Job Classification
Technology - Information Security
Your Team
Are you interested in building capabilities that make Information Security easier to understand, adopt, and execute? Prudential's Global Technology & Operations organization is strengthening Information Security governance to improve visibility into security risk, policy adoption, and program execution across the enterprise.
As the
Lead, Information Security Library & Standards, you will help build the foundation that supports Information Security governance across Prudential. This is a unique opportunity to help build and shape a growing Information Security Governance capability, with visibility across senior leadership and the ability to influence how security, risk, and governance are executed across the enterprise. Reporting to the Director of Information Security Governance, you'll partner closely with Risk Management and Information Security leaders to establish a scalable control library, mature security standards, and create the governance processes needed to support a consistent, practical, and audit-ready security program.
This role is based in our office in Newark, NJ. Our organization follows a hybrid work structure where employees can work remotely and from the office, as needed, based on demands of specific tasks or personal work preferences. This position is hybrid and requires your on-site presence on a reoccurring weekly basis at least 3 days per week.
Here is What You Can Expect on a Typical Day
Build & Govern the Information Security Control Library
- Lead the development, enhancement, and ongoing governance of Prudential's Information Security control library, ensuring consistency, traceability, and alignment with enterprise risk and compliance objectives.
- Define and maintain control taxonomy, ownership models, framework mappings, evidence requirements, control narratives, and governance standards.
- Establish traceability across security standards, controls, regulatory requirements, risks, testing activities, evidence repositories, and reporting processes.
- Partner with Information Security domain leaders across Identity & Access Management (IAM), Attack Surface Management (ASM), Cyber Defense & Response (CDR), cloud security, data protection, vulnerability management, and other security control functions to ensure controls accurately reflect current risks, technologies, and operational requirements.
Drive Standards Management, Governance & Regulatory Alignment
- Coordinate the lifecycle management of Information Security standards, including creation, review, approval, publication, maintenance, and retirement.
- Design and implement governance processes, operating models, quality controls, decision frameworks, and review routines that keep standards and controls current, consistent, and audit-ready.
- Align standards and controls with leading frameworks and regulatory requirements, including NIST, ISO 27001, FFIEC, NYDFS, SOC, and related security and assurance standards.
- Support audits, compliance reviews, risk assessments, and regulatory examinations through clear control mappings, standards documentation, evidence requirements, and governance reporting.
- Drive continuous improvement of governance processes, workflows, and control management practices to improve efficiency, transparency, and usability across the organization.
Enable Adoption, Security Alignment & Enterprise Partnership
- Partner with Information Security, Risk Management, Compliance, Technology, Legal, Internal Audit, and business stakeholders to translate complex security requirements into practical and actionable guidance.
- Work closely with Enablement and awareness teams to support adoption of security standards and controls through communications, implementation guidance, FAQs, and training content.
- Establish governance of playbooks, templates, quality standards, and documentation practices that drive consistency across security domains and control owners.
- Use stakeholder feedback, adoption trends, governance metrics, and quality reviews to continuously improve the effectiveness and usability of the control library and standards framework.
- Build trusted partnerships across Information Security, Technology, Risk, Compliance, Audit, and business functions to help drive alignment and adoption of governance standards across the enterprise.
The Skills & Expertise You Bring
- Bachelor's degree or equivalent experience in Cybersecurity, Computer Science, Information Security, Risk Management, Information Systems, Business, a related field or equivalent experience.
- Experience building or maintaining security governance, control frameworks, compliance programs, or risk management initiatives.
- Strong understanding of frameworks such as NIST, ISO 27001, FFIEC, NYDFS, SOC, or related standards.
- Working knowledge of one or more security domains such as IAM, Cloud Security, Data Protection, Vulnerability Management, Attack Surface Management, or Cyber Defense.
- Experience designing governance processes, operating models, ownership structures, quality gates, lifecycle processes and control documentation.
- Strong communication, documentation, and stakeholder management skills.
- Ability to collaborate effectively across security, risk, compliance, technology, business, and audit teams.
Preferred Qualifications
- Experience building or enhancing security control libraries, standards programs, workflow improvements or governance frameworks or Governance, Risk, and Compliance (GRC) tooling.
- Experience supporting audits, examinations, compliance reviews, or risk assessments.
- Familiarity with GRC platforms and governance tooling.
- CISSP, CISM, CRISC, CISA, or similar certifications.
What We Offer You
Prudential is required by state specific laws to include the salary range for this role when hiring a resident in applicable locations. The salary range for this role is from $114,500.00 to $188,900.00. Specific pricing for the role may vary within the above range based on many factors including geographic location, candidate experience, and skills.
- Market competitive base salaries, with a yearly bonus potential at every level.
- Medical, dental, vision, life insurance, disability insurance, Paid Time Off (PTO), and leave of absences, such as parental and military leave.
- 401(k) plan with company match (up to 4%).
- Company-funded pension plan.
- Wellness Programs including up to $1,600 a year for reimbursement of items purchased to support personal wellbeing needs.
- Work/Life Resources to help support topics such as parenting, housing, senior care, finances, pets, legal matters, education, emotional and mental health, and career development.
- Education Benefit to help finance traditional college enrollment toward obtaining an approved degree and many accredited certificate programs.
- Employee Stock Purchase Plan: Shares can be purchased at 85% of the lower of two prices (Beginning or End of the purchase period).
Eligibility to participate in a discretionary annual incentive program is subject to the rules governing the program, whereby an award, if any, depends on various factors including, without limitation, individual and organizational performance. To find out more about our Total Rewards package, visit Work Life Balance | Prudential Careers. Some of the above benefits may not apply to part-time employees scheduled to work less than 20 hours per week.
Prudential Financial, Inc. of the United States is not affiliated with Prudential plc. which is headquartered in the United Kingdom.
Prudential is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, ancestry, sex, sexual orientation, gender identity, national origin, genetics, disability, marital status, age, veteran status, domestic partner status, medical condition or any other characteristic protected by law.
If you need an accommodation to complete the application process, please email
[email protected].
If you are experiencing a technical issue with your application or an assessment, please email
[email protected] to request assistance.