JOB SUMMARY
The Director of Information Technology will have complete responsibility for the day-to-day management of the engagement and effective managing all the organization’s technology infrastructure and assets. This individual ensures the safety and soundness of the global network and its nodes. This individual participates in technical research and development to enable continuing innovation within the infrastructure. This individual ensures that system hardware, operating systems, software systems, and related procedures adhere to organizational values, enabling staff, volunteers, and vendors. This individual will assist project teams with technical issues in the project management lifecycle. These activities include the definition of needs, benefits, and technical strategy; research & development within the project life cycle; technical analysis and design; and support of operations staff in executing, testing and rolling-out the solutions. Participation on projects is focused on smoothing the transition of projects from development staff to production staff by performing operations activities within the project life cycle.
ESSENTIAL DUTIES AND RESPONSIBILITIES
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Technology Team
- Maintains staff by recruiting, selecting, orienting, and training employees; maintaining a safe and secure work environment; developing personal growth opportunities.
- Schedules, organizes, and assigns projects to members of the IT team.
- Accomplishes information technology staff results by communicating job expectations; planning, monitoring, and appraising job results; coaching, counseling, and disciplining employees; initiating, coordinating, and enforcing systems, policies, and procedures.
- Maintains quality service by establishing and enforcing bank standards.
- Assists all Systems Administrators as an escalation point in all aspects of their job duties.
- Conducts performance evaluations that are timely and constructive.
- Handles discipline and termination of employees as needed and in accordance with company policy.
- Oversees all technology operations and evaluate them according to established goals.
- Maintains professional and technical knowledge by attending educational workshops; reviewing professional publications; establishing personal networks; benchmarking state-of-the-art practices; participating in professional societies.
- Heads the IT Steering Committee.
Technical Support
- Administers and/or confirms firewall configuration approval and enforcement of firewall policies with IT staff and/or vendors.
- Administers and/or confirms VoIP routing and VLAN changes with the IT staff and/or vendors.
- Oversees necessary changes to maintain or increase levels of cybersecurity preparedness.
- Oversees the efforts of ongoing monitoring to ensure South Atlantic Bank remains agile in addressing areas of cybersecurity risk.
- Supervises and implements changes authorized by the Technology Steering Committee.
- With System Administrators, implements information security strategies and objectives to monitor and address current and emerging risks, and if necessary, implement mitigations.
- With System Administrators, participates with other financial institutions in a collaborative effort to monitor, share, and discuss emerging security threats.
- With the Information Security Officer, develops and oversees the formal process for obtaining, analyzing, and responding to data on current and emerging threats and vulnerabilities through a repeatable threat intelligence and collaboration program that may include collaborative efforts with other FIs.
Policies and Procedures
- Devises, establishes, and enforces IT policies and systems to support the implementation of strategies.
- Ensures that financial institution end users receive training at least annually on practices for safeguarding non-public information, personal data privacy requirements, data protection by design, Internet and email use guidelines, incident response, business continuity management, cybersecurity, and specific components of the IT systems, as part of the financial institution’s overall Information Security Program.
- Ensures that other individuals of the Senior Management team and the Board of Directors have trained on at least an annual basis in regard to information security awareness and cybersecurity.
- Reviews violations of security procedures; provides training to ensure violations do not recur.
- Updates and reviews the Comprehensive Asset Based Risk Assessment and supporting methodology periodically, but at least annually.
- Verifies that data recovery tests occur as required in the Data Recovery Testing Policy. These results are reviewed, and the policy will be updated to reflect necessary changes.
- With the Information Security Officer, develops and oversees the formal process for obtaining, analyzing, and responding to data on current and emerging threats and vulnerabilities through a repeatable threat intelligence and collaboration program that may include collaborative efforts with other FIs.
- With the Information Security Officer, determines curriculum and ensures annual training for end users and the Board of Directors on information security standards, cybersecurity, incident response, business continuity management, and current best practices. Periodic updates will be provided based on new risks, threats, and acceptable security controls.
