Chief Information Security Officer

1 week ago


Mt Rainier, United States Conference of State Bank Supervisors Full time

CSBS Corporate, Washington, District Of Columbia, United States of America Job Description Posted Thursday, April 11, 2024 at 4:00 AM This position is responsible for providing vision, leadership, oversight, and management of CSBS cyber security policies, procedures, and practices. He/she directs, coordinates, plans, and organizes security activities throughout CSBS. Responsible for managing information security risks that affect the organization-wide strategic objectives through ongoing risk assessment. The Chief Information Security Officer (CISO) acts as the focal point for all communications related to security, both with internal staff and third parties, and works with a wide variety of people from different internal organizational units, bringing them together to manifest controls that reflect workable compromises as well as proactive responses to current and future information security risks compliant with relevant laws and regulations. The CISO also provides thought leadership in conjunction with his/her engagement in industry and government forums, and collaboration with state and federal cyber security experts and practitioners. Guidance, direction, and authority for information security activities are centralized for the entire CSBS organization with the CISO. Essential Functions To perform this job successfully, an individual must be able to perform each essential duty and responsibility satisfactorily. Reasonable accommodations may be made to enable an individual with disabilities to perform the essential functions. Other duties may be assigned to meet business needs. Member of the Senior Leadership Team (SLT) The SLT is a group of peers with individual leadership roles at CSBS and a commitment to working across business units to achieve organizational goals. SLT members collaborate to ensure priorities and resources are aligned to successfully implement CSBS strategies. They are responsible for delivering on those strategies while also demonstrating our values to reinforce a positive and collaborative CSBS culture. People Manager At CSBS, people managers lead and engage staff to maximize organizational performance. Understanding and implementing the organizations strategies, people managers lead their teams through change with a focus on CSBS mission and vision and a commitment to our VIBE. People managers actively participate in the growth and development of their teams delegating responsibility effectively and providing timely and actionable feedback on performance. Responsible for planning and organizing their teams activity, people managers are also responsible for creating a positive employee experience while developing high-performing and innovative teams. Develop an information security vision and strategy that is aligned to organizational priorities and enables and facilitates the organization's business objectives, and ensures senior stakeholder buy-in and mandate. Develop and maintain the CSBS strategic security program and plan, taking into consideration business, fiduciary, and legal requirements, risk (likelihood and impact), and criticality; and building consensus among stakeholders. Monitor the effectiveness of the information security program and make recommendations for improvements. Develop and enhance an up-to-date information security management framework based on the National Institution of Standards and Technology Cyber Security Framework. Develop, maintain, and enforce CSBS cyber security policies and practices designed to protect sensitive corporate assets, ensure data privacy, and comply with laws and regulations, including the Federal Information Security Management Act (FISMA), Payment Card Industry (PCI) and the Criminal Justice Information System (CJIS) and other applicable -security laws. Maintain familiarity with AICPA System and Organization Control Reports such as SOC for Cybersecurity. Conduct periodic audits and assessments to ensure that the company is meeting its obligations under these regulations. Create a framework for roles and responsibilities with regard to information ownership, classification, accountability, and protection of information assets. Manage contractors and outsourcers providing technology services to CSBS, including managed security services, infrastructure engineering, operations, desktop support, and software development. Ensure compliance with the appropriate policies, laws, and regulations. Create a risk-based process for the assessment and mitigation of any information security risk at CSBS consisting of supply chain partners, vendors, consumers, and any other third parties. Work effectively with business units to facilitate information security risk assessment and risk management processes and empower them to own and accept the level of risk they deem appropriate for their specific risk appetite. Develop, maintain, and enforce CSBS security policies and procedures, for example: Identification of sensitive data and policies/practices regarding the identification of sensitive data as well as practices for information labeling, handling, and storage. Personnel security, including role-appropriate pre-employment background checks and security awareness training, ensuring necessary and appropriate content and compliance with requirements for each employee to take the training as well as the frequency of updated training. Network, infrastructure, and application security. Ensure technology solutions adhere to appropriate security practices and meet security requirements, including Software-as-a-Service (SaaS) contracts, Infrastructure-as-a-Service (IaaS) contracts, Platform-as-a-Service (PaaS) contracts, and customized software development solutions. Provide guidance and make recommendations to CSBS management and the Board of Directors with regard to the security characteristics (i.e., advantages and disadvantages) of various technologies and business practices. Ensure contracts with third parties contain appropriate security language, including data privacy and protection language required by state and federal laws. Develop, maintain, and manage a third-party security assessment program for key vendor relationships and third-party providers. Manage the CSBS incident response plan. Perform incident response planning, including developing, maintaining, and enforcing the CSBS incident response plan in addition to managing security incidents if/when they occur. This would include coordinating incidents, if