Lead Info Security Analyst - Issue and Regulatory
Listed on 2026-07-29
-
IT/Tech
Cybersecurity, Information Security & Data Protection
The Lead Information Security Analyst (Cybersecurity) is responsible for strengthening Global Cybersecurity and Fraud Management (GCFM) control programs by implementing and supporting assessment readiness activities, as well as monitoring, escalating, reporting, and influencing the prioritization of significant risks and control weaknesses.
The GCFM organization is responsible for keeping pace with the ever-changing cybersecurity and fraud management landscape, safeguarding the company's assets from threats and attacks, and managing information technology and security risks and incidents.
The Lead Information Security Analyst serves as the primary interaction point between GCFM Control and Control Program owners and line of defense partners, as well as external assessors and auditors.
Key Responsibilities And Duties- Relationship Management — Build and maintain effective relationships with key stakeholders across all three lines of defense and with internal and external business partners to successfully address current regulatory examinations, audits, and inquiries, and prepare for future ones.
- Issue Management — Support the Holistic Issue Management enterprise program and provide appropriate governance and oversight for the GCFM Issue Portfolio. Ensure the execution of program requirements and support activities required to document and report on risk remediation activities.
- Regulatory Support — Communicate the schedule of regulatory exams that impact IT, assess readiness, and provide support for interactions with regulators and assessors. Track information requests, perform preliminary reviews of artifacts prior to submission to legal and compliance partners, and schedule meetings with regulators as needed. Govern regulatory findings as they are documented and tracked as formal issues.
- Assessment Readiness — Maintain and develop the GCFM evidence catalog to support ongoing assessment readiness.
- University (Degree) Preferred
- 5+ Years Required; 7+ Years Preferred
- Physical Requirements:
Sedentary Work
8IC
Required Qualifications- 5 or more years of working experience in Cybersecurity/Information Security, IT/Technology Risk Management, IT/Technology Compliance, IT/Technology Audit, or Information Technology.
- Experience with Cybersecurity/Information Security-related laws, regulations, and control frameworks, such as NIST CSF, and experience with control testing of technology risks, controls, policies, and standards.
- Experience independently evaluating and/or performing risk and control assessments and audits across Cybersecurity/Information Security domains.
- Professional certifications including CISSP, CISA, CRISC, CISM, and/or CCSP.
Accountability, Adaptability, Business Continuity Planning, Cloud Computing Security, Collaboration, Communication, Compliance, Consultative Communication, Cybersecurity, Detail-Oriented, General Risk Management, Network Security, Prioritizes Effectively
Anticipated Posting End DateBase Pay RangeBase Pay Range: $121,000/yr - $149,000/yr
Actual base salary may vary based upon, but not limited to, relevant experience, time in role, base salary of internal peers, prior performance, business sector, and geographic location. In addition to base salary, the competitive compensation package may include, depending on the role, participation in an incentive program linked to performance (for example, annual discretionary incentive programs, non-annual sales incentive plans, or other non-annual incentive plans).
CompanyOverview
Every worker deserves a secure retirement. For more than 100 years, TIAA has delivered it for millions of people. Founded to help educators retire with dignity, today we're a market-leading retirement company fueled by world-class asset management. But we're not just another legacy financial services firm. We’re fighting harder than ever before for our clients and the many Americans who need us.
OurCulture of Impact
At TIAA, we're on a mission to build on our 100+ year legacy of delivering for our clients while evolving to meet tomorrow's challenges. We equip…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).