VP IT Security and Risk Management; Hybrid
Listed on 2025-12-18
-
IT/Tech
Cybersecurity, Information Security
Location: Short Hills
About Us
At Selective, we don't just insure uniquely, we employ uniqueness.
Selective is a midsized U.S. domestic property and casualty insurance company with a history of strong, consistent financial performance for nearly 100 years. Selective's unique position as both a leading insurance group and an employer of choice is recognized in a wide variety of awards and honors, including listing in Forbes Best Midsize Employers in 2024 and certification as a Great Place to Work in 2024 for the fifth consecutive year.
Employees are empowered and encouraged to Be Uniquely You by being their true, unique selves and contributing their diverse talents, experiences, and perspectives to our shared success. Together, we are a high‑performing team working to serve our customers responsibly by helping to mitigate loss, keep them safe, and restore their lives and businesses after an insured loss occurs.
OverviewNote for NJ based candidates:
This role will be located at our future headquarters in Short Hills, N.J. Until the new headquarters is operational, the successful candidate will be offered the ability to work in our Branchville, N.J. location during this interim period.
Selective is seeking a Deputy CISO‑ VP of Information Security, responsible for leading the information security, risk management, crisis planning, and crisis response functions within the Information Technology department. In the role, you will develop and execute short‑term plans and longer‑range strategies to mitigate cyber risk by leveraging program maturity assessments, operational reporting, and industry trends. You will also work across teams to ensure alignment with best practices and deliver security enhancement projects.
You will lead teams and projects that are complex in nature and/or of strategic importance to the Selective organization, and will have a moderate number of direct reports consisting of senior managers, managers, architects, engineers, and analysts. This is a unique opportunity to lead and develop a motivated team of security professionals and contribute to the strategic direction of the Information Technology Services (ITS) Department within a growing company.
- Assist the SVP, IT Enterprise Strategy and Execution, in managing day‑to‑day information security, cyber risk management, and incident response activities. Responsible for the daily activities, priorities, and coordination of activities of managers and staff in the security and risk management area.
- In alignment with business plans, evaluate the enterprise information security program, identify gaps, develop short‑term corrective plans and long‑range strategies, and report on program health to internal and external stakeholders.
- Lead planning and response to disaster recovery events and security incident response. Identify, manage, and communicate security incidents to key stakeholders. Maintain business impact analyses and business crisis plans.
- Be responsible and accountable for establishing, updating, and delivering a security awareness and training program.
- Develop, maintain, and enforce information security policies and procedures in alignment with stated risk appetite, changes in threats, and overall compliance goals.
- Oversee all security audits and tasks. Participate in the technical aspects of all IT‑related audits and support internally and externally managed audit activities.
- Collaborate with key business and IT leaders to assess, document, and act on information security risks, in alignment with stated risk appetite. Report to stakeholders on monitored risks as appropriate.
- Be responsible for planning, delivering, operating, and monitoring security technology, processes, and controls.
- Oversee the planning, administration, and performance of the information security and risk management budget, ensuring alignment with organizational priorities and optimal resource utilization.
Knowledge and Requirements
- Expert knowledge of current IT security techniques, software, and hardware.
- Ability to plan and control projects.
- Knowledge of risk management and cybersecurity frameworks, including NIST‑CSF, ISO‑27000, SOX, BASEL II, EU DPD,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).