Fortitude group holdings llc

AVP, Cybersecurity Compliance

Nashville Full Time

Fortitude Reinsurance Company Ltd. (Fortitude Re) is one of the world’s leading providers of legacy reinsurance solutions. They work with the world’s leading insurance companies to help them execute comprehensive, transformational solutions for legacy Life & Annuity and P&C lines. Fortitude Re manages a general account of approximately $111 billion across life, annuity, and property & casualty insurance products. The company takes a long-term view on growth and is proud to be backed by a consortium of sophisticated institutional investors led by The Carlyle Group and T&D Insurance Group. Incorporated under the laws of Bermuda on January 1, 2017, Fortitude Re’s roots in the insurance industry and the experience of their leadership go back many decades. Fortitude Re’s leadership team has an average industry tenure of over 20 years, and an impressive track record of successfully managing the most complex legacy liabilities. Their deep insurance experience and proprietary risk modeling capabilities allow them to structure bespoke transactions that benefit both insurance companies and their policyholders. Fortitude Re continues to strengthen its ability to pursue further growth and provide innovative solutions for the global insurance industry.   Click here for more information about Fortitude Re.

The AVP, Cybersecurity Compliance will play a key role in ensuring the company complies with all regulatory, legal, and industry-leading cybersecurity and privacy standards. This role is responsible for developing and maintaining a robust cybersecurity and privacy compliance program, ensuring alignment with relevant regulations (BMA Cyber, NYDFS, PIPA etc.) and industry frameworks (NIST CSF 2.0, NIST 800-53, NIST Privacy). The AVP will lead cybersecurity risk assessments, privacy impact assessments, and compliance monitoring efforts.

This role will be based in our Nashville, TN office on a hybrid basis.

What You Will Do:

  • Cyber and Privacy Regulatory Compliance:
    • Ensure compliance with relevant cybersecurity and privacy regulations, including but not limited to Bermuda Monetary Authority (BMA) Cyber, New York Department of Financial Services (NYDFS) Cybersecurity Regulation, and Personal Information Protection Act (PIPA).
    • Stay updated on regulatory changes, assess their impact on the organization, and adapt compliance programs accordingly.
    • Serve as the point of contact for regulatory inquiries and work with the compliance team to ensure timely submissions of required filings and reports.
  • Framework and Standards Alignment:
    • Lead implementation and reinforcements of cybersecurity and privacy programs in alignment with industry-leading frameworks such as NIST Cybersecurity Framework (CSF) 2.0, NIST 800-53, and NIST Privacy.
    • Ensure internal controls, policies, and procedures are aligned with these frameworks and undergo regular review and updates.
  • Risk Assessment and Management:
    • Lead comprehensive cybersecurity and privacy risk assessments, identifying vulnerabilities, assessing their potential business impact, and ensuring appropriate mitigations are in place.
    • Perform privacy impact assessments and data protection assessments to ensure compliance with privacy regulations.
    • Work closely with IT, Legal & Compliance, Risk Management, and other stakeholders to ensure that risks are understood and mitigated in accordance with regulatory and business requirements.
    • Develop and maintain a risk and control matrix to document identified risks and corresponding controls.
  • Audit and Monitoring:
    • Oversee and coordinate both internal and external cybersecurity audits, ensuring that all compliance issues are addressed effectively and promptly.
    • Develop continuous monitoring mechanisms to ensure ongoing compliance with regulatory requirements and frameworks and provide regular reports to senior leadership on compliance status.
    • Assist auditors with necessary documentation during periodic assessments, including SOC 2 reviews.
  • Training and Awareness:
    • Maintain and facilitate company-wide cybersecurity and privacy compliance training programs to ensure all employees understand their roles and responsibilities regarding regulatory compliance and data protection.
  • Incident Management:
    • Assist in the periodic assessment and testing of incident response plans, ensuring compliance with regulatory breach reporting requirements.
    • Participate in post-incident investigations to assess compliance gaps and recommend corrective actions.

What You Will Have:

  • Bachelor's degree in Cybersecurity, Information Technology, or a related field.
  • 7+ years of experience in cybersecurity compliance, governance, risk management, or audit roles, with a focus on cyber and privacy regulations.
  • Strong understanding of regulatory frameworks such as GDPR, BMA Cyber, NYDFS Cybersecurity, and PIPA.
  • Expertise in conducting cybersecurity and privacy risk assessments and developing mitigation strategies.
  • In-depth knowledge of NIST frameworks, including CSF 2.0, 800-53, and the NIST Privacy Framework.
  • Relevant certifications (e.g., CISSP, CISM, CIPP, CRISC) preferred.
  • Strong communication, collaboration, and leadership skills.

#LI-Hybrid

The base salary range for this role is listed below and will be commensurate with candidate experience. Pay ranges for candidates may differ based on the cost of labor in that location. In addition to base salary, all employees are eligible for an annual bonus based on company and individual performance as well as a generous benefits package.  

Base Salary Range
$145,000$165,000 USD

At Fortitude Re, our strength has always come from our people. Our success is deeply rooted in our ability to embrace the unique attributes, perspectives and experiences of every individual within our company.  Fostering a culture of inclusion and belonging where everyone—regardless of background, race, religion, sexual orientation or gender identity—feels valued and respected is a foundation of our culture.

We are committed to being an equal opportunity employer and evaluate qualified applicants without regard to race, color, religion, sex, pregnancy (including childbirth, lactation and related medical conditions), national origin, age, physical and mental disability, marital status, sexual orientation, gender identity, gender expression, genetic information (including characteristics and testing), military and veteran status, diversity of thought and any other characteristic protected by applicable law.

To all recruitment agencies:  Unless you have been requested to work on this position, or other positions with Fortitude Re, please do not forward any resumes to Fortitude Re employees.  Fortitude Re is not responsible for any fees related to unsolicited resumes.

Check us out on YouTube:  About Fortitude Re (youtube.com)

By submitting your application, you agree that Fortitude Re may collect your personal data for recruiting purposes.