1

Security Risk Compliance Jobs in New York (NOW HIRING)

The information security and risk posture we establish in the next 12 months will define how M0 is ... Own M0's compliance posture across SOC 2, ISO 27001, and other applicable frameworks -- driving all ...

The information security and risk posture we establish in the next 12 months will define how M0 is ... Own M0's compliance posture across SOC 2, ISO 27001, and other applicable frameworks - driving all ...

... and compliance issues. The role of the Legal Department is to support the firm in pursing the ... and information security risk so as to preserve and maximize the value of the firm over the ...

Showing results 21-40

Security Risk Compliance information

What is security risk compliance?

Security Risk Compliance refers to the process of identifying, assessing, and managing risks to an organization's information systems while ensuring adherence to relevant laws, regulations, and industry standards. Professionals in this field develop policies, conduct risk assessments, and implement controls to protect sensitive data from threats. Their work helps organizations minimize security vulnerabilities and avoid legal or financial consequences related to non-compliance.

What are the key skills and qualifications needed to thrive as a security risk compliance professional?

To thrive as a Security Risk Compliance professional, you need a solid understanding of information security frameworks, risk assessment methodologies, and relevant regulations, often supported by a degree in cybersecurity or a related field. Familiarity with tools such as GRC (Governance, Risk, and Compliance) platforms, vulnerability scanners, and certifications like CISSP, CISA, or CRISC is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and collaborate with stakeholders. These skills are vital to ensure organizations meet compliance requirements, mitigate risks, and maintain trust with clients and regulators.

What are some common challenges faced by security risk compliance professionals when balancing regulatory requirements with business objectives?

Security Risk Compliance professionals often need to navigate the delicate balance between adhering to complex regulatory standards and supporting the organization's operational goals. A major challenge is ensuring compliance without hindering business innovation or efficiency. This involves working closely with various departments to interpret regulations, communicate risks, and implement pragmatic controls that satisfy both legal requirements and business needs. Effective collaboration and ongoing education are key to overcoming these challenges and maintaining a strong security posture.

What is the difference between Security Risk Compliance vs Security Analyst?

AspectSecurity Risk ComplianceSecurity Analyst
CertificationsISO 27001 Lead Implementer, CISSP, CISACISSP, CompTIA Security+, GIAC Security Certifications
Work EnvironmentPolicy development, compliance audits, risk assessmentsMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageFinancial, healthcare, government sectors focusing on regulatory adherenceIT departments across various industries focusing on security operations

Security Risk Compliance professionals focus on ensuring organizations meet regulatory standards and manage security risks through policies and audits. Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within similar environments, their core responsibilities differ: compliance versus active security monitoring.

What cities in New York are hiring for Security Risk Compliance jobs?

Cities in New York with the most Security Risk Compliance job openings:

Infographic showing various Security Risk Compliance job openings in New York as of June 2026, with employment types broken down into 1% As Needed, 81% Full Time, 17% Part Time, and 1% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution.

Lead, Information Security Policy & Enablement

Prudential Financial, Inc.

Newark, NJ • On-site

$114K - $188K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 25 days ago


Prudential rating

8.7

Company rating: 8.7 out of 10

Based on 49 frontline employees who took The Breakroom Quiz

72nd of 315 rated insurance


Job description

Job Classification:
Technology - Information Security
Your Team
Are you interested in building capabilities that make Information Security easier to understand, adopt, and execute? As part of Prudential's Global Technology & Operations organization, the Information Security team is strengthening its governance capabilities to improve visibility into security risk, policy adoption, and program execution across the enterprise.
As the Lead, Information Security Policy & Enablement, you will serve as the primary bridge between Information Security's Secure Governance Office and business, product, technology, and corporate functions. Reporting to the Director of Information Security Governance, you'll help shape how security policies, standards, and guidance are communicated, understood, and adopted across the enterprise. Partnering with security advisors, Risk Management, Compliance, Legal, Internal Audit, Product, Engineering, and business stakeholders, you'll transform security requirements into practical guidance that helps teams confidently make security part of how they work every day.
This role is based in our office in Newark, NJ. Our organization follows a hybrid work structure where employees can work remotely and from the office, as needed, based on demands of specific tasks or personal work preferences. This position is hybrid and requires your on-site presence on a reoccurring weekly basis at least 3 days per week.
Here is What You Can Expect on a Typical Day
Drive Stakeholder Engagement
  • Partner with security, technology, product, business, risk, compliance, legal, audit, and communications teams to align policy updates and adoption strategies.