Business Continuity and Disaster Recovery
- Preserve assets by implementing disaster recovery and back-up procedures and information security and control structures. Provide IT Steering Committee, ISO and the board of directors DR test training and test results once annually.
- Ensures a formal strategy is in place to address attempted and actual security-related incidents.
- Approves changes to the data recovery test plans.
- Assists other departments in establishing appropriate disaster/business continuity tasks and timeline through Business Impact Analysis reviews.
- Train and test on Incident Response policies and procedures.
- Reviews data recovery test results and recommendations and presentation of this information to the Technology Steering Committee and ISO.
Reporting
- Administers and periodically reviews IT systems, Internet-related, software purchasing, inventory, and control systems to ensure that policies are being followed.
- Provides and maintains network topology for the entire organization and report changes to the ITSC and board of directors.
- Provides ISO a monthly report on user access and rights for the core software and Active Directory.
- Provides annual penetration tests, and vulnerability assessment from external audit firm and present findings to the ISO, ITSC and board of directors.
- Works with audit consulting firms to assist in the IT audit for the whole organization.
- Provides management responses to IT audit findings and present to the ISO, ITSC and board of directors.
- Accomplishes financial objectives by forecasting requirements; preparing an annual budget; scheduling expenditures; analyzing variances; initiating corrective action.
- Manages the process of responding to audit/review/test exceptions.
- Reviews access for individual and group level of authority on the network, databases and applications, core processing systems, applications, and the internet on at least an annual basis to ensure that only authorized changes have been made.
- Reviews and presents exceptions of security reports with the Information Security Officer monthly or more often if security notifications require immediate attention. These reports will be presented to members of the Technology Steering Committee.
- Reviews the internal and external audit/review/test results/reports with the auditors, Network Administration, the Technology Steering Committee, and ISO.
- Reviews, approves, and supports plans to address risk management and mitigate weaknesses.
Strategic Planning
- Collaborates with users to discuss computer data access needs, to identify security threats and violations, and to identify and recommend needed programming or process changes.
- Maintains organization's effectiveness and efficiency by defining, delivering, and supporting strategic plans for implementing information technologies. Provide 3–5-year IT strategic plan annually to the board of directors.
- Identifies the need for upgrades, configurations or new systems and report to upper management. Identify End of Life systems and budget for them. Control budget and report on expenditure.
- Recommends information technology strategies, policies, and procedures by evaluating organization outcomes; identifying problems; evaluating trends; anticipating requirements.
- Purchases efficient and cost-effective technological equipment and software.
- Inspects the use of technological equipment and software to ensure functionality and efficiency.
- Develops a plan to periodically update the cybersecurity assessment.
- Proposes plans for network-related expansions and upgrades.
Project Management
- Ensures that adequate resources are available to complete projects.
- Verifies application results by conducting system audits of technologies implemented.
- Analyzes the business requirements of all departments to determine their technology needs.
Vendor Management
- Assists in building relationships with vendors and creating cost-efficient contracts.
- Performs due-diligence and cost analysis on all services and products.
- Assists in maintaining vendor management program and vendor risk assessment.
- Maintains risk assessment and appropriate vendor due diligence in accordance with outsourced network services.
Bank Culture
- Aligns values with the Mission, Vision, and Values of the bank.
- Maintains and encourages open and honest business relationships within the team and throughout the bank.
- Communicates in a fashion that is respectful and well understood.
- From a distance, makes a difference in the lives of our members by helping our team members make customers’ financial dreams come true.
- Is a role model for the bank’s organizational culture by creating a positive impact at every touchpoint with people.
- Collaborates with your peers and colleagues to add to the collective innovative thinking that can drive new business ideas for the bank.
- Actively participates in community events as part of the bank’s overall commitment to corporate social responsibility.
- Utilizes lean methodology to streamline work processes and realize cost and resource efficiencies.