Skip to main content
Search USAA job opportunities

InfoSec Policy Management & Compliance Head

Job ID
R0110205
Date posted
06/13/2025

Why USAA?

At USAA, our mission is to empower our members to achieve financial security through highly competitive products, exceptional service and trusted advice. We seek to be the #1 choice for the military community and their families.

Embrace a fulfilling career at USAA, where our core values – honesty, integrity, loyalty and service – define how we treat each other and our members. Be part of what truly makes us special and impactful.

The Opportunity

As a dedicated InfoSec Policy Management & Compliance Head, you will act on behalf of the Chief Information Security Officer (CISO) for one or more line of business and/or staff agency. Serves as the primary enterprise Information Security interface, including all aspects of Information Security/Cyber strategy, operations and risk management requiring a line of business and/or staff agency implementation. Accountable to focus, prioritize and drive risk management work and activities; collaborate with risk partners on information security priorities, and identify and measure enterprise Information Security controls of critical business processes, technologies and experiences with their assigned line of business and/or staff agency. Applies Information Security expertise, industry experience, analysis and innovation to design and deliver strategic engagement plans to internal clients.

We offer a flexible work environment that requires an individual to be in the office 4 days per week. This position can be based in one of the following locations: San Antonio, TX, Plano, TX, Phoenix, AZ, Colorado Springs, CO, Charlotte, NC, Chesapeake, VA or Tampa, FL. Relocation assistance is available for this position.

What you'll do:

  • As a principal steward, works with line of business and/or staff agency senior level executives as a trusted advisor to define their business problem and structure a strategic Information Security engagement plan.

  • Actively participates as an extended member of the line of business and/or staff agency senior leadership team, and accountable for understanding and chipping in to the strategic goals and embedding Information Security risk management into their culture.

  • Provides thought leadership that directly shapes the analysis, design and implementation of business performance approaches, providing tailor-made information security solutions, while working closely with senior level executives to ensure positive impact and sustainable results.

  • Serves as a trusted advisor and leads multi-functional, matrixed teams to solve highly complex and high value Information Security related business problems.

  • Owns and facilitates the feedback loop for improvement opportunities across all Information Security programs and with the line of business and/or staff agency senior level executives to include assessment and reporting of Corrective Action Plans to improve Information Security programs and initiatives.

  • Responsible for the everyday execution of one or more Information Security strategic engagements and the quality of those solutions.

  • Provides Information Security risk understanding and enables sound decision making throughout the strategy engagement to identify, prioritize and mitigate Information Security risks, including intensifying, handling and reporting control issues; follows written risk and compliance policies, standards, and procedures for business activities.

  • Guides in the implementation of the Enterprise Information Security Training Plan within their assigned line of business and/or staff agency to include verifying training participants complete required training and understand Information Security requirements.

  • Collaborates with key collaborators and line of business/staff agency leaders to create written and verbal communications to senior level executives and at times, the Board of Directors, that provide clear guidance on Information Security strategic timeline, owner’s required investments, risk mitigation and expected results.

  • Proactively communicates high quality updates to senior level executives and other key collaborators.

  • Responsible for developing more junior team members assigned to support Information Security strategy engagements.

  • Attends and actively participates in Information Security forums and Risk Committees when necessary.

  • Ensures risks associated with business activities are effectively identified, measured, monitored, and controlled in accordance with risk and compliance policies and procedures.

What you have:

  • Bachelor’s degree in Information Security, Information Technology, Computer Science, Business Administration, Information Systems/Management or related field; OR 4 years of related experience (in addition to the minimum years of experience required) may be substituted in lieu of degree.

  • 10 years of related experience in Information Security, Cybersecurity and/or Information Technology in a large organization, major consulting firm or US military.

  • 6 years of experience leading highly complex projects/initiatives in Information Security, Cybersecurity and/or Information Technology with accountability for ensuring compliance with federal/state/regulatory information security and risk management policies, standards, and guidelines.

  • 4 years of experience providing advisory services to a line of business and/or staff agency on risk issues related to Information Security and recommending actions in support of a Bank’s broader risk management and compliance programs.

  • Demonstrated strategy development and thought leadership within Information Security and/or Cybersecurity.

  • Groundbreaking knowledge and expertise in theories, techniques and/or technologies within Information Security and/or Cybersecurity and application in a financial services and/or business operations environment.

  • Mastery of Information Security and/or Cybersecurity consulting skills to include gathering and synthesizing business requirements, and communicating and/or facilitating constructive opportunities to a variety of audience levels.

  • Demonstrated experience in and understanding of multiple information security domains (e.g. cyber regulation; policy & standards; network security; application security; identity & access management; security risk identification and management; supply chain security; cloud security; cryptography; data security, etc.).

  • Demonstrated experience in guiding, and influencing sound business, risk and security remediation strategies aligned with core business objectives and risk appetite without direct authority.

  • Exceptional relationship management building skills with the ability to cultivate and maintain collaborative partnerships across all levels of an organization, to include C-suite and Board of Directors.

What sets you apart:

  • 10+ years of hands-on experience leading teams - developing and handling InfoSec policies, standards, and other program documents e.g. WISP to align with Industry standards, as well as governance of approvals and exceptions.

  • Experience in building and handling a reference library of requirements driving the InfoSec program, including reference to standards, regulations, control.

  • Experience in conducting regulatory assessment (e.g. GLBA, NYDFS, HIPAA, DORA etc.) and conducting InfoSec program maturity assessments using industry standard benchmarking frameworks e.g. FFIEC, CRI by examining applicable InfoSec control design and operating effectiveness.

  • Experience building strong working partnerships with IT teams, 2nd and 3rd Line Of Defense teams.

  • Experience with other InfoSec governance risk and compliance functions, and Operational functions (e.g. Access Management, Data Protection, Cyber Operations etc.) is a strong plus.

  • Strong people and function leadership, and superb communication and presentation skills

Compensation range: The salary range for this position is: $189,370.00 - $361,950.00.

USAA does not provide visa sponsorship for this role. Please do not apply for this role if at any time (now or in the future) you will need immigration support (i.e., H-1B, TN, STEM OPT Training Plans, etc.).

Compensation: USAA has an effective process for assessing market data and establishing ranges to ensure we remain competitive. You are paid within the salary range based on your experience and market data of the position. The actual salary for this role may vary by location.

Employees may be eligible for pay incentives based on overall corporate and individual performance and at the discretion of the USAA Board of Directors.

The above description reflects the details considered necessary to describe the principal functions of the job and should not be construed as a detailed description of all the work requirements that may be performed in the job.

Benefits: At USAA our employees enjoy best-in-class benefits to support their physical, financial, and emotional wellness. These benefits include comprehensive medical, dental and vision plans, 401(k), pension, life insurance, parental benefits, adoption assistance, paid time off program with paid holidays plus 16 paid volunteer hours, and various wellness programs. Additionally, our career path planning and continuing education assists employees with their professional goals.

For more details on our outstanding benefits, visit our benefits page on USAAjobs.com.

Applications for this position are accepted on an ongoing basis, this posting will remain open until the position is filled. Thus, interested candidates are encouraged to apply the same day they view this posting.

USAA is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Apply