applicable, with associated third-party providers and, if applicable, multiple regulatory organizations and stakeholders. Coordinate, provide leadership and management for security related audits and inspections. Interface as the primary contact with state and federal regulators and third-party contractors with regard to CSBS security posture and practices. Collaborate and liaise with the Chief Privacy Officer to ensure that data privacy requirements are included where applicable. Facilitate a metrics and reporting framework to measure the efficiency and effectiveness of the program, facilitate appropriate resource allocation, increase the maturity of the information security, and review it with stakeholders at the executive and board levels. Brief leadership and the Board of Directors annually, and as needed, on the security risk posture of the organization. Manage the information security budget, ensuring that resources are allocated appropriately to address the most critical risks. This includes identifying and prioritizing security initiatives and working with other leaders in the company to secure funding for these initiatives. Additional Responsibilities Provide thought leadership to industry and government forums related to cyber security practices, issues, and challenges in the financial services industry, such as the Executive Leadership of Cybersecurity. Collaborate with industry and government security officials on security-related issues and initiatives, including national security issues impacting the financial services sector. Monitor industry trends for changes in physical and cyber security threats and implement planning, policy, and procedure changes in response. Contribute to industry and government forums that develop industry guidance and regulations regarding security practices. Prepare and present security related briefings for senior CSBS and industry executives as well as state and government regulators. Minimum Qualifications To perform this job successfully, an individual should possess the knowledge, skills, and abilities listed and meet the amount of education, training and/or work experience required. Education and Experience Masters degree in technology related discipline or a bachelors degree with masters equivalent work experience in information security, privacy, or compliance. Industry Security Certification such as a valid and current CISSP, CISA or CISM certification is desired. Additional certification in CAP (FISMA), PCI QSA, ITIL, CSA CCSK (Cloud) or ISO 27001 is desired, but is optional. Minimum of 10 years of experience in security is required. Experience in the role of a Chief Information Security Officer (CISO)/Chief Security Officer (CSO) of an organization with a significant footprint in the financial services industry preferred. At least 8 years of experience in managing information security programs in accordance with the Federal Information Security Management Act (44 U.S.C. 3544), guidance and standards from the National Institute of Standards and Technology (NIST) and the Federal Information Processing Standards (FIPS). Minimum eight (8) years of management experience. Knowledge, Skills, and Abilities Knowledge of, and experience with, current physical and logical security issues and best practices in datacenter infrastructure, networks, end-user computing and applications. Knowledge of the cloud computing industry, including Software-as-a-Service (SaaS), Platform-as-a-Service (PaaS), and Infrastructure-as-a-Service (IaaS), including the security and privacy issues associated with using cloud infrastructure. Ability to work calmly during stressful circumstances. Strong interpersonal skills and communication skills. Ability to communicate at the executive level, including CXO level personnel as well as the CSBS Board of Directors and the SRR Board of Managers. Strong planning and task management skills. Strong vendor management skills. Ability to manage and assure successful delivery from outsourced third-party security and infrastructure providers. Ability to work in collaboration with a variety of stakeholders to identify and discuss issues. Ability to work in fast-paced environment managing multiple projects driven by multiple deadlines. Requirements Must be eligible to obtain or currently possess a U.S. Government clearance at the Public Trust (NACI) moderate level or higher. Must be an authorized United States citizen. Due to the nature of CSBSs business in support of state financial services supervision, all CSBS employees have the potential of interacting with confidential information related to the supervision of financial services companies (Confidential Supervisory Information). As a result, in addition to general business conflicts of interest, all CSBS employees are expected to disclose conflicts of interest in financial services companies on at least an annual basis and to proactively avoid such conflicts. Protect the confidentiality, integrity, and availability of CSBS information and information systems in accordance with CSBS policies and procedures. Values Instilled Behaviors for Excellence Member/ Customer Service Builds and values relationships. Prioritizes work. Advocates and advances member's goals. Teamwork Gives credit to others. Has a pitch in attitude. Learns from successes and setbacks. Respect/Trust Listens and learns from others. Speaks the truth even when uncomfortable. Honors the expertise of others. Recognizes the contributions of others. Consults and communicates effectively. Desires to make others successful. Ownership/Engagement Perseveres through adversity. Experiments and takes risks. Plans ahead and is forward-thinking. Core Leadership Competencies Achievement Oriented Thinking Focuses on prioritization what must your team really accomplish and by when. Achieves goals of strategic plan. Change Management Leads and enables change by demonstrating engagement, enthusiasm, advocacy and support for the change which includes being a first adopter. Participates throughout the lifecycle of the change. Builds a sponsor coalition to drive change success. Communicates directly with employees and facilitates open discussions about the change. Understands and manages resistance to ensure adoption. Manages own emotions productively to stay in role. Handles emotionally charged situations productively and with empathy. Asks for and openly accepts feedback; looks for opportunities to grow. Conducts conversations courageously - hitting difficult issues head-on with an eye on maintaining relationships. J-18808-Ljbffr



