See all roles

Sr Director, IT Security

Work from home Full-time role Hiring

Our Company Explore how you can contribute at AmeriLife. For over 50 years, AmeriLife has been a leader in the development, marketing and distribution of annuity, life and health insurance solutions for those planning for and living in retirement. Associates get satisfaction from knowing they provide agents, marketers and carrier partners the support needed to succeed in a rapidly evolving industry. Job Summary Explore how you can contribute at AmeriLife. For over 50 years, AmeriLife has been a leader in the development, marketing and distribution of annuity, life and health insurance solutions for those planning for and living in retirement. Associates get satisfaction from knowing they provide agents, marketers and carrier partners the support needed to succeed in a rapidly evolving industry. The Sr. Director of IT Security serves as AmeriLife’s leader for enterprise cybersecurity, responsible for defining, implementing, and operating a comprehensive cybersecurity program spanning security architecture, cloud security, identity & access management, DevSecOps, incident response, and security operations. This role provides regular cybersecurity insights and updates to the Senior Management, the Board and/or the or Audit Committee and leads a high‑performing organization that includes Security Operations, Security Engineering, and additional specialized functions. This position works closely with the IT Governance, Risk & Compliance (GRC) leader in developing and maintaining a full cybersecurity program. The position ensures that cybersecurity initiatives are fully aligned with business priorities, regulatory requirements, and AmeriLife’s overall risk appetite, while driving a multi‑year roadmap that strengthens AmeriLife’s enterprise security posture. This leader is accountable for consistent regulatory compliance, improved audit and examination outcomes, and the reduction of cyber risk across all AmeriLife entities. Through strategic leadership and operational excellence, the Sr. Director will advance mature, scalable security operations and engineering capabilities and foster a security‑aware culture embedded across the enterprise, enabling increased resilience and ongoing protection of AmeriLife’s technology ecosystem.

Job Description

Key Responsibilities Strategic Leadership & Cybersecurity Program Execution Develop and drive a unified, enterprise‑wide cybersecurity strategy. Monitor emerging threats, technologies, and regulatory requirements, update strategy accordingly. Establish a multi‑year roadmap aligned with AmeriLife’s technology and business goals. Regulatory Compliance & Risk Management Works closely with IT GRC leader to ensure compliance with NYDFS Part 500, SOX ITGC, GLBA, HIPAA, and other regulations. Oversee SOX IT controls, evidence collection, testing, remediation, and audit liaison. Participate in regular cybersecurity risk assessments and report findings to executives and the Board. Security Architecture & Cloud Security Oversee enterprise security architecture across on‑prem, cloud, and hybrid environments. Lead Azure and Microsoft 365 cloud security programs, including CSPM, secure configuration, and tenant governance. Implement Zero Trust principles across identity, devices, networks, and applications. Ensure secure cloud migrations and consistent standards across AmeriLife affiliates. DevSecOps & Application Security Integrate security into SDLC and CI/CD pipelines. Establish secure coding standards and oversee SAST/DAST, dependency scanning, and penetration testing. Promote security‑by‑design principles across development and engineering. Security Operations & Incident Response Direct all SOC activities, including internal analysts and external MDR providers. Oversee MDR and EDR operations, ensuring integration, tuning, detection fidelity, and coordinated response. Maintain the enterprise Incident Response Plan, including triage, containment, forensics, recovery, and root‑cause analysis. Partner with external incident‑response firms for escalated investigations. Oversee managed vulnerability services, ensuring timely scanning, risk scoring, prioritization, and remediation tracking. Manage enterprise vulnerability management lifecycle and patch governance. Governance, Compliance & Audit Assist with the creation and maintaining cybersecurity policies and standards aligned to NIST CSF, NIST 800‑53, ISO 27001. Chair cybersecurity forums to coordinate enterprise adoption and alignment. Team Leadership & Organizational Development Build and lead a high‑performing cybersecurity organization. Define roles, competencies, and KPIs; mentor and develop staff. Promote collaboration between security, IT, and business functions. Enterprise Collaboration & Stakeholder Engagement Partner with IT, Legal, Compliance, ERM, and business leaders to embed security into projects and operational processes. Serve as primary cybersecurity liaison to affiliates. Promote cybersecurity awareness and education enterprise‑wide. Executive Reporting & Budget Management Serve as cybersecurity advisor to the CIO, executive leadership, and the Board. Provide business‑aligned reporting on threats, risks, incidents, compliance, and program maturity. Own and manage the cybersecurity budget; prioritize investments based on risk and regulatory drivers.

