AVP-Technology

Principal Financial GroupDes Moines, IA
7d$179,000 - $243,000Hybrid

About The Position

We’re looking for an AVP of Technology to join our Information Security team. Reporting to the CISO, you will own and lead security engineering outcomes across cloud security, AI‑enabled automation, IAM/CIAM, and enterprise data protection. In this role, you will set the strategic vision and drive execution through your teams for how the organization designs, builds, and operates secure cloud and identity‑centric platforms—reducing risk through engineered, automated controls rather than manual processes. You will build and mature scalable security control planes across cloud, identity, and data—leveraging automation and AI to improve speed, consistency, and resilience—while enabling engineering teams to move from current‑state implementations to future‑state, secure‑by‑design architectures. Your Day Could Look Like: Cloud Security Engineering & Architecture Cloud Security Engineering owns the strategy and security engineering outcomes for enterprise cloud security across our cloud infrastructures, including identity‑centric access controls, secure cloud architectures, workload protection, and automated policy enforcement. Delivers measurable improvements in cloud risk reduction, configuration consistency, and secure‑by‑default adoption through engineered and automated controls. Automation Strategy & Program Leadership Defines and drives the enterprise security automation and AI vision, aligning roadmap and investments to modernize cloud security, IAM/CIAM, and data protection. Accountable for reducing manual security effort and increasing control coverage and reliability through automation. Program, Portfolio & Budget Stewardship Owns a multi‑year investment roadmap and annual operating plan for security engineering (cloud security, AI/automation, IAM/CIAM, data protection). Establishes business cases and success metrics; manages budget‑to‑value; and leads prioritization trade‑offs (manual controls vs. automation, build vs. buy, tactical remediation vs. strategic platform uplift) aligned to enterprise risk appetite. IAM / CIAM Engineering Provides strategic oversight of enterprise IAM capabilities, including IGA, CIAM, PAM, authentication modernization, and least‑privilege enforcement across cloud and on‑prem environments, strengthening identity‑centric cloud security patterns. Data Protection & Security Engineering Leads strategy and engineering execution for enterprise data protection across cloud, SaaS, and on‑prem environments, delivering improved data visibility, policy enforcement, and reduction of high‑risk exposures through automated controls

Requirements

  • Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field, with 15+ years of IT experience focused on security engineering and/or operations, including deep exposure to IAM/CIAM and data protection.
  • 6+ years of people leadership and 5+ years leading enterprise security initiatives, including building and leading engineering teams that deliver enterprise‑scale platforms.
  • Strong enterprise leadership with the ability to lead through influence, partnership, and formal authority, communicate across technical and non‑technical stakeholders, and drive alignment and adoption for complex security programs
  • Strong understanding of modern cloud security engineering practices across AWS/Azure, including identity architecture, zero trust principles, and data protection controls.
  • Hands‑on or strategic experience with IAM/CIAM technologies—including IGA, PAM, MFA, SSO, and directory services—and with data security platforms such as encryption, DLP, key management, and DSPM.
  • Demonstrated ability to design and govern automation patterns and orchestration workflows, and to guide teams through implementation.
  • Maintains strong technical fluency to lead architectural reviews and coach engineers—not as a day‑to‑day implementer, but as an applied technical leader.

Nice To Haves

  • Advanced security certifications (CISSP, CISM, SANS) are a plus, along with cloud security, IAM, or DevSecOps credentials (CCSP, AWS/Azure, CIAM, PAM certifications).
  • Strong familiarity with applying AI/ML in cybersecurity, including AI-driven detection tools (UEBA, anomaly detection, AI-based threat intelligence), and experience integrating identity analytics and data security monitoring into automated response workflows.
  • Experience implementing zero trust architecture principles across identity, device, network, and data layers.
  • Demonstrated success modernizing IAM and data protection programs in complex, hybrid enterprise environments.
  • Experience working in a financial institution.

Responsibilities

  • Cloud Security Engineering & Architecture
  • Automation Strategy & Program Leadership
  • Program, Portfolio & Budget Stewardship
  • IAM / CIAM Engineering
  • Data Protection & Security Engineering

Benefits

  • Flexible Time Off (FTO) is provided to salaried (exempt) employees and provides the opportunity to take time away from the office with pay for vacation, personal or short-term illness. Employees don’t accrue a bank of time off under FTO and there is no set number of days provided.
  • Pension Eligible
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service