  • Mt Rainier, United States CourseFinder Australia Pty Ltd Full time

    How to Become a Chief Technology Officer: Australian Careers in IT The role of a Chief Technology Officer (CTO) is pivotal in todays technology-driven landscape. As a senior executive, the CTO is responsible for overseeing the development and implementation of technology strategies that align with the organisations goals. This position requires a deep...


  • Mt Rainier, United States CourseFinder Australia Pty Ltd Full time

    How to Become a Chief Technology Officer: Australian Careers in IT The role of a Chief Technology Officer (CTO) is pivotal in todays technology-driven landscape. As a senior executive, the CTO is responsible for overseeing the development and implementation of technology strategies that align with the organisations goals. This position requires a deep...


  • Mt Rainier, United States National Association of States Full time

    The National Skills Coalition (NSC) is seeking a Chief Development Officer (CDO) who will serve as an executive leader responsible for driving organizational growth and aligning development strategies with NSC's long-term objectives. This is a remote position with a competitive salary and benefits. The CDO is responsible for overseeing donor engagement,...


  • Mt Rainier, United States National Association of States Full time

    The National Skills Coalition (NSC) is seeking a Chief Development Officer (CDO) who will serve as an executive leader responsible for driving organizational growth and aligning development strategies with NSC's long-term objectives. This is a remote position with a competitive salary and benefits. The CDO is responsible for overseeing donor engagement,...


  • Mt Rainier, United States Catholic Charities Full time

    Chief Development Officer (CDO) The Chief Development Officer (CDO) develops and executes the Agency strategy for all fundraising activities to include securing individual, corporate and foundation contributions and government grants and contracts. The CDO implements a clear and passionate vision to achieve dynamic growth in all areas of the Agencys...


  • Mt Rainier, United States District of Columbia Full time

    Chief Technology Officer, Government of the District of Columbia Full-time The Office of the Chief Technology Officer (OCTO) is the central technology organization of the District of Columbia Government. OCTO develops, implements, and maintains the Districts technology infrastructure; develops and implements major enterprise applications; establishes and...


