At Principal, we invest in what matters. And building dedicated teams is where it all begins. We're drawn to people who bring outstanding perspectives, passion, and expertise to help us advance the financial security and well-being of our customers. We also aim to transform our growing business and drive positive change in the communities where we live and work.
When we invest in you, and you invest in us, great things happen.
We are looking for an Information Security Officer (ISO) who will responsible for overseeing the implementation and management of the information security program, including policies, procedures, standards, and guidelines within a specific region. The ISO actively works with the PI BISO, corporate Information Security team and local leadership to ensure consistency of approach and alignment with overall security objectives and priorities. The Information Security Officer is responsible for communicating to local stakeholders and the PI BISO the state of local compliance with information security policies and procedures, while supporting the organization's overall cybersecurity posture and regulatory obligations.
What You'll Do
- Act as the primary local point of contact for Information Security, partnering with the PI BISO, enterprise Information Security teams, senior management and key stakeholders on security-related matters.
- Establish and maintain effective relationships with local business, technology, risk, compliance, audit, privacy and regulatory stakeholders to support information security objectives and compliance requirements.
- Oversee the implementation, governance and continuous improvement of the Information Security Program, ensuring alignment with enterprise policies, standards, industry frameworks and applicable regulatory requirements.
- Provide governance and oversight across key information security domains, including security operations, identity and access management, data protection, vulnerability management, third-party risk management, security awareness and related cybersecurity controls.
- Identify, assess, monitor and report information security risks, vulnerabilities, emerging threats and control effectiveness, providing recommendations to strengthen the organization's security posture and resilience.
- Support security risk assessments, audits, regulatory reviews and remediation activities, ensuring timely resolution of information security findings and compliance gaps.
- Coordinate and support the response to security incidents, regulatory inquiries and other cybersecurity matters in partnership with enterprise Information Security, Risk and Incident Response teams.
- Promote security awareness and foster a strong security culture by supporting employee training, policy adherence and ongoing engagement activities.
- Support business continuity, disaster recovery and other security-related initiatives and projects, providing guidance to ensure successful implementation.
- Prepare and communicate information security updates, metrics and reports to management, governance committees and boards, where appropriate.
- Participate in local risk, audit and governance forums and provide consultation and security guidance to business and technology stakeholders.
Who You Are
- Bachelor's degree holder in Computer Science, Information Security or a related field.
- Minimum of 8–10 years of experience in information security, preferably within a regional or multi-site environment.
- Strong knowledge of security frameworks such as ISO 27001, NIST and COBIT.
- Experience with information security risk assessment and risk management.
- Strong understanding of cybersecurity domains including Security Operations, Identity and Access Management (IAM), Data Loss Prevention (DLP), Vulnerability and Patch Management, Asset Management, Security Awareness and Third-Party Risk Management.
- Experience supporting information security audits, regulatory reviews, control assessments and remediation activities.
- Excellent communication, stakeholder management and influencing skills, with the ability to collaborate effectively across all levels of the organization.
- Strong written and presentation skills with the ability to prepare and present information security reports to senior management, governance committees and boards of directors.
- Ability to work well under pressure, manage competing priorities and respond effectively to tight deadlines.
- Strong analytical skills with the ability to analyze, interpret and communicate security-related data and trends.
- Relevant professional certifications such as CISSP, CISM, CRISC, GIAC or equivalent are preferred.
- Experience in security operations and handling cybersecurity incidents preferred.
Who We Are
Principal Financial Group is a Fortune 500 global leader in financial services focused on insurance, retirement, and asset management. We have 18,000 employees and 51 million customers around the world with over $714B in assets under management.