDS Global Security and Compliance team.
- Develop maintain implement and improve Velogica security and compliance policies standards procedures guidelines controls technical safeguards and evidence practices in alignment with SDS Global Security and Compliance team-defined control baselines.
- Lead and coordinate Velogica US assurance activities including SOC 2 Type II ISO 27001 alignment audit preparation evidence collection control owner coordination audit remediation and ongoing control monitoring.
- Harmonize IT security and assurance practices between SDS and Velogica US by implementing common control baselines repeatable processes shared tooling consistent evidence standards and aligned reporting.
- Provide hands-on technical security guidance across cloud environments application security DevSecOps AI/LLM risk management vulnerability management access control logging/monitoring incident response business continuity and secure SDLC practices.
- Work with engineering cloud infrastructure data product legal HR vendor management privacy and business stakeholders to ensure security and compliance requirements are embedded into operating practices and delivery processes.
- Manage client-facing security and compliance activities including client security questionnaires due diligence requests evidence requests periodic reviews and assurance discussions.
- Coordinate penetration tests security reviews remediation plans and status reporting in a risk-based and audit-defensible manner.
- Support critical incident response planning investigation coordination lessons learned and corrective actions including on-call availability for emergency information security analysis or corrective action when required.
- Maintain operational documentation control evidence decision records risk registers issue logs and management reporting to an audit-ready standard.
Qualifications
- Bachelors degree in computer science Information Security Cybersecurity Information Systems Engineering Risk Management Mathematics Business Technology or a related field; equivalent practical experience may be considered.
- Masters degree in Cybersecurity Information Systems Risk Management Business Administration or a related discipline is advantageous but not required.
- One or more relevant professional certifications is strongly preferred such as CISSP CISM CRISC CCSP ISO 27001 Lead Implementer GIAC security management certifications or equivalent recognized security cloud or risk management certification.
- Additional certifications or training in cloud security business continuity security management AI/LLM security secure software development DevSecOps or control testing are considered a plus.
- At least 7 years of progressive experience across information security security engineering & operations or a closely related discipline; candidates with slightly fewer years may be considered where they demonstrate strong hands-on technical depth.
- Demonstrated experience with recognized security and assurance frameworks such as SOC 2 Type II ISO 27001/27002 NIST CSF CIS Controls COBIT or equivalent control frameworks including practical control design implementation evidence collection and remediation tracking.
- Hands-on technical security experience across cloud platforms (Azure GCP) Experience supporting control harmonization security integration assurance standardization operating model alignment or related Security M&A/post-integration activities across entities offices regions or business units preferred.
- Experience working closely with multiple stakeholders to translate security and compliance requirements into practical operating controls.
- Experience managing client-facing assurance activities including security questionnaires due diligence requests audit evidence requests contractual security requirements recurring client reviews and customer assurance discussions.
- Strong ability to operate independently as a senior individual contributor manage competing priorities influence stakeholders without direct authority make risk-based recommendations and escalate material decisions appropriately.
- Experience in insurance reinsurance regulated financial services SaaS underwriting technology health/medical data environments or other client-assurance-heavy sectors preferred.
You may not meet every requirement listed in the job description. If you bring broad expertise and alignment to the role and resonate with our core values we encourage you to apply.
Relocation assistance within the U.S. is available for this position. Candidates must have valid authorization to work in the U.S. without the need for employer sponsorship now or in the future.
Hybrid Work Policy:
SCOR is committed to an in-office culture where people can collaborate exchange ideas and establish stronger working relationships while ll providing flexibility. To support employee work-life balance and increase opportunities for employees to excel every day SCOR operates with a hybrid working arrangement. SCOR employees work 3 days per week in an office with the flexibility to work 2 days per week remotely.
At SCOR we CARE about clients people and societies and we are committed to placing them at the center of everything we do. Providing great benefit choices to you and your family is just one of the ways we support the physical financial and emotional well-being of the people who make our company successful you.
Benefits We Offer
Medical vision and dental coverage
401(k) Plan with a competitive match
Company-funded Defined Contribution Retirement Program
Life and AD&D insurance
Long- and Short-Term Disability
Flexible Parental Leave
Unlimited Sick Days
Volunteer Time
Summer Fridays
Learning & Development Resources
Personal Wellness Tools and Rewards
Competitively priced gym memberships from a large nationwide network of gym brands and local fitness studios
And More!
About Company
As a leading global reinsurer, SCOR offers its clients a diversified and innovative range of reinsurance and insurance solutions and services to control and manage risk. Applying “The Art & Science of Risk,” SCOR uses its industry-recognized expertise and cutting-edge financial soluti ... View more