Position Description
Title: Information Security Manager
Department: Risk Management
Reports to: FVP, Chief Risk Officer
Supervises: None
Classification: Exempt
Date Prepared: April 2025
Summary / Objective
The Information Security Officer is responsible for developing, implementing, and maintaining the organization’s information security program in compliance with the FFIEC IT Examination Handbook and other regulatory requirements. The ISO ensures the protection of sensitive data, manages cyber risks, and works closely with management, IT, risk, and compliance teams to enforce security policies, controls, and best practices.
Experience & Education Requirements:
- Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or a related field or equivalent experience.
- Industry-recognized certifications such as CISSP, CISM, CISA, CRISC, or GIAC preferred
- 5+ years of experience in information security, cybersecurity, or IT risk management, preferably within a financial institution.
- Strong understanding of FFIEC guidelines, Information Security frameworks, PCI-DSS, GLBA, and banking regulations.
- Experience with security architecture, incident response, SIEM tools, and identity & access management (IAM).
- Familiarity with cloud security, digital banking risks, and payment systems security.
Job Requirements:
- Strong risk management skills and mindset.
- Extensive knowledge of cyber security concepts, principles, methods, and products.
- General knowledge of financial and banking technology including core banking software, loan origination platforms, online and mobile banking platforms, general ledger software, ATM technology, etc., preferred.
- Proficiency in interpreting and analyzing impact of federal and state regulations, with proficiency in banking regulations required, preferred.
- Experience performing compliance reviews/audits for a financial institution, preferred.
- Experience in developing and delivering Information/Cyber Security or other technical training.
- Ability to communicate complex technical topics to non-technical audience.
- Ability to keep pace with the rapidly evolving threat landscape.
- Proficient in Microsoft Office Suite products.