Information Security Officer
- Expired: over a month ago. Applications are no longer accepted.
HYBRID ROLE IN NYC
This position reports directly to the Head of the Information Security Office, contributes to, and supports the firm's overall Information Security. The position interfaces with various levels of IT and business personnel, monitoring critical security functions, evaluating key IT processes from a perspective of information security, and advises on best practices and approaches. The ISO is an advanced role supporting the entire cybersecurity program. This individual provides executive support, strategic and tactical guidance, and complete execution for a world-class cybersecurity program, primarily supporting regional enterprise security initiatives.
As directed by the CISO, the ISO helps drive strategy while providing oversight and reporting on the execution of enterprise security systems, applications and operations. As a business enabler, the ISO ensures business decisions are not obstructed by cybersecurity but instead are made using sound security principles and supporting corporate security policies and plans. The ISO will work with an adaptable and secure business-supporting cybersecurity team, in addition to influencing and executing with technical teams, which includes but is not limited to patch management, security operations, security engineering and software development.
Stay abreast of information security and information technology issues, threats, vulnerabilities and regulatory changes affecting the organization, and perform independent research as needed. Provide consultation and guidance to IT teams as and when needed to address issues.
Ensure security governance is uniformly applied and remain informed on projects progress; create quality reports illustrating program status, areas for improvement and success
Work with, monitor and provide guidance, evaluation and advocacy on information security related audits including scope of audits, issue finding, and disposition of issues to put the institution in its best light.
Work closely with various business functions (e.g., banking, equities, operational risk, compliance, legal, HR and audit teams) to provide security best practice expertise. Stay abreast of new laws, regulations and standards, and assess their impacts to the business
Drive efforts to internally assess, evaluate and make recommendations to management regarding the adequacy of the security controls, security programs across the enterprise
Conduct independent verification of the company networks and sensitive programs through internal team resources and independent consultant engagements
Provide status reports and dashboards on various matters (BAU activity, projects, KRIs, strategy, etc.)
Perform other duties as assigned
Demonstrates highly effective communications skills with the ability to influence business units
Solid knowledge of information security tools and techniques, including: data leakage prevention, incident response, vulnerability scanning and reporting, security operations, identity management and Cloud security
Ability to independently work, be counted upon, manage priorities, and remain flexible in a changing environment while meeting project timelines
Proven high level of integrity, trustworthiness and confidence, as well as ability to represent the company and security leadership with the highest level of professionalism
Strong project management and organizational skills
Applicable knowledgeable with the cybersecurity requirements and best practices recommended by various regulators such as the Federal Reserve Bank (FRB), New York Department of Financial Services (NYDFS) regulations and frameworks, and others;
Intimate familiarity with National Institute of Technology (NIST) standards, International Standards Organization (ISO) standards, etc. and aligning those with enterprise solutions & processes
Education and Experience Requirements
Bachelor's degree and/or Masters degree in computer science, MIS, information assurance or related technical field. Related experience acceptable in lieu of related degree.
10+ years’ cybersecurity experience with at least 5+ years in an operationally focused security practitioner role
Solid knowledge of several information security and technology frameworks including: FFIEC, ISO, NIST
Financial Services/Banking experience is preferred
CISSP, CRISC, CISA, CISM, CEH or CCSP certifications a plus
AddressNew York, NY
TechnologyView all jobs at ACS Solutions
Get fresh Information Security Officer jobs daily straight to your inbox!
You Already Have an Account
We're sending an email you can use to verify and access your account.
If you know your password, you can go to the sign in page.