Company Details
Berkley Cyber Risk Solutions provides first and third-party cyber coverage for emerging cyber exposures, complemented by pre and post breach services. A team of experienced professionals delivers comprehensive cyber coverage and data breach protection to commercial insureds of all sizes and industries. Our singular focus of viewing cyber as a peril allows us to constantly refine and update new coverage options for emerging risks and trends and be responsive to client specific coverage and service needs.
BerkleyShield is an innovative insurtech embedded withing Berkley Cyber Risk Solutions, focused on transforming the SME cyber insurance market through technology, data, and proactive risk management. Our platform helps organizations better understand, mitigate, and insure cyber risk while enabling brokers and partners to deliver faster, smarter cyber coverage solutions.
Responsibilities
A successful candidate will develop and oversee the cyber risk intelligence and loss control operations.
The ideal candidate will have significant experience within the field of information security controls, industry frameworks such as NIST and ISO 270001 and working with companies to implement improvements to Cyber Risk Controls. Must possess an ability to understand and collaborate closely with multiple functional groups such as underwriting leadership, field underwriting, sales/business development, enterprise risk management, actuarial, claims, operations, information technology and external customers such as Brokers and Policyholders.
The candidate will develop, implement and manage the cyber risk advisory and policyholder risk engineering services. Candidate must be capable of representing W. R. Berkley and Berkley Cyber Risk’s practice in the market, serving as subject-matter expert to agents and brokers, clients, vendors, and partners; and also participating in panels or media-related activities. Role will complement our mission of providing first and third-party cyber insurance coverage for emerging cyber exposures, complemented by pre and post-breach services delivered thru the Risk Engineering role. Providing valuable risk mitigation advice and tools will assist policyholders in avoiding cyber incidents improving our loss ratio.
Key Functions
- Assist CUO in developing and implementing cyber risk underwriting tools and guidelines for improved risk selection
- Develop and oversee Policyholder Risk Engineering services to policyholders including the establishment of services and loss control expense budget to include but not limited to:
- Policyholder On boarding and IR coordination
- Policyholder dashboard to request and receive services
- Develop and deploy self service risk mitigation tools thru Risk Management hub
- Cyber Alerts via email notification
- Virtual CISO services
- Premium credit workshops for key exposures/loss trends
- Educational training resources
- Engage with organizations outside of Berkley Cyber on topics of cyber risk to maintain centers of excellence and expert resources to support organizational objectives
- Evaluate and select best data sources and vendors for Pre Event services
- Assist BCRS Claims as technical resource on open claims
- Collaborating closely with W. R Berkley’s internal Infosec group, sharing information, resources, and capabilities to share claims trends, threat intelligence and best practices
- Provide training and coaching underwriting and operations staff as a senior resource and subject-matter expert
- Support Affiliate Manager in engaging with other operating companies on the selection, creation, and/or deployment of cyber risk mitigation tools and resources to policyholders
- Stay in tune with daily cyber risk information (new threats, CVEs, data, bulletins, mitigations, etc)
- Support Underwriting team thru the evaluation of policyholder risk controls, evaluating 3rd party Security Score assessments, participating in InfoSec client meetings, and provide pre and post policy inception risk assessments for underwriting, claims, brokers and policyholders
Qualifications
Education Requirement:
- 7+ years of experience within, insurance carrier cyber risk engineering, information security or IT Security consulting
- Bachelor’s degree preferred; experience in the field of information security.
Qualifications: Include necessary skills/experience and core competencies required
- Strong knowledge of cyber risk assessment, compliance, and data frameworks (NIST, CVE, CIS Top 20, PCI/DSS, Soc 2, ISO 27001, etc)
- CISM or CISSP designation(s)
- Strong knowledge of third party information risk management processes
- Strong knowledge of cyber risk scanning tools and technologies, both outside-in (e.g. BitSight, SecurityScorecard)
- Knowledge of SecOps (Security + Operations)
- Knowledge of insurance industry
- Knowledge of cyber insurance industry
- Knowledge of underwriting concepts, practices, and procedures
- Familiarity with key management metrics, and strategies to influence them, within commercial insurance
- Microsoft Word, Excel, Powerpoint, and Outlook
- Internet usage
- Oral and written communication skills
- Project management and project participation skills
- Negotiation skills
- Marketing skills