Required Qualifications

Bachelor’s degree required; Master's degree or MBA preferred. CISSP or CISM required; CRISC, CISA, CCSP preferred. 6-8 years of progressive cybersecurity leadership; 3-5 years leading teams or major security functions for a company of 3,000+ employees. Strong experience in financial services or insurance. Deep knowledge of NYDFS Part 500, SOX ITGC, GLBA, HIPAA. Expertise in cloud security (Azure/M365), IAM, network security, SOC operations, incident response, and DevSecOps. Exceptional communication skills and the ability to present complex issues to executives and the Board. What AmeriLife Offers A comprehensive benefits package that includes PTO, medical, dental, vision, retirement savings, disability insurance, and life insurance. Equal Employment Opportunity Statement We are an Equal Opportunity Employer and value diversity at all levels of the organization. All employment decisions are made without regard to race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), sexual orientation, gender identity or expression, age, national origin, ancestry, disability, genetic information, marital status, veteran or military status, or any other protected characteristic under applicable federal, state, or local law. We are committed to providing an inclusive, equitable, and respectful workplace where all employees can thrive. Americans with Disabilities Act (ADA) Statement We are committed to full compliance with the Americans with Disabilities Act (ADA) and all applicable state and local disability laws. Reasonable accommodations are available to qualified applicants and employees with disabilities throughout the application and employment process. Requests for accommodation will be handled confidentially. If you require assistance or accommodation during the application process, please contact us at [email protected]. Pay Transparency Statement We are committed to pay transparency and equity, in accordance with applicable federal, state, and local laws. Compensation for this role will be determined based on skills, qualifications, experience, and market factors. Where required by law, the pay range for this position will be disclosed in the job posting or provided upon request. Additional compensation information, such as benefits, bonuses, and commissions, will be provided as required by law. We do not discriminate or retaliate against employees or applicants for inquiring about, discussing, or disclosing their pay or the pay of another employee or applicant, as protected under applicable law. Pay ranges are available upon request. Background Screening Statement Employment offers are contingent upon the successful completion of a background screening, which may include employment verification, education verification, criminal history check, and other job-related inquiries, as permitted by law. All screenings are conducted in accordance with applicable federal, state, and local laws, and information collected will be kept confidential. If any adverse decision is made based on the results, applicants will be notified and given an opportunity to respond.

About Us

Since 1971, AmeriLife has served the needs of its clients. Today, we are a national leader in the development, marketing and distribution of annuity, life and health insurance solutions, with more than 1,000 associates across the country. AmeriLife partners with leading carriers to support consumers’ financial-wellness goals.

Our Mission

AmeriLife offers insurance and retirement solutions to provide peace of mind and help people live longer, healthier lives. Our Values AmeriLife practices five core values at all levels of the organization: Honesty – We deal truthfully with all of our clients Integrity – We always do what is right for our clients Accountability – We put our clients’ needs first by taking take ownership of our actions Excellence – We do more than our jobs by going the extra mile for our clients Courage – We stand up for what is right Apply tot his job Apply To this Job

You might like

Cybersecurity Engineer (SOAR) [JOB ID 20260319]

Work from home Full-time role

Content Marketing Executive, Cyber-Security

Work from home Full-time role

Cybersecurity Cloud Subject Matter Expert

Work from home Full-time role

Cybersecurity Specialist - Freelance AI Trainer Project

Work from home Full-time role

Remote AI Security Assessor & Penetration Expert

Work from home Full-time role

Practice Client Partner-Cyber Security

Work from home Full-time role

Senior Cybersecurity Advisor – Cloud Security

Work from home Full-time role

Security Monitoring Specialist (SIEM, ZTA tools)

Work from home Full-time role

Senior Cyber Security Analyst

Work from home Full-time role

Network Security Director – Cybersecurity Engineering

Work from home Full-time role

Experienced Customer Service Representative – Specialized Services at arenaflex

Work from home Full-time role

Mental Health Therapist - Full Time

Work from home Full-time role

SAP Production Planning

Work from home Full-time role

Chinese Interpreter, DOJ LSS

Work from home Full-time role

Experienced Learning Associate – Virtual Training Facilitator for arenaflex Customer Channels Performance Solutions

Work from home Full-time role

Marketing Manager - Mom & Baby [Maternity Cover]

Work from home Full-time role

Remote Physical Therapist in WA

Work from home Full-time role

Remote Financial Services Recruiter (Insurance & Risk) | Consultant

Work from home Full-time role

Dir, IP Packaging & Label

Work from home Full-time role

Experienced Remote Customer Interaction Specialist – Flexible Hours, Competitive Pay, and Opportunities for Growth

Work from home Full-time role