ForgeApply · Job listing
Lead, Information Security GRC Automation
Pru
See all 105 open roles at Pru →
Tailor your resume for this Pru job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Pru's site. Free trial, no card required.
About this role
Job Classification: Technology - Information Security
Your Team
Are you interested in building capabilities that make Information Security easier to understand, adopt, and execute? As part of Prudential's Global Technology & Operations organization, the Information Security team is strengthening its governance capabilities to improve visibility into security risk, policy adoption, and program execution across the enterprise.
As the Lead, Information Security GRC Automation , you will help build and scale Prudential's automated control testing, monitoring, telemetry, and evidence capabilities. Reporting to the Director of Information Security Governance, you'll work across Risk Management, Technology, Audit, and Information Security to modernize how controls are monitored and reported. This role offers the opportunity to help shape a more automated, data-driven governance function that reduces manual effort and improves risk visibility across the enterprise.
This role is based in our office in Newark, NJ. Our organization follows a hybrid work structure where employees can work remotely and from the office, as needed, based on demands of specific tasks or personal work preferences. This position is hybrid and requires your on-site presence on a reoccurring weekly basis at least 3 days per week.
Here is What You Can Expect on a Typical Day
Build Automated Control Monitoring & Evidence Capabilities
• Design and implement automated control testing, continuous monitoring, telemetry, and evidence collection capabilities that improve visibility into control effectiveness and reduce reliance on manual processes.
• Translate control library requirements into scalable automation solutions, metrics, monitoring routines, and testing approaches that support risk-based governance and compliance objectives .
• Identify opportunities to automate testing and evidence collection across the control environment, helping mature governance from periodic assessments to near real-time monitoring.
• Ensure automated testing results, evidence, and supporting data to remain accurate , traceable, and audit-ready .
Build Integrated Governance Data & Technology Solutions
• Establish and maintain connections across governance, risk, asset, technology, CMDB, and evidence platforms to create a scalable and connected governance ecosystem.
• Partner with technology teams and control owners to onboard new evidence sources, improve data quality, and enhance traceability across controls, assets, risks, and reporting.
• Design sustainable automation frameworks that support control monitoring, reporting, remediation tracking, and executive visibility across Information Security Governance.
• Help establish the foundational data structures, taxonomies, and integration patterns required to scale future automation initiatives
Drive Governance Transformation & Operational Excellence
• Partner closely with Library & Standards, Policy & Enablement, Business Intelligence, Risk Management, Internal Audit, and Technology teams to create an integrated governance capability that connects controls, standards, adoption, metrics, and executive reporting.
• Lead continuous improvement of automation operating models, including intake, prioritization, testing, evidence collection, reporting, and governance workflows.
• Develop scalable playbooks, standards, and operational routines that improve consistency, accelerate adoption, and enhance the effectiveness of automated control monitoring.
• Influence cross-functional stakeholders to modernize governance practices, reduce manual effort, and drive a more data-driven approach to risk and control management across the enterprise
The Skills & Expertise You Bring
• Bachelor's degree or equivalent experience in Cybersecurity, Information Systems, Computer Science, Risk Management , related field or equivalent experience.
• Experience implementing automated controls testing, continuous monitoring, evidence collection, or governance capabilities in a regulated environment .
• Knowledge of security controls, testing methodologies, evidence management, and risk-based monitoring practices.
• Understanding of technology delivery lifecycle including software development, DevOps, CI/CD, release management, and technology delivery processes.
• Experience working with Governance, Risk, and Compliance ( GRC ) platforms, APIs, ServiceNow or asset inventory data, workflow automation, integrations, or control reporting capabilities.
• Ability to translate control library requirements into automated test scripts, telemetry, metrics, evidence routines, and executive -ready reporting outputs.
• Strong knowledge on Azure DevOps, Jira, GitHub, Jenkins, Power Automate, cloud platforms, or related technologies.
• Strong analytical, communication, and stakeholder management skills, with the ability to lead working sessions and drive timely resolution across multiple workstreams.
Preferred Qualifications
• Experience with ServiceNow IRM or similar Governance, Risk, and Compliance ( GRC ) platforms.
• Experience implementing continuous controls monitoring, automated evidence collection, or control-as-code approaches.
• Experience integrating governance and compliance activities into technology delivery workflows.
• Experience supporting financial services, regulatory, audit, or compliance programs such as NYDFS, SOX/JSOX, SWIFT, CCPA, JFSA, SOC 1/2, ISO 27001, or similar requirements.
• Certifications such as CISSP, CISM, CRISC, CISA, or ServiceNow credentials.
• Experience developing automation playbooks, operating routines, intake processes, dashboards, adoption materials, or training content for governance or control capabilities.
#LI-Hybrid #LI-LR1
What we offer you:
Prudential is required by state specific laws to include the salary range for this role when hiring a resident in applicable lo
Salary insight
The midpoint of this range ($152k) is about 8% below the median disclosed salary for New York roles listed on ForgeApply ($165k across 8,051 jobs).
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this Pru role before you apply.
Tailor my resume for this jobSimilar jobs
- Senior Security GRC Lead — Gongio · Austin | Chicago | New York City | Salt Lake City | San Francisco
- Lead, Information Security Policy & Enablement — Pru · Newark, NJ
- Lead, Business Intelligence, Information Security Governance — Pru · Newark, NJ
- Program Manager, Security GRC — Stripe · Remote
- Senior Security Engineer I, GRC — Oscar · New York, New York, United States
- Head of Security GRC — Drivewealth · Remote
- Lead, Network Security Automation Engineer — Pru · Newark, NJ
- Security Automation Lead — Point72 · New York, NY
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)