- Lead USAA’s enterprise Privileged Access Management program
- Own the PAM strategy and roadmap
- Drive implementation and ongoing effectiveness of privileged account governance, credential management, session management, and least-privilege capabilities
- Serve as senior product owner and PAM subject matter expert
- Partner with cybersecurity, engineering, audit, risk, compliance, legal, and business stakeholders
- Prioritize investments, deliver security solutions, and meet regulatory commitments
- Provide strategic and operational leadership
- Oversee vendor relationships and manage remediation efforts
- Report program performance and risk to senior leadership
- Own strategic direction, roadmaps, policies, standards, procedures, governance, and metrics for the information security domain
- Direct effective operation of the enterprise information security domain, including capacity, resilience, and dependability
- Develop and communicate information security risk management policies and procedures with the CISO and senior leaders
- Represent USAA in discussions with external regulators
- Oversee continuous monitoring of cybersecurity activities and alert senior management to risks, compliance issues, and inefficiencies
- Develop and deliver governance and assurance models across multiple domains and the enterprise
- Identify and evaluate operational solutions to reduce risk and meet compliance requirements
- Promote information security awareness
- Manage organizational manpower and budgets as financial steward
- Build and oversee a team through recruiting, development, retention, coaching, performance management, and managerial activities
- Ensure business risks are identified, measured, monitored, and controlled
Requirements
- Bachelor's degree in Information Security, Information Technology, Computer Science, Business Administration, Information Systems/Management, or related field; OR 4 years of relevant education and/or experience
- 8 years of related information security experience in one or more domains
- 3 years of direct team lead, supervisor, or management experience in an Information Security or Information Technology domain
- 4 years of researching, designing or implementing technology, information security or cybersecurity solutions in a large financial institution or large enterprise information security program
- Experience driving delivery of PAM capabilities and controls, including privileged account governance, credential management, session management, and least-privilege initiatives
- Experience partnering with engineering, security, audit, risk, and business stakeholders to define requirements, prioritize work, and implement PAM solutions
- Experience administering and supporting CyberArk PAM solutions, including Safes, Platforms, CPM, PSM, and PVWA
- Strong knowledge of cryptography, authentication, authorization, and security controls
- Knowledge of IT risks and experience implementing security solutions
- Experience managing regulatory and audit commitments related to privileged access
- Experience acting as primary PAM product owner and subject matter expert
- Expert business acumen in business operations, risk management, industry practices, and emerging trends
- Expert knowledge of FFIEC, Gramm-Leach-Bliley, FFIEC Cybersecurity Assessment Tool, NIST Cybersecurity Framework, and PCI DSS
- Strong written and verbal communication skills
- Must not require immigration support or visa sponsorship now or in the future
Core Competencies
Demonstrates expertise in Privileged Access Management (PAM) strategy, governance, and implementation, with a strong focus on risk management and compliance within the information security domain. Proven ability to lead teams, manage vendor relationships, and communicate effectively with stakeholders at all levels.
Highest-signal resume keywords
- Privileged Access Management (PAM)
- CyberArk PAM Solutions
- Information Security Risk Management
- Regulatory Compliance Management
- Team Leadership and Development
ATS Optimization Keywords
Hard Skills
- Privileged Account Governance
- Credential Management
- Session Management
- Least-Privilege Capabilities
- Cryptography
- Authentication
- Authorization
- Security Controls
- Risk Management
- Cybersecurity Solutions
Soft Skills
- Strong Written Communication
- Strong Verbal Communication
Industry Keywords
- Information Security
- Cybersecurity
- Financial Institution
- Audit Commitments
- Business Operations
Tools & Technologies
- CyberArk
- FFIEC Cybersecurity Assessment Tool
- NIST Cybersecurity Framework
- PCI DSS
Director, Information Security – Privileged Access Management in san antonio at Unknown Company
This position is listed as full time and onsite.