Reinsurance Group of America logo
Reinsurance Group of America

Reinsurance Group of America, Incorporated (RGA), a Fortune 500 company, is among the leading global providers of life reinsurance and financial solutions, with approximately $3.5 trillion of life reinsurance in force and assets of $92.2 billion as of December 31, 2021. Founded in 1973, RGA today is recognized for its deep technical expertise in risk and capital management, innovative solutions, and commitment to serving its clients. With headquarters in St. Louis, Missouri, and operations around the world, RGA delivers expert solutions in individual life reinsurance, individual living benefits reinsurance, group reinsurance, health reinsurance, facultative underwriting, product development, and financial solutions. To learn more about RGA and its businesses, visit our website at www.rgare.com.

Senior Security & Risk Management Specialist

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 3,164Since 1973

Location

Worldwide

Posted

4 days ago

Salary

$89.3K - $134.9K / year

Seniority

Senior

Job Description

Senior Security & Risk Management Specialist

Reinsurance Group of America

Role Description Under limited supervision, this role acts as a strategic bridge between technical security controls and enterprise compliance and risk requirements as part of a ServiceNow IRM/GRC implementation team supporting the Global Security Office (GSO) and Enterprise Risk initiatives; with primary accountability for automating, designing, configuring, and sustaining scalable IRM capabilities while adhering to security frameworks within the ServiceNow platform. The position requires practical experience translating regulatory, risk, audit, and compliance requirements into production-ready platform configurations, mappings, workflows, data models, and reporting analytics, not just advisory guidance, including requirements validation against user stories, UAT coordination, agile testing support, and release readiness. The role requires a strong analytical and problem-solving approach to operationalize GRC lifecycles—including policy, compliance, risk, audit, and regulatory change management—and to clearly communicate complex IRM concepts and design decisions to both technical teams and business stakeholders, supported by stakeholder enablement through role-based training, job aids, and awareness communications. Responsibilities include monitoring and evaluation of control, regulatory, and security processes to ensure assurance over global systems and data, leveraging advanced understanding of ServiceNow IRM/Audit functionality, CMDB and entity modeling fundamentals, and an in-depth understanding of ServiceNow platform dependencies and integrations. Principal Duties - Work with functional and technical requirements to design and implement within ServiceNow Enterprise IRM Application and automate where possible. - Support and maintain ongoing processes for Enterprise IRM Application with scope, product, and operational changes/maintenance. - Capture, support, and validate requirements to technical developers and move along deployment lifecycle including user acceptance testing and agile testing, assuring alignment between stories and stakeholders and taking processes into features/requirements for implementations. - Understand dependencies as aligned to ServiceNow architectural requirements. - Collaborate with compliance, security, and risk professionals on projects related to compliance with regards to Security Frameworks (NIST CSF/SOX/DORA) and other regulations. - Develop and administer just-in-time training and awareness campaigns for various IRM/GRC groups within the company. - Provide process improvement recommendations to mitigate risk, meet business obligations, and regulatory requirements. - Facilitate incoming audits and assessments, coordinate discussions with appropriate owners and business stakeholders, and follow up on any remediation activities identified to meet associated due dates to ensure timely completion. - Participate in the development of policies, standards, controls, procedures, and security and privacy audits and assessments. - Ability to structure, scope, and compile data to support reporting. - Perform other duties as assigned. Qualifications - Bachelor’s degree or equivalent experience - Required - Master's degree or professional industry certification - Preferred - 4+ years' relevant experience in IT security, privacy, audit, controls and regulatory compliance, or related experience - Required - Deep understanding of ServiceNow platform and its capabilities, dependencies with proficiency in ServiceNow administration and development and architectural requirements with experience in Version(s) after Yokohama - Required - ServiceNow GRC framework and process administration (Regulatory Change Management a plus) - Required - General knowledge of business and technology operations; ability to work well within a team setting and maintain a high level of confidentiality - Required - Intermediate knowledge of global standards and regulations regarding security, privacy, and fraud - Required - Demonstrated ability to learn and stay current on data privacy, data security, and fraud threats and vulnerabilities - Required - Intermediate organizational, planning and task management skills with high attention to detail; ability to adjust to changing priorities and work under tight timelines - Required - Intermediate level of investigative, analytical and problem-solving skills; ability to set goals, communicate expected outcomes and liaise with individuals across a variety of functions and levels - Required - Excellent customer service skills; ability to balance multiple priorities, deadlines and deliverables while maintaining a positive attitude - Required - Intermediate oral and written communication skills; ability to convey information in a clear and concise manner and provide regular proactive updates to team members, key stakeholders, and mid-level management - Required - Quick to adapt to new methods; ability to be flexible when needed, take initiative and demonstrate accountability - Required - Insurance/Reinsurance industry experience or certifications - Preferred - Information security, privacy, compliance, risk or audit professional certifications, such as: SSCP, CIPP, CISA and Security+ - Preferred - Intermediate understanding of domestic and global security & regulations - Preferred Requirements - ServiceNow Expertise as GRC Admin or GRC/IRM implementation analyst OR ServiceNow University GRC: Integrated Risk Management (IRM) Implementer - Required - Strong understanding of GRC Lifecycles management (Policy, Controls, Audit, Risk, Regulatory Change Management, Advance Risk and Advance Audit) - Required - Strong understanding of Reporting, Dashboards, and workspace within ServiceNow - Required - Understanding of Regulatory tool integrations with ServiceNow - Strong understanding of Entities/CMDB within ServiceNow - Required - Microsoft Office application experience (Excel, Word, Visio, Teams, SharePoint) - Required - Familiarity with IT and security systems - Required - Knowledge of applicable regulations such as Sarbanes-Oxley, DORA, NY DFS, GLBA, GDPR etc. - Required - IT Control Frameworks including NIST CSF/P, NIST AI, COBIT, ITIL, ISO 27001/27002, CIS, etc. - Preferred - Knowledge of risk assessment methods - Preferred - Experience reviewing SOC1 and SOC2 attestations - Preferred - Project management skills/experience - Preferred - Power-BI Experience for reporting, queries and creating dashboards - Preferred Benefits - Gain valuable knowledge from and experience with diverse, caring colleagues around the world. - Enjoy a respectful, welcoming environment that fosters individuality and encourages pioneering thought. - Join the bright and creative minds of RGA, and experience vast, endless career potential. Compensation Range $89,310.00 - $134,870.00 Annual. Base pay varies depending on job-related knowledge, skills, experience and market location. In addition, RGA provides an annual bonus plan that includes all roles and some positions are eligible for participation in our long-term equity incentive plan. RGA also maintains a full range of health, retirement, and other employee benefits. Company Description RGA is a purpose-driven organization working to solve today’s challenges through innovation and collaboration. A Fortune 200 Company and listed among its World’s Most Admired Companies, we’re the only global reinsurance company to focus primarily on life- and health-related solutions.

