Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Talcott Financial Group

Senior IT Risk and Compliance Engineer

Talcott Financial Group

Senior IT Risk and Compliance Engineer for cybersecurity team. Partnering across business units to evolve information security policies and risk management processes.

Posted 7/28/2026full-timeHartford • Connecticut • 🇺🇸 United StatesSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates extensive expertise in cybersecurity governance, risk management, and compliance, with a strong focus on developing and operationalizing security policies and procedures. Proficient in translating technical risks into clear communication for diverse stakeholders while leading security assessments and managing third-party relationships.

Highest-signal resume keywords
Cybersecurity ExperienceGovernance, Risk, Compliance (GRC)CISSP, CISM, CRISC CertificationNIST 800-53, ISO 27001 FrameworksCloud Security Controls (Azure, Oracle Cloud, Microsoft 365)

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Threat and Vulnerability AnalysisSecurity AssessmentsProcess AutomationScripting (Python, PowerShell)Metrics and Reporting Development
Soft Skills
Exceptional Written CommunicationStrong Organizational Skills
Tools & Technologies
ServiceNow GRCArcherSecurity Operations CenterData Loss Prevention
Certifications & Qualifications
CISSPCISMCRISC
Industry Keywords
Insurance IndustryFinancial ServicesRegulatory ExaminationsThird-Party Risk Assessment

Tech Stack

Tools & technologies
AzureCloudCyber SecurityOraclePythonServiceNow

About the role

Key responsibilities & impact
  • Partner with business units and IT leadership to develop, maintain, and operationalize information security policies, standards, and procedures
  • Collaborate with stakeholders across the enterprise to formulate security strategies and risk reduction guidelines that align with business objectives.
  • Consult with business and technology teams on building secure processes and information systems from the ground up
  • Help evolve the security awareness program, translating technical risk into clear communication for employees at all levels within the organization
  • Lead efforts with business units to assess, document, accept, and/or mitigate risk associated with enterprise-wide initiatives and third-party relationships
  • Perform detailed threat and vulnerability analysis, combining sound analytical skills with advanced knowledge of IT security risks
  • Evaluate the severity and potential impact of identified threats, translating findings into actionable recommendations for leadership and business stakeholders
  • Maintain a current understanding of the threat landscape through ongoing research into emerging risks and their potential impact on our environment
  • Lead and perform security assessments of third parties and partners, documenting findings and driving remediation
  • Serve as a key resource in preparing for internal audits, external audits, and state regulatory examinations including drafting responses, managing evidence, and tracking remediation commitments
  • Monitor ongoing compliance with information security policies and assist business units in managing exceptions to policy and standards
  • Provide oversight of managed security services, including vulnerability management, firewall operations, Security Operations Center, and data loss prevention
  • Investigate, document, and follow through on information security incidents and policy violations, ensuring appropriate resolution and lessons learned
  • Identify and implement opportunities to automate manual GRC and compliance workflows, reducing operational overhead and improving program consistency and accuracy
  • Develop metrics, dashboards, and reporting mechanisms to provide leadership clear visibility into risk posture and program health
  • Evaluate new and emerging security technologies leading proof-of-concept assessments and making recommendations to management

Requirements

What you’ll need
  • Bachelor’s degree in information security, Computer Science, Information Systems, or a related field.
  • Minimum of 7 years of cybersecurity experience with strong expertise in governance, risk, compliance, or audit support functions.
  • Industry-recognized certification such as CISSP, CISM, CRISC, or equivalent ISACA or GIAC credential.
  • Working knowledge of security frameworks including NIST 800-53, ISO 27001, and/or NIST CSF.
  • Demonstrated experience supporting regulatory examinations or external audits, including evidence preparation and remediation tracking.
  • Practical experience with cloud security controls (Azure, Oracle Cloud, or Microsoft 365).
  • Experience identifying and implementing process automation within GRC or compliance workflows.
  • Exceptional written and verbal communication skills, with the ability to convey technical risk clearly to non-technical audiences.
  • Strong organizational skills with the ability to manage multiple workstreams, priorities, and stakeholders simultaneously
  • Experience in the insurance or financial services industry, particularly in environments subject to state insurance department oversight is preferred
  • Familiarity with GRC platforms or security automation tooling (e.g., ServiceNow GRC, Archer, or similar) is a plus
  • Experience scripting or light automation skills (Python, PowerShell) applied to security or compliance use cases is a plus
  • Familiarity with vulnerability management programs and third-party risk assessment methodologies is preferred

Benefits

Comp & perks
  • Remote work will be considered
  • Collaborative work environment
  • Opportunities for professional growth
  • Engagement with senior leadership