1

Information Security Officer Jobs (NOW HIRING)

ROLE SUMMARY The Information Security Officer is responsible for monitoring, analyzing, and maintaining the bank's technical security controls in support of City First Bank's Information Security ...

IT Security Officer I/II

Eureka, CA · On-site

$33.07 - $45.73/hr

Information Security Officer II: This is the journey-level classification in the Information Technology Security Officer series. Positions at this level are distinguished from the I-level by the ...

Chief Information Security Officer

Miami, FL · On-site

  • Medical

  • Dental

  • Vision

  • Retirement

Chief Information Security Officer (CISO) Position at GVW Group, LLC Job Title: Chief Information Security Officer (CISO) Location: Birmingham, AL or Chicago, IL Onsite, in office-based position ...

Chief Information Security Officer

Austin, TX · On-site

$115 - $188/hr

  • Medical

  • Retirement

  • PTO

Chief Information Security Officer Job Title: Director VI Agency: Health & Human Services Comm Department: CHIEF INFO SECURITY OFFICE Posting Number: 19093 Closing Date: 09/14/2026 Posting Audience:

Showing results 21-40

Information Security Officer information

See salary details

$29.5K

$94.9K

$170.5K

How much do information security officer jobs pay per year?

As of Aug 16, 2026, the average yearly pay for information security officer in the United States is $94,926.00, according to ZipRecruiter salary data. Most workers in this role earn between $49,500.00 and $127,500.00 per year, depending on experience, location, and employer.

What is the difference between Information Security Officer vs Security Analyst?

AspectInformation Security OfficerSecurity Analyst
CertificationsCISSP, CISM, CompTIA Security+CompTIA Security+, GIAC Security Essentials
Work EnvironmentOversees security policies, manages security teams, strategic planningMonitors security systems, analyzes threats, incident response
Employer & Industry UsageUsed across industries for security leadership rolesCommon in IT departments for threat detection and analysis

The main difference is that an Information Security Officer focuses on strategic security management and policy development, while a Security Analyst primarily monitors and analyzes security threats. Both roles require similar certifications and are vital in protecting organizational assets, but they differ in scope and responsibilities.

What are the key skills and qualifications needed to thrive as an information security officer, and why are they important?

To thrive as an Information Security Officer, you need strong expertise in risk management, cybersecurity frameworks, incident response, and typically a bachelor’s degree in information security or a related field. Familiarity with tools like SIEM systems, vulnerability scanners, and certifications such as CISSP or CISM are highly valued. Exceptional analytical thinking, attention to detail, and effective communication skills help you stand out in this role. These competencies are crucial for protecting organizational data, ensuring compliance, and responding swiftly to evolving cyber threats.

What is an information security officer?

An information security officer is an information technology (IT) analyst who leads a team to monitor and improve an organization’s information security. You are responsible for computer systems security, and your duties include designing and running security tests, hiring and training new team members, and making reports on your findings to other departments in the company. A career as an information security analyst requires you have some formal qualifications and experience, generally a bachelor’s degree in IT, computer science, or a related field, as well as several years of experience as a part of an IT security team. Continuing education opportunities can keep you abreast of the latest technologies, vulnerabilities, and threats, and will help set you ahead of other candidates in your job search. Useful job skills include analytical problem-solving, security risk evaluation, and knowledge of best practices for secure systems.

What are some common challenges information security officers face when implementing security policies across an organization?

Information Security Officers often encounter challenges such as gaining buy-in from various departments, ensuring staff compliance with security procedures, and keeping up with rapidly evolving cyber threats. Balancing robust security measures with business operations can also be demanding, as overly strict policies may hinder productivity. Successful officers typically address these challenges by fostering a culture of security awareness, collaborating closely with IT and management, and continuously updating policies to reflect current risks.

What cities are hiring for Information Security Officer jobs?

Cities with the most Information Security Officer job openings:

What are the most commonly searched types of Information Security Officer jobs?

The most popular types of Information Security Officer jobs are:

Who are the top companies hiring for Information Security Officer jobs?

The top employers for Information Security Officer jobs are:

What states have the most Information Security Officer jobs?

States with the most job openings for Information Security Officer jobs include:

What job categories do people searching Information Security Officer jobs look for?

The top searched job categories for Information Security Officer jobs are:

Infographic showing various Information Security Officer job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 74% Full Time, 22% Part Time, and 3% Contract. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution, with an average salary of $94,926 per year, or $45.6 per hour.