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 10,001+Since 1997H1B No Sponsor

• Assist with monitoring security alerts and investigating potential security incidents. • Support vulnerability scanning and help document findings and remediation efforts. • Participate in security assessments, audits and compliance activities. • Assist with user access reviews and identity and access management processes. • Use data analysis, statistical models, historical information, and financial knowledge to make informed risk exposure and management strategies decisions. • Help develop internal processes and methodologies for risk assessment and risk monitoring. • Perform other cyber security-related projects and tasks as assigned.

California
$27 - $33 / hour
Defy Security logo

Enterprise Account Executive, Cybersecurity

Defy Security

Cybersecurity experts who put customers back where they belong: First.

Full TimeRemoteTeam 51-200Since 2017H1B No Sponsor

• Own the enterprise sales cycle — from prospecting and qualification to negotiation and close — across $1B+ revenue organizations. • Engage directly with CISOs, CIOs, and CFOs to align cybersecurity investments to enterprise goals. • Lead multi-stakeholder deals (6–12 months) in partnership with Solutions Architects, Services, and OEM channel partners. • Drive platform adoption — move customers from point products to integrated cybersecurity architectures. • Collaborate cross-functionally with Defy’s Services, Engineering, and Partner teams to deliver client success and measurable outcomes. • Apply consultative methodologies (e.g., MEDDPICC, Challenger, Command of the Message) to position Defy’s value and differentiation. • Consistently exceed quarterly and annual sales goals for bookings, revenue, and gross margin. • Represent Defy with executive presence — leading presentations, proposals, and value discussions with boards and senior leaders.

Minnesota
$110K - $130K / year
Defy Security logo

Enterprise Account Executive – Cybersecurity

Defy Security

Cybersecurity experts who put customers back where they belong: First.

Full TimeRemoteTeam 51-200Since 2017H1B No Sponsor

• Own the enterprise sales cycle — from prospecting and qualification to negotiation and close — across $1B+ revenue organizations. • Engage directly with CISOs, CIOs, and CFOs to align cybersecurity investments to enterprise goals. • Lead multi-stakeholder deals (6–12 months) in partnership with Solutions Architects, Services, and OEM channel partners. • Drive platform adoption — move customers from point products to integrated cybersecurity architectures. • Collaborate cross-functionally with Defy’s Services, Engineering, and Partner teams to deliver client success and measurable outcomes. • Apply consultative methodologies (e.g., MEDDPICC, Challenger, Command of the Message) to position Defy’s value and differentiation. • Consistently exceed quarterly and annual sales goals for bookings, revenue, and gross margin. • Represent Defy with executive presence — leading presentations, proposals, and value discussions with boards and senior leaders.

New York
$110K - $130K / year
Defy Security logo

Enterprise Account Executive – Cybersecurity

Defy Security

Cybersecurity experts who put customers back where they belong: First.

Full TimeRemoteTeam 51-200Since 2017H1B No Sponsor

• Own the enterprise sales cycle — from prospecting and qualification to negotiation and close — across $1B+ revenue organizations. • Engage directly with CISOs, CIOs, and CFOs to align cybersecurity investments to enterprise goals. • Lead multi-stakeholder deals (6–12 months) in partnership with Solutions Architects, Services, and OEM channel partners. • Drive platform adoption — move customers from point products to integrated cybersecurity architectures. • Collaborate cross-functionally with Defy’s Services, Engineering, and Partner teams to deliver client success and measurable outcomes. • Apply consultative methodologies (e.g., MEDDPICC, Challenger, Command of the Message) to position Defy’s value and differentiation. • Consistently exceed quarterly and annual sales goals for bookings, revenue, and gross margin. • Represent Defy with executive presence — leading presentations, proposals, and value discussions with boards and senior leaders.

Texas
$110K - $130K / year