HMA Group Holdings, LLC is a privately held insurance brokerage that has been operating since 1932, with roots in the Des Moines metro and presence across multiple states. The firm's structure as an independent, employee-owned company is central to how it works - no external shareholders dictating strategy, which translates to fewer layers between decisions and execution.
For security professionals, the relevant context here is risk: insurance brokerages sit at the intersection of sensitive client data, financial transactions, and regulatory obligations spanning multiple jurisdictions. The threat surface includes PII exposure, claims data exfiltration, and supply-chain risk from carrier and third-party integrations. How HMA's internal security posture addresses these vectors - endpoint protection, access control architecture, incident response readiness, compliance frameworks - is where the technical work lives.
The company emphasizes a culture of continuous learning through internal programs like the Brainery and DiscoverYou, and employee ownership means operational decisions aren't siloed. That structure can matter for security teams: fewer bureaucratic constraints theoretically allow faster patching cycles, more direct access to leadership for risk communication, and room to build tooling without navigating layers of approval. Whether the reality matches the structure is the question worth asking in any interview.






