Principal Information Security Analyst
Listed on 2026-07-18
-
IT/Tech
Cybersecurity, Information Security
Established nearly two centuries ago, FM is a leading mutual insurance company whose capital, scientific research capability and engineering expertise are solely dedicated to property risk management and the resilience of its policyholder-owners. These owners, who share the belief that the majority of property loss is preventable, represent many of the world’s largest organizations, including one of every four Fortune 500 companies.
They work with FM to better understand the hazards that can impact their business continuity to make cost-effective risk management decisions, combining property loss prevention with insurance protection.
Schedule & Location
:
This position requires on-site work one day per week at our Corporate Headquarters and flexibility to be on-site when needed based on the demands of the business.
Relocation is not offered for this position.
Summary
FM is seeking a Principal Information Security Analyst with deep expertise in cybersecurity regulatory compliance and oversight. In this high-impact role, you will lead the execution of FM’s global cybersecurity regulatory compliance program, ensuring the organization proactively identifies, understands, and responds to evolving global cybersecurity requirements.
You will play a critical role in protecting FM by evaluating how cybersecurity regulatory expectations apply to our systems, data, and internal processes, and translating those requirements into actionable controls and practices. This is a highly visible role where your expertise in cyber risk, regulatory frameworks, and control design will help shape business decisions, strengthen our security posture, and ensure ongoing alignment with regulatory obligations.
You will partner closely with security, technology, risk, legal, and business teams to identify gaps, define expectations, and recommend practical, business-aligned solutions. Additionally, you will act as a primary point of coordination for external cybersecurity inquiries, including regulators, auditors, and clients.
You will lead end-to-end cybersecurity regulatory assessments and control evaluations, going beyond standard compliance activities to evaluate alignment across systems, data, and technical processes.
Key Responsibilities
Regulatory & Compliance: Lead the end-to-end cybersecurity regulatory compliance function, including governance, processes, tooling, and reporting.
Respond to External Inquires: Coordinate and lead responses to regulatory exams, client cybersecurity questionnaires, and other external information requests. Partner with Information Security, IT, Risk, Legal, and business stakeholders to gather, validate, and communicate accurate, consistent, and audit-ready responses aligned to FM’s control environment.
Regulatory Horizon Scanning & Impact Analysis: Proactively monitor and evaluate emerging cybersecurity regulations, standards, and guidance globally. Perform impact assessments to determine applicability and required changes to FM’s control environment.
Gap Identification & Remediation Oversight: Lead regulatory gap assessments and control evaluations. As necessary, partner with technical and business teams to define remediation actions and track remediation progress, validate closure of gaps, and escalate risks as needed.
Governance, Reporting, & Audit Readiness: Develop and maintain metrics, dashboards, and reporting on compliance posture, risks, and trends. Provide clear, concise updates to senior leadership and governance committees.
Advisory & Stakeholder Engagement: Act as a trusted advisor on regulatory and compliance matters across IT, security, and business teams. Provide guidance on control design, risk treatment, and regulatory alignment. Influence decisions to ensure alignment with FM’s risk appetite and regulatory obligations.
Program Maturity & Continuous Improvement: Identify opportunities to enhance program efficiency, automation, and maturity. Implement leading practices in regulatory compliance, controls management, and assurance.
Lead and mentor: Lead complex initiatives and provide direction to cross-functional contributors. Promote a culture of accountability,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).