Information Security Officer
Irvine, CA 
Share
Posted 13 days ago
Job Description
Description

The Information Security Officer is responsible for oversight of the Information Security Department. This position is also responsible for the execution of the Bank's Information Security, Physical Security, Data Governance, and Business Continuity Programs.

RESPONSIBILITIES

  • Develop, implement and monitor a strategic, comprehensive enterprise information security program to ensure the integrity, confidentiality and availability of data.
  • Document and maintain a risk assessment framework covering information and physical security, data governance and business continuity. Develop and maintain information security policies, standards and guidelines. Oversee the approval, training, and dissemination of security policies, standards and guidelines.
  • Develop and oversee effective business continuity and disaster recovery policies and standards to align with enterprise business continuity management program goals. Coordinate the development of implementation plans and procedures to ensure systems are recovered in the event of a
  • security event.
  • Monitor the external threat environment for emerging threats, and advise relevant stakeholders on the appropriate courses of action. Manage security incidents and events to protect corporate IT assets, including intellectual property, regulated data and the company's reputation.
  • Partner with the Enterprise Risk Management to define standards and processes and provide subject-matter expertise to oversee vendor information security risk and inform periodic audits of third-party service providers' information security and business continuity controls. Provide regular and consistent reporting on the current status of the information security program to enterprise risk teams, senior business leaders and the board of directors as part of the strategic enterprise risk management program
  • Provide strategic risk guidance for IT projects, including the evaluation and recommendation of technical controls. Define and facilitate the information security risk assessment process, including the reporting and oversight of treatment efforts to address findings. Develop and manage information security budgets, and monitor them for variances.

QUALIFICATIONS

  • Must have 10+ years' experience in banking regulatory compliance or similar work experience in compliance or risk management.
  • Must have extensive knowledge of privacy and data protection laws, regulations and best practices, including GLBA; GRC tools and implementation; data breach handling and cross-border data transfer requirements and industry standards/frameworks (NIST, ISO27k, COBIT 5, FFIEC).
  • Strong presentation and written communication skills and the ability to analyze and make effective, business-centric recommendations to business leaders and senior management.
  • Experienced developing a comprehensive security program, including risk assessment framework. Must have security certification CISM, CISSP, or equivalent.

A reasonable, good faith estimate of the minimum and maximum base salary or pay for this position is $131,221.20 to $196,831.80. Actual compensation will vary based on various factors including but not limited to location, experience, and performance. A discretionary bonus and/or business line incentive may be provided, in addition to a medical and other benefits, dependent on the position. For more information regarding our benefits, please visit

#LI-Onsite



Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities

The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor's legal duty to furnish information. 41 CFR 60-1.35(c)

 

Job Summary
Start Date
As soon as possible
Employment Term and Type
Regular, Full Time
Required Experience
10+ years
Email this Job to Yourself or a Friend
Indicates required fields