Director, Information Security at USAA
Skip to main content

Director, Information Security

Job ID
Date posted

Purpose of Job

Let’s do something that really matters.

At USAA, we have an important mission: facilitating the financial security of millions of U.S. military members and their families. Not all of our employees served in our nation’s military, but we all share in the mission to give back to those who did. We’re working as one to build a great experience and make a real impact for our members.

We believe in our core values of honesty, integrity, loyalty and service. They’re what guides everything we do – from how we treat our members to how we treat each other. Come be a part of what makes us so special!

We are seeking a dedicated Director, Information Security to be responsible for the making sure the policies and standards around customer access and identity management are incorporated into the Member/customer experiences. The ideal candidate will have expert knowledge of NIST 800.63 and FFIEC guidance for this space.

This Director position can be based in San Antonio, TX or work remotely in the continental U.S. with occasional business travel.

Oversees one or more teams providing analytical, business or technical support functions and is responsible for the development, implementation, management and oversight of enterprise information security policies, standards, processes and solutions that ensure USAA establishes, deepens and retains a best-in-class security posture. Engages with senior leadership to develop, design, and deliver a balanced governance and assurance model across multiple domains to ensure security mentorship is implemented as designed. This role has a direct impact on protecting USAA’s brand and reputation within assigned Information Security domains. Establishes strategic direction and coordinates the overall strategies and procedures for their information security domain. Directs, plans, and coordinates activities of professional and administrative staff engaged in providing information security/cyber security services associated with existing and emerging security risks in a sophisticated and highly regulated environment. Partners with the lines-of-business, Enterprise Risk and Compliance, Audit Services, and Legal, to support enterprise Information security risk and compliance initiatives

Job Requirements

What you'll do:

  • Identifies and runs existing and emerging risks that stem from business activities and the job role.

  • Ensures risks associated with business activities are effectively identified, measured, supervised, and controlled.

  • Follows written risk and compliance policies, standards, and procedures for business activities.

  • Responsible for strategic ownership of critical security domains or capabilities, develops multi-year roadmaps and/or a leader of Manager Seniors.

  • Establishes and ensures compliant execution of their information security domain's short- and long-term strategic vision, strategy, goals, and metrics and governs the overall policies, standards, and procedures for their assigned information security domain.

  • Directs and ensures effective operation of an enterprise information security domain including capacity, resilience and dependability capabilities and how changes in conditions, operations, or the environment will affect the system's operation.

  • Develops, reviews and communicates information security risk management policies and procedures in partnership with the Chief Information Security Officer (CISO) and other senior leaders to ensure appropriateness and adequacy versus industry standard processes and regulatory requirements.

  • Works with external regulators to represent USAA in discussions regarding their specific information security domain.

  • Leads all aspects of the continuous monitoring of cybersecurity activities and alerts senior management to potential risks, compliance issues, and operational inefficiencies.

  • Develops, designs, and delivers a balanced governance and assurance model across multiple domains and the Enterprise.

  • Identifies, monitors and evaluates operational solutions to reduce information security risk, meet compliance requirements and increase enterprise workforce efficiency, business agility and workforce scalability.

  • Promotes information security awareness across the enterprise and with the external security community

  • Serves as financial steward for the organization and lea manpower and budgets to ensure they efficiently meet the needs of the organization.

  • Builds and supervises a team of employees for assigned functional area through ongoing execution of recruiting, development, retention, mentor and support, performance management, and managerial activities.

What you have:

  • Bachelor’s Degree in Information Security, Information Technology, Computer Science, Business Administration, or Information Systems/Management or related field; OR 4 years of related experience (in addition to the minimum years of experience required) may be substituted in lieu of degree.

  • 8 years of related information security experience in one or more domains, e.g.: Cyber Security, Identity and Access Management, Information Assurance and Governance, Operational Risk Management and/or Information Technology to include strong accountability for projects, programs, processes, or policies.

  • 3 years of direct team lead, supervisor, or management experience in an Information Security or Information Technology domain.

  • 4 years of researching, designing or implementing technology, information security or cybersecurity solutions in a large financial institution or large enterprise information security program with a proven track record of delivering results in compliance with federal/state/regulatory information security and risk management policies, standards, and guidelines.

  • Experienced knowledge of relevant regulations and standards related to risk management and information security, e.g.: FFIEC, Gramm-Leach-Bliley, FFIEC Cybersecurity Assessment Tool, NIST Cybersecurity Framework and the Payment Card Industry Data Security Standard.

  • Solid understanding of security technologies to include cryptography, authentication, authorization, and controls.

  • Solid Understanding of IT risks and experience implementing security solutions.

  • Knowledge of threats, vulnerabilities, attack methods and countermeasures for web-based applications, networks, and cyber security solutions.

  • Demonstrated financial competence involving budgets, forecasting, and completing the budgets for applicable information security, cybersecurity, or technology support function.

  • Experienced level of discernment in the areas of business operations, risk management, industry practices and emerging trends.

  • Strong written and verbal communication skills, including the ability to communicate technical analyses to a non-technical audience.

What sets you apart:

  • US military experience through military service or a military spouse/domestic partner [

The above description reflects the details considered necessary to describe the principal functions of the job and should not be construed as a detailed description of all the work requirements that may be performed in the job.

What we offer:

Compensation: USAA has an effective process for assessing market data and establishing ranges to ensure we remain competitive. You are paid within the salary range based on your experience and market data of the position. The actual salary for this role may vary by location. The salary range for this position is: $152,290-$291,040.

Employees may be eligible for pay incentives based on overall corporate and individual performance and at the discretion of the USAA Board of Directors.

Benefits: At USAA our employees enjoy best-in-class benefits to support their physical, financial, and emotional wellness. These benefits include comprehensive medical, dental and vision plans, 401(k), pension, life insurance, parental benefits, adoption assistance, paid time off program with paid holidays plus 16 paid volunteer hours, and various wellness programs. Additionally, our career path planning and continuing education assists employees with their professional goals.

For more details on our outstanding benefits, please visit our benefits page on

Relocation assistance is not available for this position.

USAA is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.