Source description
About the role
About us: We are a highly successful 190-year-old, Fortune 500 commercial property insurance company of 6,000+ employees with a unique focus on science and risk engineering. Businesses worldwide trust our expertise to protect their assets, relying on our comprehensive risk assessments and robust, engineering-based insurance solutions to safeguard against fire, natural disasters, and other perils. Serving over a quarter of the Fortune 500 and major corporations globally, we deliver data-driven strategies that enhance resilience, ensure business continuity, and empower organizations to thrive. FM India is a strategic location for driving our global operational efficiency. Our presence in India allows us to leverage the countrys talented workforce and advance our capabilities to serve our clients better. We have diverse corporate functions that emphasize research, advanced technologies like AI and analytics, risk engineering, research, finance, marketing, HR, etc. working together to provide innovative solutions and nurture lasting relationships from co-workers to clients. Role Title: Prin Info Security Risk Engineer IND Position Summary: This role is considered an Information Security subject matter expert (SME), working closely with enterprise and solution architects, along with product and service owners to understand security requirements and associated risks in moderate to large and complex business line and enterprise initiatives and solutions. The incumbent is an expert cyber security and risk professional, responsible for identifying emerging threats, assessing the organizations cyber and information security risk exposures, providing business-oriented, protection and mitigation strategies encompassing the confidentiality, integrity, and availability of assets against technical and non-technical threats. Regularly meets with senior leadership to elevate business leaders awareness of their critical business exposures, influencing decision making and providing fit-for-purpose risk mitigation strategies. This role defines security requirements for the organization to address the changing threat and technology landscape, and creates strategies and specific objectives for the information security risk assessment function in support of the enterprise. Job Responsibilities: With minimal guidance manage the security assessment process - perform security assessments to ensure that the organizations security policy requirements and risk mitigation expectations have been appropriately addressed within the scope of moderate to large, complex business line and enterprise initiatives and solutions to include: development / implementation and modifications to the organizations business systems, applications, and corresponding processes; complex / strategic technical architectures and third-party provider/vendor relationships. Influence the organizations technical and business leaders to incorporate security requirements into application/architecture/process designs and to correct identified security risk issues. Meet regularly with senior and executive leadership (as appropriate) to discuss identified security risk concerns, provide education and guidance, and influence appropriate action(s).Performs research and analysis of security threats, vulnerabilities, mitigating strategies, and industry trends to help leadership understand emerging risks. From this analysis, develops program level, process, or technical recommendations, and supporting documentation, to be shared with peers and leadership.Integrates with business and technology stakeholders, maintains a high level of communication and teamwork both within Information Security & Risk Management across the organization to successfully accomplish goals & objectives. Effectively communicates with senior and executive leadership to promote security awareness, understanding, and influencing improvements.Support the continued development of the security assessment program. Proactively identifies, plans and influences changes and/or improvements to the program, tool and business processes to address business needs.Maintain cybersecurity expertise, certifications and skills. Attend industry and/or technology relevant training, workshops, conferences to stay abreast of changes in security/technology landscape. Drawing on industry security and technology trends, familiarity with the changing threat landscape, and experience through assessment and knowledge of the internal environment, contribute to FM Global security standards. Skill and Experience: 8 years of experience required to perform essential job functions.Additional Experience Qualifier (optional): Relevant experienceDemonstrated ability to work collaboratively with technical experts, business managers, and senior leadershipAbility to understand complex, technical issues and communicate them into meaningful business and risk guidance and recommendationStrong knowledge of operating Ab
More at FM