AgriSompo North America Logo

AgriSompo North America

Information Security Officer

Posted Yesterday
Be an Early Applicant
In-Office
London, Greater London, England, GBR
Expert/Leader
In-Office
London, Greater London, England, GBR
Expert/Leader
Manages and modernizes Sompo’s global information security program across technical controls, vulnerability management, security alerting, incident response, SDLC participation, security communications, regulatory alignment, and risk reporting. The role leads hybrid security teams, maintains security strategy and architecture, translates metrics into risk indicators, and oversees environments spanning Windows, cloud, SaaS, network devices, and physical and cloud locations.
The summary above was generated by AI

Job Description

Sompo has a unique opportunity for an Information Security Officer to join our Information Security team.

This role will manage and continuously modernize our Information Security program for global operations, while maintaining alignment with external and corporate requirements.   The Information Security Officer will manage more than 7,000 users, hundreds of developers and IT staff working in a range of technologies, more than 10,000 network devices and 75+ physical and cloud locations.

Location: This position can be based out of any of our US offices such as Purchase, NY / New York City / Morristown, NJ / Conshohocken, PA or Charlotte, NC. We strive for collaboration which is why we offer a work environment where our employees thrive and develop long lasting careers.

Our business, your impact, our opportunity:

What you’ll be doing:

  • Maintaining an effective set of technical security controls across all systems and processes.  Controls must have documented designs and real-time instrumentation.   Core domains include:

    • malicious activity prevention and detection

    • encryption

    • data loss prevention and detection

    • activity/audit logging, especially for privileged identities and access

    • adversarial simulation

  • Detecting, reporting, and escalating vulnerabilities to the operational teams that support those vulnerable systems or processes.    Maintaining org-wide vulnerability data for both periodic and threat-drive real time reporting

  • Operating an efficient, instrumented, and effective security alerting function that is continuously evolving to match Sompo’s threat environment

  • Maintaining an efficient and tested incident response procedure capable of handling events of any scale

  • Participating in the systems development lifecycle to ensure alignment with our information security program

  • Establishing a communications program to keep all Sompo users aware of emerging threats, upcoming policy changes, recent achievements, and general security recommendations.

What you’ll bring:

  • Minimum of 15 years of experience in a combination of technical, security, and risk management roles

  • Minimum of 7 years in a senior management role within an information security function.

  • Technical familiarity with security patterns, operations and controls for traditional (Windows), cloud, and SaaS environments Systematic thinking – understanding the place of security controls within the larger operating environment, anticipating issues and engaging colleagues to minimize disruption (or the potential for it).  

  • Structure projects and programs in risk-prioritized manner.

  • Experience integrating regulatory requirements, corporate policies, and industry standards into operating procedures and designs Experience maintaining and communicating security strategy and technical architecture.

  • Ability to translate operational metrics into meaningful KPIs and risk quantifiers.

  • Excellent written, verbal and interpersonal communications with a range of audiences, including non-technical leaders, customers, regulators, and technical colleagues.

  • Experience maintaining a fast-changing security program with continuous improvement driven by changes in: threat intelligence and adversary tactics operational metrics company priorities Leadership experience managing a hybrid team of: direct reports (including ongoing professional development) matrix reports managed services and specialist contractors.

  • Bachelor’s degree in computer science, information security, or a related field.

  • Recognized information security certification (CISSP, CISM, etc.).

Preferred Qualifications:

  • Prior experience with adoption of FAIR Threat modeling within the SDLC Familiarity with DevSecOps processes, tooling, and controls Experience gaining and maintaining certifications like ISO 270xx, SOC 2, etc.

  • Knowledge of regional security data privacy regulations related to Minimization Encryption Cross-border data access

Salary Range: $180,000 – $225,000 Actual compensation for this role will depend on several factors including the cost of living associated with your work location, your qualifications, skills, competencies, and relevant experience.

At Sompo, we recognize that the talent, skills, and commitment of our employees drive our success. This is why we offer competitive, high-quality compensation and benefit programs to eligible employees.