Information Security Officer

CityFirst Bank

Washington, DC • On-site

$135K - $140K/yr

Full-time

Re-posted 27 days ago


Job description

WHO WE ARE
City First Bank N.A. is a mission-driven Community Development Financial Institution (CDFI) principally focused on a transformative impact in underserved, urban markets with the highest needs to drive equitable economic development. Our credit activities are purely commercial and focused on the following segments: Multifamily Affordable Housing, Not-for-Profit Finance, and Small Business Finance. As a depository and commercial lending provider with over $1.3 billion in bank assets as of December 31, 2024, our unified organization has over 100 employees in Washington DC and Los Angeles/Inglewood, CA.
ROLE SUMMARY
The Information Security Officer is responsible for monitoring, analyzing, and maintaining the bank's technical security controls in support of City First Bank's Information Security Program. This role will be focused on maintaining the security of the bank's applications and network which includes creation and timely execution of security projects, tool installations and integrating risk-based threat intelligence into the operational environment. The role also supports the ability to maintain assurance in our technical security controls, especially on the Cloud, so that risks to the confidentiality, integrity, and availability of the bank's information systems and infrastructure are sufficiently mitigated which in turn, supports the bank's operational and compliance goals. The role will also perform triage and analysis of security events escalated from the Tier1 and Tier-2 support teams.
ESSENTIAL FUNCTIONS AND RESPONSIBILITIES
  • Advanced monitoring of the day-to-day operation of Security Information and Event Management (SIEM) and Network Anomaly Detection and other security control tools.
  • Act as the first point of response for security event alerts and notifications. Maintain an efficient and secure IT computing infrastructure on the bank's environment, cloud, and SaaS products.
  • Provide regular security reporting and risk metrics to IT Leadership, Senior Leadership, and committees as appropriate.
  • Monitor knowledge sharing services and advise leadership on cybersecurity trends, emerging threats, and regulatory guidance.
  • Leads Information Security compliance tasks and coordinate and gather artifacts for internal and external audits.
  • Serve as the bank's designee for regulatory and audit purposes. Align controls with guidance and recommendations.
  • Work with Compliance to identify, assess, and track remediation of security risk and findings.
  • Ensure compliance with GLBA, FFIEC, and other regulatory, industry, and cybersecurity standards for access control and system permissions.
  • Manage identity and access, roles and permissions, assignments and changes, and all other activities to ensure adherence to policies and procedures.
  • Oversee periodic User Access Reviews for key bank systems.
  • Enable and oversee the process of employee user account provisioning and de-provisioning, including Active Directory and SaaS applications.
  • Lead the creation, implementation and integration of identity tools and practices that enhance the organization's security and regulatory compliance.
  • Conduct and maintain IT risk assessments including Information Security, GLBA, and Vendor / Third Party reviews.
  • Manage vendor due diligence reviews from an information security and technology perspective.
  • Develop and evaluate security procedures for IT Department.
  • Develop and administer the bank's security awareness program including annual training and phishing simulations.
  • Partner with IT infrastructure, application, and operations teams to ensure secure system design and configuration.
  • Generate and analyze reports, monitor alerts, and review reports to monitor security activities and document findings and recommend corrective actions.
  • Work with managed service providers, network administrators and security operations to resolve problems, evaluate new solutions, recommend changes, and investigate incidents.
  • Collaborate with lines of business, system, and network administrators to develop and manage role-based access control groups for ensuring appropriate access to information systems, applications, and data.
  • Responsible for analyzing user access roles, permissions, and profiles to establish user provisioning within all bank applications.
  • Implement and upgrade network security tools running in the physical and virtual environments.
  • Ensure confidential data is secure and implement controls to ensure visibility and auditability across organization for changes in roles, functions, access-levels, and data footprint.
  • Other duties as assigned.

Requirements
EDUCATION & EXPERIENCE
Required Education/Experience:
  • Bachelor's degree in Computer Science or Information Systems, Information Technology, or related focused technical training (CISSP, CISM, CRISC, or CISA) or in lieu 4 additional years of engineering and information security experience.
  • 7+ years' experience in a combination of information security, or IT operations/engineering, or IT risk management
  • 4+ years' experience with designing and implementing information security technologies.
  • Extensive experience in banking regulations and compliance requirements, specifically related to regulatory examinations and security requirements.
  • Experience in supporting and managing audit, examination, and regulatory interactions.

Preferred Education/Experience:
  • 8 years of Engineering or Security Administration in banking preferred.
  • 2 years security engineering/administration in the banking/financial sector

KNOWLEDGE, SKILLS, AND ABILITIES
Required Knowledge & Skills:
  • Knowledge of Microsoft Azure and Microsoft O365 virtualized environment and tools is a must. Ability to configure and work on Azure Security Center and O365 Security Center.
  • Knowledge of Active Directory, Azure AD, identity management, DLP policies, Azure Sentinel and other security tools essential.
  • Familiarity with at least one security best practice standards such as the Center for Internet Security (CIS) Security Controls or NIST Cybersecurity Framework, or equivalent.
  • Excellent knowledge of Azure Security Center and Azure portal. Knowledge of SEIM and AD tools.
  • Excellent knowledge of Microsoft Operating system and Azure tools. Strong Active Directory and Windows Group Policy knowledge.
  • Networking technology and protocols, including routers, switches, VPNs, Citrix, email gateways, etc.
  • Requires skill in providing expert input into technology projects.
  • Assist the Tier-1 and Tier-2 escalations with troubleshooting and analysis of security events.

Salary Description
$135,000 - $140,000, annually