Chief Information Security Officer (CISO)
Position Summary : The Chief Information Security Officer (CISO) is a senior-level executive responsible for developing, implementing, and overseeing Milliman's global information security program. As a member of Global Corporate Services (GCS) reporting directly to the Chief Information Officer (CIO) and working closely with the CEO, Board of Directors, and Equity Principals, the CISO ensures the confidentiality, integrity, and availability of Milliman's information assets, technology infrastructure, and data across all practices and geographies. This role provides strategic leadership, vision, and governance for all aspects of information security, aligning security initiatives with business objectives and regulatory requirements.
Responsibilities :
Strategic Leadership & Governance :
- Drive the information security function across Milliman, ensuring alignment with organizational goals.
- Establish and implement a global information security vision and strategy by collaborating with the Board, senior leaders, and Equity Principals.
- Design and deliver the security roadmap, including staffing and budget plans, and manage the approved corporate information security budget.
- Serve as an expert advisor to the Board and senior leadership on IT security matters.
- Facilitate organization-wide security enhancements that integrate business objectives with IT infrastructure, physical infrastructure, and human resources.
- Act as the primary change agent facilitating information security improvements in security culture, business relationships, and product / service design.
- Chair the Security Technology Steering Group (STSG).
Risk Management & Compliance :
Collaborate with senior leadership on IT-related risk management to identify, assess, and address risks.Oversee the development, implementation, and maintenance of global information security policies, standards, guidelines, and procedures.Ensure compliance with relevant laws, regulations, and industry frameworks (e.g., ISO 27001, HIPAA, HITRUST, SOC 2).Partner with the Legal Department to maintain a collaborative approach to information security and privacy.Manage third-party / vendor security risk programs and ensure alignment with corporate policies.Serve as a voting member of the Enterprise Risk Management Committee and Technology Operations Committee and act as a key advisor to senior leadership on IT security matters.Incident Response & Operational Oversight :
Oversee emergency procedures and incident response protocols, serving as the control point during significant security incidents.Direct teams to detect, report, contain, and mitigate incidents impacting data and infrastructure security.Oversee periodic security reviews of all business units and present findings to the Enterprise Risk Committee and Board.Partner with the Legal team in response to privacy incidents and significant events.Collaborate with IT teams to develop, evaluate, and improve network disaster recovery plans.Maintain relationships with law enforcement and relevant government agencies in support of the information security program.Program Development & Stakeholder Engagement :
Develop and implement enterprise-wide security awareness training.Build and report on metrics and KPIs to measure program effectiveness.Recommend security enhancements and purchases consistent with evolving threats and strategic objectives.Stay current on technological advances and identify opportunities for adoption within Milliman.Provide coordination, communication, and dissemination of best practices across the organization.Support Equity Principals and their practi