Our compensation program is built on a foundation that promotes a pay-for-performance culture, resulting in higher incentive awards, on average, when the Company does well and lower incentive awards when the Company underperforms. The total compensation opportunity for all regular, full-time employees is a combination of base salary and incentives that gets adjusted upfront based on overall Company performance with final awards based on individual performance.

We continuously evaluate and update our benefit programs to ensure that our plans remain competitive and meet the needs of our employees and their dependents. Below is a summary of our current comprehensive U.S. benefit programs:

  • Two medical plans to choose from, including a Traditional PPO & a Consumer Driven Health Plan with a Health Savings account providing a competitive employer contribution

  • Pharmacy benefits with mail order options

  • Dental benefits including orthodontia benefits for adults and children

  • Vision benefits

  • Health Care & Dependent Care Flexible Spending Accounts

  • Company-paid Life & AD&D benefits, including the option to purchase Supplemental life coverage for employee, spouse & children

  • Company-paid Disability benefits with very competitive salary continuation payments

  • 401(k) Retirement Savings Plan with competitive employer contributions

  • Competitive paid-time-off programs, including company-paid holidays

  • Competitive Parental Leave Benefits & Adoption Assistance program

  • Employee Assistance Program

  • Tax-Free Commuter Benefit

  • Tuition Reimbursement & Professional Qualification benefits

In today’s world, what do we stand for?

Ethics and integrity are the foundation of delivering on our commitment to you. We believe that core values drive success, and that when relationships are held in the highest regard, there is nothing that cannot be accomplished. At Sompo, our ring is more than a logo, it is a symbol of our promise. Click here to learn more about life at Sompo.

Sompo is an equal opportunity employer and we intentionally value inclusion and diversity. Above all, we want you to work in an environment that respects everyone’s unique contributions – we are passionately committed to equal opportunities. We do not discriminate based on race, color, religion, sex orientation, national origin, or age.

Similar Jobs

11 Days Ago
Remote or Hybrid
Mid level
Mid level
Information Technology
Performs IT audits and cybersecurity control validation for complex systems, applications, enclaves, and classified or unclassified networks. Assesses vulnerabilities, risks, security requirements, and mitigation effectiveness against Federal and DoD standards. Provides technical evaluations and recommends security improvements while balancing business needs with security concerns. Requires experience with RMF, DODI 8500.2 or NIST SP 800-53, eMASS, network implementation, and an active DoD Secret clearance.
Top Skills: Dodi 8500.2EmassMicrosoft AccessExcelMS OfficeMicrosoft PowerpointMicrosoft WordNetwork SecurityNist Sp 800-53Risk Management Framework (Rmf)
18 Days Ago
Hybrid
Senior level
Senior level
Legal Tech
The Chief Information Security Officer leads DLA Piper’s enterprise cybersecurity strategy, governance, risk management, incident response, data protection, third-party security, security awareness, and operational resilience programs. The role advises executives and governance bodies, oversees security controls and emerging technology risk, translates technical risks into business and legal impacts, and builds a high-performing global information security organization. The CISO also manages security policies, audits, regulatory and client obligations, vendor oversight, budgets, talent development, and executive communications.
Top Skills: Ai SdlcCis ControlsCloudData Loss PreventionDevsecopsEmail SecurityEncryptionEndpoint ProtectionIdentity And Access ManagementIso/Iec 27001Logging And MonitoringNistZero Trust Architecture
Senior level
Mobile • Security • Software • Cybersecurity
Serve as the ISSO for assigned systems, maintain system security documentation (SSPs, control narratives, POA&Ms), support FedRAMP/GovRAMP/DoD authorization and continuous monitoring, coordinate remediation and assessments with engineering and auditors, support incident response and audit readiness, and track security metrics and evidence.
Top Skills: AWSChatgptClaudeDod Impact Level 5FedrampFedramp HighFips 199Fips 200GovcloudGovrampGovramp HighIso 27001Nist Risk Management Framework (Rmf)Nist Sp 800-37Nist Sp 800-53Nist Sp 800-53APlans Of Action And Milestones (Poa&M)Privileged Access Management (Pam)Soc 2System Security Plan (Ssp)

What you need to know about the London Tech Scene

London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account