Principal Purple Team Operator
Listed on 2026-09-30
-
IT/Tech
Cybersecurity, IT Project Manager
Ally and Your Career Ally Financial only succeeds when its people do - and that’s more than some cliché people put on job postings. We love this stuff! We see our people as, well, people - with interests, families, friends, dreams, and causes that are all important to them. Our focus is on the health and safety of our teammates as well as work-life balance and diversity and inclusion.
From generous benefits to a variety of employee resource groups, we strive to build paths that encourage employees to stretch themselves professionally. We want to help you grow, develop, and learn new things. You’re constantly evolving, so shouldn’t your opportunities be, too?
Work Schedule:
Ally designates roles as (1) fully on-site, (2) hybrid, or (3) fully remote. Hybrid roles are generally expected to be in the office a certain number of days per week as indicated by your manager. Your hiring manager will discuss this role's specific work requirements with you during the hiring process. All work requirements are subject to change at any time based on leader discretion and/or business need.
Opportunity
The Principal of Cyber Security position at Ally is a member of the Information Protection and Risk Management team and works closely with other members of the IPRM program to develop and implement a comprehensive approach to the management of security risks Principal of Cyber Security role requires an individual with a strong technical background as well as an ability to work with the IT organization and business management to align priorities and plans with key business objectives.
Responsible for providing technical guidance to staff as they work to accomplish company objectives. This is a mid-level to senior-level highly technical role. At this time, Ally will not sponsor a new applicant for employment authorization for this position.
- Work with the Director of Security Operations to ensure the security program addresses identified risks and business requirements.
- Manage the process of gathering, analyzing and assessing the current and future threat landscape, as well as providing the Director of Security Operations with a realistic overview of risks and threats in the enterprise environment.
- Identify process improvement opportunities and develop subsequent plans of action to resolve gaps with minimal management intervention.
- Monitor and report on compliance with security policies and standards, as well as the enforcement of policies within the IT department.
- Propose changes to existing policies and procedures to ensure operating efficiency and regulatory compliance.
- Assist resource owners and IT staff in understanding and responding to security audit failures reported by auditors and regulatory bodies.
- Provide security communication, awareness and training for audiences which may range from senior leaders to field staff.
- Work as a liaison with vendors and the legal and purchasing departments to establish mutually acceptable contracts and service level agreements.
- Manage production issues and incidents and participate in problem and change management forums.
- Manage and coordinate operational components of incident management, including detection, response and reporting.
- Manage the day-to-day activities of threat and vulnerability management, identify risk tolerances, recommend treatment plans and communicate information about residual risk.
- Manage security projects and provide expert guidance on security matters for other IT projects.
- Ensure audit trails, system logs and other monitoring data sources are reviewed periodically and are in compliance with policies and audit requirements.
- Design, coordinate and oversee security testing procedures to verify the security of systems, networks and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).