The Director of Information Security reports directly to the Global Head of Technology and is responsible to establish, maintain and oversee the enterprise-wide vision, strategy, architecture, policies and programs to ensure information assets are protected, technology systems are secure, and security and business continuity risk/reward decisions are balanced and comply with external regulatory requirements while maintaining an understanding of the challenges facing the business.
The person in this role will drive an information privacy and security-conscious culture, and is responsible for the analysis of risks, the design for risk remediation and the communication of security risks, both tactical and strategic to other business leaders, senior executives, internal and external auditors and boards of directors. The person in this role manages Russell Investments’ outsourced Security Operations Center (SOC) and the end-to-end IT Security Services (operationally and architecturally) coming from the firm’s primary IT Managed Services Provider. In addition, the person in this position is responsible in consultation with the Compliance and Global Risk Management Departments for developing and maintaining the Information Security policies, standards and guidelines which support regulatory compliance and security best practices.
The Director of Information Security directly manages a Security team of internal Russell Associates in the functional areas including, but not limited to:
- Security Governance
- Security Forensics
- Threat Intelligence
- Security Analysis
- Security Engineering
- Security Provider Management
- Security Operations
- Security Architecture
- Security Awareness
- Vendor Management
- Audit Assurance
- Security Communication to all levels of associates and senior management
The person in this role is accountable for managing, leading and developing the team into an increasingly well-educated and effective group of Security experts while also cultivating, within the team, a solid understanding of business needs and process cycles needed to ensure the successful execution of service levels, metrics, and reporting for advanced Security solutions and outsourced Security Services. The Director of Information Security is required to effectively balance the business’ evolving needs for flexible and easy-to-use solutions with requirements that keep Russell Investments’ information assets secure.
The responsibilities of the individual in this position include:
- Establish an IT security vision and strategy by collaborating with senior leadership team and work with all aspects of the business and company to develop and drive the security vision. Accountable for designing and delivering the security roadmap.
- Lead and mentor a collaborative and responsive team of skilled security professionals covering the breadth of shared services, engineering, application security, and risk management.
- Collaborate with senior leadership on all IT related aspects of risk management to identify, assess and, as necessary, address these risks. Serve as an expert advisor to senior leadership on IT security matters.
- Design, promote and assist with the implementation of organization-wide security solutions, which align Russell Investments’ business objectives with its information technology infrastructure, physical infrastructure and its human resources.
- Develop and maintain Information Security policies, standards and guidelines which support regulatory compliance and security best practices.
- Stay current on technological advances in the field and identify areas of use in the organization, particularly with financial services Fintech.
- In collaboration with Global Risk Management, orchestrate integrated contingency plans and business resumption efforts throughout Russell Investments so that all such efforts are responsive to Russell Investments’ needs.
- Develop plans, goals, objectives, service level agreements (SLAs) and other project management aids for the coordination of all security efforts throughout the organization in a manner which is fully in support of business strategies and objectives.
- Act as the primary change agent who facilitates information security related improvements in organizational culture, business relationships and product/service design.
- Oversee the development, implementation, and maintenance of global information security policy, information security standards, guidelines and procedures; develop emergency procedures and incident response protocols; acts as the control point during significant information security incidents.
- Detect, report, contain and mitigate incidents that impair adequate data and infrastructure security.
- Understand potential threats, vulnerabilities, and control techniques. Monitor network of vendors and employees to ensure the safeguarding of information assets. Facilitate periodic penetration testing and security audits; establish information security related risk assessment criteria and methodology.
- Manage the multiple tiers of Security Technicians who oversee the individual service delivery areas they have been assigned to enable SLA monitoring, customer satisfaction, problem and change management, escalation, notification and resolution.
- Actively manage, monitor, and negotiate brokered service contracts to reflect the Business Unit’s evolving expectations and requirements.
- Maintain relationships with local, state and federal law enforcement and other related government agencies in support of information security program and roadmap.
- Ensure a formal System Deployment Lifecycle and body of technical standards and methodologies are defined and followed which supports Russell Investments’ interests, including security, technology and business needs.
- Collaborate with the Compliance and Legal Departments to ensure that information security programs comply with relevant laws, regulations and policies, and to maintain a collaborative and integrated approach to information security and privacy.
- Anticipate and identify issues inhibiting the attainment of project goals; develop and implement corrective actions.
- Foster and maintain good relationships with customers to ensure processes are integrated to support expected customer service levels.
- Facilitate an effective team environment.
The successful candidate will have extensive demonstrable skills and experiences including the following:
- At least 15 years of successful experience in security, IT architecture or engineering management. Significant understanding of system infrastructure technologies including network, server, end-point, mobile, storage.
- 10 years of senior management experience working with C-Level executives, clients and customers.
- Experience in preparing for and leading responses to cybersecurity incidents, including readiness testing, detection, investigation, and remediation, and demonstrated understanding of the business, legal, reputational, and other risks and considerations that cybersecurity threats pose.
- Knowledge of the Asset Management & Financial Services industry.
- Knowledge of software development lifecycle.
- Business continuity/disaster recovery knowledge and experience.
- Ability to translate complex technical concepts into language suitable for a range of audiences, including software engineers, business and technical leaders and external security community members.
- Superior verbal, written and presentation communication skills.
- Ability to influence; collaboration and strong leadership skills along with the ability to lead enterprise change.
- Knowledge of security best practice frameworks, with a preference for NIST, ISO 27001.
- Bachelor degree in Business, MIS, Engineering, Computer Science or related field (or equivalent experience).
- Relevant certifications such as CISSP and CISM are preferred.
Russell Investments is a global financial services firm that serves institutional investors, financial advisors and individuals working with their advisors in more than 40 countries.
Founded in 1936, Russell Investments is one of only a few firms that offers actively managed multi-asset portfolios and services that include advice, investments and implementation. With core capabilities extending across capital market insights, manager research, asset allocation, portfolio implementation and factor exposures Russell Investments stands with clients to achieve their desired investment outcomes.
A pioneer, Russell Investments began its strategic pension fund consulting business in 1969 and today is a consultant to some of the largest pools of capital in the world. With four decades of experience researching and selecting investment managers, meeting annually with more than 2,200 managers around the world, Russell Investments is well-known worldwide for its investment advice.
Headquartered in Seattle, Washington, Russell Investments operates globally with 21 offices (as of August 2016) across the world, providing Investment Services in the world’s major financial centers, including London, Paris, Amsterdam, Sydney, Tokyo, Shanghai, San Diego and New York.
Russell Investments offers a competitive compensation and benefit package to associates including: medical, vision and dental coverage; a profit-sharing retirement plan; sabbatical leave every 10 years; and tuition assistance. Most importantly, Russell Investments offers a work environment where respect for the individual and teamwork are part of our fundamental values. As an Equal Opportunity Employer, Russell Investments supports workforce diversity.