pra

AVP - Information Security - Americas

Apply Now

At a Glance

Location
Norfolk, Virginia, United States
Employment
Full time
Experience
12+ years
Posted
2026-06-26

Key Requirements

Required Skills

AWSPythonREST APISQL

Certifications

  • CISM
  • CISSP

Domain Knowledge

  • Automation
  • Engineering
  • Finance
  • Healthcare

Requirements

Minimum of 12 years of progressive experience in information security, with significant hands-on technical depth across both architecture and engineering functions

Minimum of 5 years in a senior leadership role with direct management of security architects, engineers, or equivalent technical practitioners

Minimum of 5 years operating in complex, regulated enterprise environments (financial services, healthcare, or equivalent)

Minimum of 2 years of direct, hands-on experience implementing AI or ML capabilities within a security operations or engineering context

Working knowledge of LLM-based enrichment, ML-based anomaly detection, or AI-assisted investigation workflows

Understanding of AI-related security risks: hallucination, bias, data leakage, and model governance  and how to operationalize mitigations

Responsibilities

Serve as the senior technical execution and delivery leader within our global Information Security organization.

Accountable for the full lifecycle of security solution design, build, and operation across a complex, regulated multinational environment encompassing both U.S.

and European operations.

Responsible for developing and maintaining PRA’s information security posture in a manner that supports and improves the business, is efficient and effective within PRA’s technology environment, and enables usability and productivity for PRA’s employees.

Direct management authority over Security Architects and Solutions Engineers and will be the primary decision-maker for security architecture standards, platform selection, tooling strategy, and engineering execution.

Working in close partnership with the CISO, IT Architecture, and Risk functions, translates enterprise security strategy into implementable, technically defensible controls that demonstrably reduce risk.