Job Description
This role owns enterprise information security end‑to‑end. The hire will build and operate a scalable security program aligned to business growth, regulatory requirements, and audit rigor across a multi‑entity, highly regulated environment. This leader is hands‑on where needed, decisive on risk, credible with auditors and regulators, and trusted by executives. This is not an advisory or audit‑only role
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.
Required Skills & Experience
• Has personally owned SOC 2 Type II end‑to‑end (planning, scoping, evidence, remediation, auditor interaction)
• Experience operating in regulated environments (SOC 2, NYCRR, FTC, SOX, or similar)
• Proven ability to scale audit scope (e.g., expanding revenue coverage) without degrading evidence quality
• Has established and enforced control ownership across Engineering, IT, and Business teams
• Demonstrated incident command leadership (Sev 1 / Sev 2): structured response, executive comms, post‑incident CAPA
• Has built and led an InfoSec program and team (not audit‑only, not advisor‑only)
Comfortable blocking go‑lives or vendors until minimum controls or documented risk acceptance is in place
Nice to Have Skills & Experience
• Previously reported into a CTO or CIO
• Experience in federated / multi‑entity organizations
• Background balancing GRC rigor with security operations
• Has managed multiple SOC 2 audits concurrently (Type I + Type II)
• Experience scaling security from a small initial team (1–3 people)
• Prior exposure to board‑level or audit committee briefings
Benefit packages for this role will start on the 1st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401k retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.