The posting
The position is described below. If you want to apply, click the Apply button at the top or bottom of this page. You'll be required to create an account or sign in to an existing one.
If you have a disability and need assistance with the application, you can request a reasonable accommodation. Send an email to Accessibility (accommodation requests only; other inquiries won't receive a response).
Regular or Temporary:
Regular
Language Fluency: English (Required)
Work Shift:
1st Shift (United States of America)
Please review the following job description:
CRC Group is a leading, independent pure-play brokerage and underwriting specialty insurance distributor. Our culture puts people first, prioritizing long-term relationships, ethical decision-making, and continuous improvement. As a result of listening to our employees, CRC Group earned a Top Workplaces USA award three years in a row based solely on employee feedback and CRC Group is currently Great Place To Work Certified! If you want to work for a company where employees are valued and growth is encouraged, CRC Group could be the place.
The Senior Cybersecurity Operations and Defense Director provides strategic leadership for organizational information security programs, including governance, risk management, cyber defense, and protection of enterprise assets. This role ensures resilience against threats, establishes security frameworks, and oversees compliance with regulatory and industry standards while leading cross-functional teams to implement and maintain robust defense capabilities.
KEY RESPONSIBILITIES:
Following is a summary of the essential functions for this job. Other duties may be performed, both major and minor, which are not mentioned below. Specific activities may change from time to time.
- Develop and execute enterprise-wide information security strategy aligned with organizational objectives.
- Oversee governance, risk, and compliance initiatives to ensure adherence to legal, regulatory, and internal standards.
- Lead development and implementation of security policies, standards, and guidelines across the organization.
- Direct vulnerability management, incident response, and threat detection operations to safeguard assets.
- Oversee AI enablement for Cyber Operations
- Partner with executive leadership, legal, and IT teams to manage security risks and maintain business continuity.
- Drive enterprise security awareness programs and influence adoption of best practices.
- Lead, mentor, and manage senior-level security professionals and cross-functional security initiatives.
- Develop security budgets, resource plans, and ensure ROI from security investments.
EDUCATION AND EXPERIENCE
The requirements listed below are representative of the knowledge, skill and/or ability required. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.
- Bachelor’s degree in Information Technology, Cybersecurity, or a related field.
- Master’s degree in Cybersecurity, Information Assurance, or related discipline preferred.
- 12+ years of experience in information security or IT risk management roles.
- 7+ years of experience in leadership roles directing enterprise security functions.
- 3-5 years of experience in AI enablement for security operations, i.e. integration of AI security operations, automation, auto-triage; experience Security Copilot, Claude and/or ChatGPT
- Experience developing and implementing cybersecurity strategies and frameworks.
- Proven track record in incident response, security architecture, threat management, and compliance.
CERTIFICATIONS / LICENSES / REGISTRATIONS
- Certified Information Systems Security Professional (CISSP) preferred.
- Certified Information Security Manager (CISM) is desirable.
- Certified Information Systems Auditor (CISA) or equivalent risk/compliance certification preferred.
FUNCTIONAL SKILLS
- Strategic thinking and vision setting for cybersecurity programs.
- Advanced knowledge of security architecture, threat intelligence, and vulnerability management.
- Strong leadership and team development skills.
- Expertise in regulatory compliance frameworks such as NIST, ISO 27001, and SOC standards.
- Ability to influence executives and communicate complex security concepts effectively.
- Proficiency in risk management and business continuity planning.
General Description of Available Benefits for Eligible Employees of CRC Group: At CRC Group, we're committed to supporting every aspect of teammates' well-being – physical, emotional, financial, social, and professional. Our best-in-class benefits program is designed to care for the whole you, offering a wide range of coverage and support. Eligible full-time teammates enjoy access to medical, dental, vision, life, disability, and AD&D insurance; tax-advantaged savings accounts; and a 401(k) plan with company match. CRC Group also offers generous paid time off programs, including company holidays, vacation and sick days, new parent leave, and more. Eligible positions may also qualify for restricted stock units and/or a deferred compensation plan.
CRC Group supports a diverse workforce and is an Equal Opportunity Employer that does not discriminate against individuals on the basis of race, gender, color, religion, citizenship or national origin, age, sexual orientation, gender identity, disability, veteran status or other classification protected by law. CRC Group is a Drug Free Workplace.
EEO is the Law Pay Transparency Nondiscrimination Provision E-Verify



