Lead, Information Security Library & Standards
Prudential Financial
- Location
- Newark, NJ, USA
- Work model
- On-Site
- Level
- Senior
- Posted
- Aug 13, 2026
About this role
Job Classification: Technology - Information Security Your Team Are you interested in building capabilities that make Information Security easier to understand, adopt, and execute? Prudential's Global Technology & Operations organization is strengthening Information Security governance to improve visibility into security risk, policy adoption, and program execution across the enterprise. As the Lead, Information Security Library & Standards , you will help build the foundation that supports Information Security governance across Prudential. This is a unique opportunity to help build and shape a growing Information Security Governance capability, with visibility across senior leadership and the ability to influence how security, risk, and governance are executed across the enterprise. Reporting to the Director of Information Security Governance, you'll partner closely with Risk Management and Information Security leaders to establish a scalable control library, mature security standards, and create the governance processes needed to support a consistent, practical, and audit-ready security program. This role is based in our office in Newark, NJ. Our organization follows a hybrid work structure where employees can work remotely and from the office, as needed, based on demands of specific tasks or personal work preferences. This position is hybrid and requires your on-site presence on a reoccurring weekly basis at least 3 days per week. Here is What You Can Expect on a Typical Day Build & Govern the Information Security Control Library Lead the development, enhancement, and ongoing governance of Prudential's Information Security control library, ensuring consistency, traceability, and alignment with enterprise risk and compliance objectives . Define and maintain control taxonomy, ownership models, framework mappings, evidence requirements, control narratives, and governance standards. Establish traceability across security standards, controls, regulatory requirements, risks, testing activities, evidence repositories, and reporting processes. Partner with Information Security domain leaders across I dentity & Access Management (IAM), Attack Surface Management (ASM), Cyber Defense & Response (CDR), cloud security, data protection, vulnerability management, and other security control functions to ensure controls accurately reflect current risks, technologies, and operational requirements. Drive Standards Management, Governance & Regulatory Alignment Coordinate the lifecycle management of Information Security standards, including creation, review, approval, publication, maintenance, and retirement. Design and implement governance processes, operating models, quality controls, decision frameworks, and review routines that keep standards and controls current, consistent, and audit-ready . Align standards and controls with leading frameworks and regulatory requirements, including NIST, ISO 27001, FFIEC, NYDFS, SOC, and related security and assurance standards. Support audits, compliance reviews, risk assessments, and regulatory examinations through clear control mappings, standards documentation, evidence requirements, and governance reporting. Drive continuous improvement of governance processes, workflows, and control management practices to improve efficiency, transparency, and usability across the organization. Enable Adoption, Security Alignment & Enterprise Partnership Partner with Information Security, Risk Management, Compliance, Technology, Legal, Internal Audit, and business stakeholders to translate complex security requirements into practical and actionable guidance. Work closely with Enablement and awareness teams to support adoption of security standards and controls through communications, implementation guidance, FAQs, and training content. Establish governance of playbooks, templates, quality standards, and documentation practices that