ForgeApply · Job listing
Lead, Information Security Library & Standards
Pru
See all 105 open roles at Pru →
Tailor your resume for this Pru job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Pru's site. Free trial, no card required.
About this role
Job Classification: Technology - Information Security
Your Team
Are you interested in building capabilities that make Information Security easier to understand, adopt, and execute? Prudential's Global Technology & Operations organization is strengthening Information Security governance to improve visibility into security risk, policy adoption, and program execution across the enterprise.
As the Lead, Information Security Library & Standards , you will help build the foundation that supports Information Security governance across Prudential. This is a unique opportunity to help build and shape a growing Information Security Governance capability, with visibility across senior leadership and the ability to influence how security, risk, and governance are executed across the enterprise. Reporting to the Director of Information Security Governance, you'll partner closely with Risk Management and Information Security leaders to establish a scalable control library, mature security standards, and create the governance processes needed to support a consistent, practical, and audit-ready security program.
This role is based in our office in Newark, NJ. Our organization follows a hybrid work structure where employees can work remotely and from the office, as needed, based on demands of specific tasks or personal work preferences. This position is hybrid and requires your on-site presence on a reoccurring weekly basis at least 3 days per week.
Here is What You Can Expect on a Typical Day
Build & Govern the Information Security Control Library
• Lead the development, enhancement, and ongoing governance of Prudential's Information Security control library, ensuring consistency, traceability, and alignment with enterprise risk and compliance objectives .
• Define and maintain control taxonomy, ownership models, framework mappings, evidence requirements, control narratives, and governance standards.
• Establish traceability across security standards, controls, regulatory requirements, risks, testing activities, evidence repositories, and reporting processes.
• Partner with Information Security domain leaders across I dentity & Access Management (IAM), Attack Surface Management (ASM), Cyber Defense & Response (CDR), cloud security, data protection, vulnerability management, and other security control functions to ensure controls accurately reflect current risks, technologies, and operational requirements.
Drive Standards Management, Governance & Regulatory Alignment
• Coordinate the lifecycle management of Information Security standards, including creation, review, approval, publication, maintenance, and retirement.
• Design and implement governance processes, operating models, quality controls, decision frameworks, and review routines that keep standards and controls current, consistent, and audit-ready .
• Align standards and controls with leading frameworks and regulatory requirements, including NIST, ISO 27001, FFIEC, NYDFS, SOC, and related security and assurance standards.
• Support audits, compliance reviews, risk assessments, and regulatory examinations through clear control mappings, standards documentation, evidence requirements, and governance reporting.
• Drive continuous improvement of governance processes, workflows, and control management practices to improve efficiency, transparency, and usability across the organization.
Enable Adoption, Security Alignment & Enterprise Partnership
• Partner with Information Security, Risk Management, Compliance, Technology, Legal, Internal Audit, and business stakeholders to translate complex security requirements into practical and actionable guidance.
• Work closely with Enablement and awareness teams to support adoption of security standards and controls through communications, implementation guidance, FAQs, and training content.
• Establish governance of playbooks, templates, quality standards, and documentation practices that drive consistency across security domains and control owners.
• Use stakeholder feedback, adoption trends, governance metrics, and quality reviews to continuously improve the effectiveness and usability of the control library and standards framework.
• Build trusted partnerships across Information Security, Technology, Risk, Compliance, Audit, and business functions to help drive alignment and adoption of governance standards across the enterprise.
The Skills & Expertise You Bring
• Bachelor's degree or equivalent experience in Cybersecurity, Computer Science, Information Security, Risk Management, Information Systems, Business , a related field or equivalent experience.
• Experience building or maintaining security governance, control frameworks, compliance programs, or risk management initiatives.
• Strong understanding of frameworks such as NIST, ISO 27001, FFIEC, NYDFS, SOC, or related standards.
• Working knowledge of one or more security domains such as IAM, Cloud Security, Data Protection, Vulnerability Management, Attack Surface Management, or Cyber Defense.
• Experience designing governance processes, operating models, ownership structures, quality gates, lifecycle processes and control documentation.
• Strong communication , documentation, and stakeholder management skills.
• Ability to collaborate effectively across security, risk, compliance, technology, business, and audit teams.
Preferred Qualifications
• Experience building or enhancing security control libraries, standards programs, workflow improvements or governance frameworks or Governance, Risk, and Compliance (GRC) tooling.
• Experience supporting audits, examinations, compliance reviews, or risk assessments.
• Familiarity with GRC platforms and governance tooling.
• CISSP, CISM, CRISC, CISA, or similar certifications.
#LI-Hybrid #LI-LR1
What we offer you:
Prudential is required by state specific laws to include the salary range f
Salary insight
The midpoint of this range ($152k) is about 8% below the median disclosed salary for New York roles listed on ForgeApply ($165k across 8,051 jobs).
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this Pru role before you apply.
Tailor my resume for this jobSimilar jobs
- Lead, Information Security Policy & Enablement — Pru · Newark, NJ
- Lead, Application Security — Pru · Newark, NJ
- Lead, Offensive Security — Humana · Remote
- Lead, Offensive Security — Humana · Remote
- Lead, Business Intelligence, Information Security Governance — Pru · Newark, NJ
- Information Security Lead — Clicktherapeutics · New York, NY or Boston, MA
- Lead, Information Security GRC Automation — Pru · Newark, NJ
- Lead, Infrastructure Security Engineer — Pru · Newark, NJ
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)