  • Gather stakeholder feedback and translate security requirements into practical, actionable expectations.

  • Build trusted partnerships across Information Security, business, technology, risk, compliance, legal, and audit teams to drive alignment and successful outcomes.

Lead Change, Communications & Adoption
  • Develop communication and change management strategies that increase awareness and adoption of security policies and standards.

  • Create stakeholder communications, FAQs, implementation guidance, talking points, and readiness materials.

  • Drive alignment and adoption through coordinated engagement, clear communications, and collaboration with awareness and education teams.

  • Track adoption trends and stakeholder feedback to continuously improve program effectiveness.

Enable Policy Adoption & Stakeholder Readiness
  • Build reusable toolkits, templates, and engagement playbooks that support consistent policy implementation.

  • Translate complex security priorities, policy requirements, and governance expectations into practical guidance for technical, operational, and executive audiences.

  • Help stakeholders understand not just what is changing, but why it matters and how it supports broader business objectives.

The Skills & Expertise You Bring
  • Bachelor's degree or equivalent experience in Cybersecurity, Information Security, Risk Management, Business, Communications, a related field or equivalent experience

  • Experience supporting information security governance, policy management, compliance programs, or technology risk initiatives.

  • Working knowledge of security and risk frameworks such as NIST, ISO 27001, FFIEC, NYDFS, SOC, or similar standards.

  • Ability to translate complex security concepts, risk priorities, governance expectations, and control obligations into clear, practical guidance for diverse audiences.

  • Strong communication, change management, and stakeholder engagement skills.

  • Experience influencing across technology, business, risk, compliance, and audit organizations.

  • Working knowledge in one or more security domains such as IAM, ASM, CDR, cloud security, third-party risk, or data protection.

Preferred Qualifications
  • Experience within an Information Security, Technology Risk, BISO, Security Advisory, or Governance function.

  • Experience developing enablement materials, policy adoption metrics, communications strategies, adoption programs, or learning content.

  • Experience supporting audits, regulatory examinations, or governance forums.

  • Familiarity with GRC platforms, policy management tools, Jira, or ServiceNow.

  • CISSP, CISM, CRISC, CISA, Prosci, or similar certifications.

#LI-Hybrid #LI-LR1
What we offer you:
Prudential is required by state specific laws to include the salary range for this role when hiring a resident in applicable locations. The salary range for this role is from $114,500.00 to $188,900.00. Specific pricing for the role may vary within the above range based on many factors including geographic location, candidate experience, and skills.
  • Market competitive base salaries, with a yearly bonus potential at every level.
  • Medical, dental, vision, life insurance, disability insurance, Paid Time Off (PTO), and leave of absences, such as parental and military leave.
  • 401(k) plan with company match (up to 4%).
  • Company-funded pension plan.
  • Wellness Programs including up to $1,600 a year for reimbursement of items purchased to support personal wellbeing needs.
  • Work/Life Resources to help support topics such as parenting, housing, senior care, finances, pets, legal matters, education, emotional and mental health, and career development.
  • Education Benefit to help finance traditional college enrollment toward obtaining an approved degree and many accredited certificate programs.
  • Employee Stock Purchase Plan: Shares can be purchased at 85% of the lower of two prices (Beginning or End of the purchase period).

Eligibility to participate in a discretionary annual incentive program is subject to the rules governing the program, whereby an award, if any, depends on various factors including, without limitation, individual and organizational performance. To find out more about our Total Rewards package, visit Work Life Balance | Prudential Careers. Some of the above benefits may not apply to part-time employees scheduled to work less than 20 hours per week.
Prudential Financial, Inc. of the United States is not affiliated with Prudential plc. which is headquartered in the United Kingdom.
Prudential is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, ancestry, sex, sexual orientation, gender identity, national origin, genetics, disability, marital status, age, veteran status, domestic partner status, medical condition or any other characteristic protected by law.
If you need an accommodation to complete the application process, please email accommodations.hw@prudential.com.
If you are experiencing a technical issue with your application or an assessment, please email careers.technicalsupport@prudential.com to request assistance.

What Prudential employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom