Cybersecurity Risk & Compliance Lead
Kansas City, Missouri, United States of America
Information Technology
2500CM
Cybersecurity Risk & Compliance Lead
Kansas City, Missouri, United States of America
Information Technology
2500CM
Working at Lockton
At Lockton, we’re passionate about helping our people achieve their ultimate potential. Our people are curious, action-oriented and always striving to make ourselves and those around us better. We’re active listeners working to ensure understanding and problem solvers developing innovative solutions. If you can see yourself delivering excellent service to clients, giving back to our communities and being a part of our caring culture, you belong here.
Business unit
Lockton Management, LLC
Schedule
Full-time
Lockton Benefits Offerings
Click Here
Workplace
Hybrid
Your Responsibilities
Cybersecurity Risk & Compliance management plays a pivotal role in embedding a culture of cyber risk and control management across the Lockton business. Cybersecurity risk management capability is a key component in enabling Lockton to inform and manage its enterprise risk profile. The Cybersecurity Risk & Compliance Lead will enable this by establishing cyber risk management program, processes to assess and manage Lockton’s cyber risk profile. They will build processes to identify, communicate, measure and report the operational effectiveness of Lockton’s cyber controls. They will be responsible for articulating cyber risk to enable decision-making towards finding the optimum balance between security risks and controls while enabling the business. Working closely with cross-functional teams, they will provide expert guidance on security best practices, risk management, and compliance requirements. The scope of this role is global, and they will report directly to the Global Chief Information Security Officer.
You will have overall accountability for:
• Cybersecurity Risk Management and Controls
• Maintain and mature Lockton’s cyber risk management program.
• Maintain and continually improve Lockton’s key cyber control framework, including alignment to global standards.
• Maintain an accurate view of Lockton’s cybersecurity risk profile across the globe through regular risk assessment and management.
• Work with product and platform owners to ensure a common understanding of the control requirements for business-critical assets.
• Adopt a data driven approach to measuring the effectiveness of Lockton’s cyber controls.
• Maintain Third Party and First Party Risk Management programs
• Maintain New System Security Risk Assessment process
• Maintain Security Awareness and Training program
• Maintain and continually improve Lockton’s processes for measuring and managing risk across our contracted third parties.
• Maintain an accurate view of our risk profile across third-party suppliers.
• Cybersecurity Posture Reporting
• Maintain and continually improve Lockton’s cybersecurity metrics framework to measure the effectiveness of controls.
• Identify opportunities to introduce automation over control effectiveness measurement.
• Produce executive and stakeholder reporting on the Cyber posture of the organization.
• Foster a culture of Cyber risk & compliance management across the organization.
• Seek solutions to enable the business by leveraging insights.
• Cybersecurity Policy Development
• Maintain global security policies and standards.
• Assist in completion of internal and external audits and regulatory assessments.
What will set you apart from the rest?
• Strong influencer - Ability to form open, effective, and trusting relationships with business and IT leaders
• Strong communicator - Excellent communications skills, both written and verbal, and the ability to translate security principles and risks into business terms
• Strong leadership acumen - Passionate about driving and sustaining change and innovation through committed leadership. Servant-leader mindset.
• Previous experience building and maturing multi-country cyber GRC programs
• Creative and results-oriented, who is good at balancing multiple priorities and issues
• Strong collaborator - Team player up and down the organizational structure, ability to partner with global IT/ Security/risk departments
• Provides a high level of professional service to customers (both internal and external) consistent with Lockton standards and procedures.
• Self-starter and strong organizational skills in a fast-paced environment
• Actively listen to other team members
• Finding new ways of solving problems
• Able to accept and action feedback
Qualifications
• Bachelor’s or master’s degree in computer science, Information Assurance, MIS or related field or equivalent.
• Minimum 10 years of experience in information security, with a minimum of 5 years in cyber risk management, building and maturing cyber risk management/GRC programs
• Preferred relevant certifications such as CISSP, CRISC, CGEIT, CISM and/or SANS certifications
• Broad understanding of cybersecurity risks and control domains such as Network Security, Identity Security, Cloud Security, Data Protection.
• Deep expertise with Security frameworks, including NIST and ISO27001.
• Expertise with Risk Management frameworks and experience in measuring risk.
• Expertise in measuring effectiveness of security controls.
• Data and analytics mindset.
• Employing authentic storytelling techniques to drive compelling stories and messages.
Equal Opportunity Statement
Lockton Companies is proud to provide everyone an equal opportunity to grow and advance. We are committed to an inclusive culture and environment where our people, clients and communities are treated with respect and dignity.
At Lockton, supporting diversity, equity and inclusion is ingrained in our values, and we believe that we are at our best when we fully embrace everyone. We strive to cultivate a caring culture that learns from, celebrates and thrives because of our breadth of differences. As such, we recognize that recruiting, developing and retaining people with diverse backgrounds and experiences is vital and enabling our people to thrive personally and professionally is critical to our long-term success.
About Lockton
Lockton is the largest privately held independent insurance brokerage in the world. Since 1966, our independence has allowed us to serve our clients, take care of our people and give back to our communities. As such, our 10,000+ Associates doing business in over 100 countries are empowered to do what’s right every day.
At Lockton, we believe in the power of all people. You belong at Lockton.
How We Will Support You
At Lockton, we empower you to be true to yourself in all that you do. Your success is our success, and we provide opportunities to help you grow and create a rewarding career path, however you envision it.
We are ready to meet you where you are today, and as your needs change over time. In addition to industry-leading health insurance, we offer additional options to support your overall health and wellbeing.
No Agencies Please
Any Employment Agency, person or entity that submits an unsolicited resume to this site does so with the understanding that the applicant's resume will become the property of Lockton Companies, Inc. Lockton Companies will have the right to hire that applicant at its discretion and without any fee owed to the submitting Employment Agency, person or entity. Employment Agencies, who have fee Agreements with Lockton Companies must submit applicants to the designated Lockton Companies Employment Coordinator to be eligible for placement fees.
Similar Vacancies
View allLife at Lockton

March 11, 2025

March 1, 2025

February 11, 2025

February 5, 2025