~36m ago
New

Vice President, Information Security

United StatesUnited States·Denverexecutive
OtherInformation Security
2 views0 saves0 applied

Quick Summary

Overview

PTMA is an SEC-registered investment adviser serving governments, school districts, and public agencies across treasury management, cash and liquidity management, and investment advisory services.

Technical Tools
OtherInformation Security

PTMA is an SEC-registered investment adviser serving governments, school districts, and public agencies across treasury management, cash and liquidity management, and investment advisory services. Our clients trust us with public funds and sensitive financial data, and we treat protecting that trust as a core business obligation. We are a firm of about 300 people with a technology organization spanning Information Security, Data & AI, Salesforce, and Corporate IT. The firm’s primary operational hubs are in Denver, Colorado, and Naperville, Illinois, with other offices throughout the United States. 

The VP, Information Security is PTMA's senior security executive and owns our information security program end to end. This leader sets security strategy, runs day-to-day security operations through an in-house team and managed service partners, commands incident response, and represents the program to the executive team, the board, regulators, auditors, and clients.

The role reports to the Chief Information, Data & AI Officer, with a dotted line to the General Counsel and Chief Compliance Officer and a documented right to escalate directly to the CEO and board. That structure gives security the authority to challenge technology decisions as a peer of IT, not a subordinate to it.

We are looking for a builder. Our controls, tooling, and incident response roadmap are in place and maturing. The VP will turn that foundation into a measurable, exam-ready program that scales with our growth and our expanding use of data and AI.

Responsibilities

~2 min read

Program strategy and leadership

•         Own the information security strategy, multi-year roadmap, and annual budget, aligned to PTMA's business and technology plans.

•         Run the firm's cyber risk assessment cycle, maintain the risk register, and present risk acceptance decisions to executive leadership.

•         Report program health, top risks, and incidents to the executive team and the board on a regular cadence, in business terms.

Governance, regulatory, and audit

•         Maintain the written information security program, policies, and standards, and keep them current with regulatory change.

•         Lead security readiness for SEC examinations, internal and external audits, client due diligence questionnaires, and cyber insurance renewals.

•         Own compliance of security controls with SEC Regulation S-P (including incident response and customer notification requirements), SEC Rule 204-2 recordkeeping, and PCI DSS where applicable.

•         Partner with Legal and Compliance on regulatory interpretation, breach notification decisions, and client contract security terms.

Security operations and incident response

•         Serve as incident commander for security incidents, from detection through containment, notification, and post-incident review.

•         Complete and maintain our incident response playbook library, and run tabletop exercises with technical teams and executive leadership.

•         Manage managed detection and response and other security service providers to defined service levels.

•         Own log management and SIEM retention, vulnerability management, and threat intelligence programs.

Security architecture and technology

•         Own the security technology stack across endpoint, email, identity, cloud security posture, network, and secure access service edge.

•         Set security requirements for cloud, SaaS, and data platform initiatives, including Microsoft 365, Azure, Microsoft Fabric, and Salesforce.

•         Define security and privacy controls for AI adoption in partnership with the Data & AI team and the firm's AI governance council.

•         Run third-party and vendor risk assessments for technology providers.

Team and culture

•         Lead, develop, and grow the information security team, with clear career paths and development plans.

•         Run security awareness training and phishing simulation programs for all employees.

•         Build working relationships across IT, Data & AI, Salesforce, Product, HR, and Compliance so that security is part of how work gets done.

In the first 12 months, the VP will:

1.       Deliver a security strategy and 3-year roadmap, approved by executive leadership, within the first 90 days.

2.       Own and present board security reporting independently, with a defined metrics set the board sees every cycle.

3.       Close all open findings from the current incident response playbook reviews and complete the remaining playbooks in the roadmap.

4.       Run at least one executive tabletop exercise and one technical incident simulation.

5.       Refresh the cyber risk assessment, with every high risk carrying an owner, a remediation plan, and a target date.

6.       Bring the firm through any SEC examination, audit, or major client due diligence request without a material security finding.

7.       Put a written development plan in place for every member of the security team.

Requirements

~1 min read

Required

•         12+ years in information security, including 5+ years leading a security program or function.

•         Security leadership experience at an SEC- or FINRA-regulated firm, such as an investment adviser, broker-dealer, asset manager, or bank.

•         Direct experience leading regulatory examinations, audits, and client security due diligence.

•         A track record of presenting security risk to boards or audit and risk committees.

•         Hands-on incident response leadership, including acting as incident commander.

•         Experience managing outsourced security services (MDR, MSSP) to service levels.

•         Working knowledge of Microsoft cloud security (Entra ID, Microsoft 365, Azure) and modern cloud and SaaS security controls.

•         Bachelor's degree in a related field, or equivalent experience.

Preferred

•         CISSP, CISM, or equivalent senior security certification.

•         Experience building a security program at a mid-sized firm of 200 to 1,000 employees.

•         Familiarity with NIST CSF, CIS Controls, and SEC Regulation S-P requirements.

•         Experience with public-sector clients and their security expectations.

•         Exposure to AI governance and the security of AI and data platforms.

Location & Eligibility

Where is the job
Denver, United States
On-site at the office
Who can apply
US

Listing Details

First seen
October 7, 2026
Last seen
October 7, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
57%
Scored at
October 7, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

Vice President, Information Security