
Sr Business Information Security Officer
- GLBA
- Risk Management
- Regulatory Compliance
- Incident Response
- ISO 27001
- SOC2
- CISSP
- CISM
- CRISC
- CISA
- SIEM
- AI
- Health insurance
- Pension
The Sr Business Information Security Officer is Lennar Financial Services' seniorinformation security and privacy risk leader, ensuring LFS's security program remainslegally sound, defensible, and operationally effective across mortgage operationsnationwide. Serving as the primary liaison between Legal, Compliance, the CISO, IT, andthe business, this role translates regulatory, contractual, and litigation risk into practical,board-ready security controls. Partnering closely with LFS and enterprise securityleadership, the VP owns the Written Information Security Program, leads regulatory andaudit engagements, and delivers executive and board-level risk reporting. The role builds
trusted, cross-functional partnerships while holding LFS accountable to Lennar'sstandards of quality, value, and integrity.
Your Responsibilities on the Team
•Own and continuously mature the LFS Written Information Security Program(WISP), supporting policies, and control framework, ensuring legal sufficiencyand regulatory alignment.
•Define LFS-specific security standards and control baselines across origination,servicing, capital markets, and corporate functions in alignment with the enterprisesecurity strategy.
•Lead the annual LFS security program review, including risk assessment and controlgap analysis, and remediation roadmap, presenting findings to senior LFS andEnterprise leadership.
•Drive preparation and delivery of board and executive-level security riskmaterials, translating technical and regulatory complexity into clear, action-oriented narratives.
•Serve as the business and legal security subject matter expert in regulatoryexams, audits, and investor reviews, owning response materials and corrective actionsaction plans.
•Interpret and operationalize GLBA, FFIEC, state privacy and cybersecurity laws,and investor security requirements across all LFS operations, partnering withLegal on litigation and enforcement exposure.
•Own the LFS information security risk register, providing independent challengeto security design decisions and escalating material risks through appropriategovernance channels.
•Lead security incident governance, coordinating with the CISO, IT, and Legal oninvestigation, notification, and disclosure, and maintaining examination-readydocumentation.•Partner with Legal and Procurement to steer third-party security riskmanagement, defining vendor review standards, and resolving unacceptable riskthrough governance channels.
•Champion team development and security awareness across LFS, providingleadership and mentorship to security risk Associates and driving required training completion.•Contribute to enterprise security budget planning as the LFS subject matter lead,managing LFS-specific security spend and vendor relationships in coordinationwith enterprise leadership.
Your Toolbox
•Bachelor's degree in Information Security, Cybersecurity, Information Systems,Computer Science, or Business Administration required; advanced degree (MBA,MS in Cybersecurity or Risk Management) preferred.
•15+ years of progressive experience in information security, IT risk, regulatorycompliance, or audit, including at least 5 years in a BISO or senior, business-Facing a security leadership role.
•Financial services or mortgage industry experience required; non-depositoryMortgage lenders experience a significant differentiator.
•Proven track record leading security programs through regulatory examinations,investor audits, and incident response, including board-level reporting.
•Deep knowledge of GLBA Safeguards Rule, FFIEC guidance, state privacy andcybersecurity laws, and investor security requirements (FNMA, FHLMC, GinnieMae).
•Working fluency in NIST CSF/800-53, ISO 27001/27002, SOC 2, and FAIRquantitative risk analysis frameworks.
•Demonstrated ability to quantify cyber risk in financial terms and communicate itclearly to executives, Board members, and Legal leadership.
•Strong written and oral communication skills, with experience producing board-quality materials and executive risk briefings.
•CISSP, CISM, or CRISC certification required (at least two); CISA, CGRC, orISO 27001 Lead Auditor preferred.
•Working knowledge of GRC platforms, SIEM tools, identity and accessmanagement, and third-party risk management systems.
•Discretion and sound judgment in handling sensitive consumer financial data andconfidential regulatory matters.
Â
This description outlines the basic responsibilities and requirements for the position noted. This is not a comprehensive listing of all job duties of the Associates. Duties, responsibilities and activities may change at any time with or without notice.
During the course of your employment, you may be required to use, download, or access certain Company-approved tools, programs, applications, or systems. These resources may include, but are not limited to, applications designed for customer engagement, operational efficiency, data analysis, Artificial Intelligence (AI) tools, and other business functions.Â
Lennar is an equal opportunity employer and complies with all applicable federal, state, and local fair employment practices laws.
Life at Lennar
At Lennar, we are committed to fostering a supportive and enriching environment for our Associates, offering a comprehensive array of benefits designed to enhance their well-being and professional growth. Our Associates have access to robust health insurance plans, including Medical, Dental, and Vision coverage, ensuring their health needs are well taken care of. Our 401(k) Retirement Plan, complete with a $1 for $1 Company Match up to 5%, helps secure their financial future, while Paid Parental Leave and an Associate Assistance Plan provide essential support during life's critical moments. To further support our Associates, we provide an Education Assistance Program and up to $30,000 in Adoption Assistance, underscoring our commitment to their diverse needs and aspirations. From the moment of hire, they can enjoy up to three weeks of vacation annually, alongside generous Holiday, Sick Leave, and Personal Day policies. Additionally, we offer a New Hire Referral Bonus Program, significant Home Purchase Discounts, and unique opportunities such as the Everyone’s Included Day. At Lennar, we believe in investing in our Associates, empowering them to thrive both personally and professionally. Lennar Associates will have access to these benefits as outlined by Lennar’s policies and applicable plan terms. VisitLennartotalrewards.com to view our suite of benefits.
Join the fun and follow us on social media to see what's happening at our company, and don't forget to connect with us on Lennar: Overview | LinkedIn<https://www.linkedin.com/company/lennar/> for the latest job opportunities.
Lennar is an equal opportunity employer and complies with all applicable federal, state, and local fair employment practices laws.
Sr Business Information Security Officer · Lennar