  • Mt Rainier, United States Advancing States Full time

    The National Skills Coalition (NSC) is seeking a Chief Development Officer (CDO) who will serve as an executive leader responsible for driving organizational growth and aligning development strategies with NSC's long-term objectives. This is a remote position with a competitive salary and benefits. The CDO is responsible for overseeing donor engagement,...


  • Mt Rainier, United States LoginSoft Full time

    Job Title: Chief Cybersecurity Solutions Officer (CCSO) Location: Washington, DC - Metro Full Time About LoginSoft: LoginSoft is a renowned provider of cybersecurity engineering services, specializing in delivering customized solutions to clients in the cybersecurity industry. With a strong track record of partnering with leading cyber product companies, we...


  • Mt Rainier, United States International Erosion Control Association Full time

    Compass Point is a premier independent, full-service investment firm providing a wide range of investment banking, research, and sales and trading services to our clients. We serve as an expert advisor and resource to corporate clients and institutional asset managers including mutual funds, hedge funds, and family offices. We are currently seeking a highly...


  • Mt Rainier, United States International Erosion Control Association Full time

    Compass Point is a premier independent, full-service investment firm providing a wide range of investment banking, research, and sales and trading services to our clients. We serve as an expert advisor and resource to corporate clients and institutional asset managers including mutual funds, hedge funds, and family offices. We are currently seeking a highly...


  • Mt Rainier, United States Compass Point Research & Trading LLC Full time

    Compass Point is a premier independent, full-service investment firm providing a wide range of investment banking, research, and sales and trading services to our clients. We serve as an expert advisor and resource to corporate clients and institutional asset managers including mutual funds, hedge funds, and family offices. We are currently seeking a highly...


  • Mt Rainier, United States EPIP Full time

    N Street Village is a community of empowerment and recovery for women experiencing homelessness and poverty in Washington, DC. With comprehensive services addressing both emergency and long-term needs, N Street Village helps women achieve stability and make meaningful gains in their housing, income, employment, mental health, physical health, and addiction...


  • Mt Rainier, United States National Restaurant Association Full time

    At the National Restaurant Association, we are committed to providing a dynamic and inclusive culture that inspires our work.We are seeking an experienced Chief Creative Officer - Brand Strategy to join our team. This is a hands-on production and leadership role overseeing a creative team of multimedia designers, video producers, writers, content developers,...


  • Mt Rainier, United States World Bank Full time

    Regional Chief Risk Officer - Global Industries and Risk Architecture Job : req30171 Organization: IFC Sector: Risk Grade: GI Term Duration: 3 years 0 months Recruitment Type: International Recruitment Location: Washington, DC, United States Required Language(s): English Preferred Language(s): None Closing Date: 12/6/2024 (MM/DD/YYYY) at 11:59pm UTC...


  • Mt Rainier, United States Tecknomic Full time

    This is a full-time position with Tecknomic and the project is with the Office of the Chief Financial Officer (OCFO). This is a hybrid role on-site at least 1 day/week. On-site requirements are subject to change based on client's needs . Please note, in order to apply for this position, you must be able to provide proof of Covid-19 vaccination at the initial...


  • Mt Rainier, United States FrameWorks Institute Full time

    FrameWorks Institute is seeking a Chief of Staff About the Role FrameWorks Institute is seeking a Chief of Staff who will partner with the CEO and other members of the senior leadership team to design and implement organization-wide initiatives to ensure: cross departmental integration; efficient internal functioning of the organization; strong...


  • Mt Rainier, United States FrameWorks Institute Full time

    FrameWorks Institute is seeking a Chief of Staff About the Role FrameWorks Institute is seeking a Chief of Staff who will partner with the CEO and other members of the senior leadership team to design and implement organization-wide initiatives to ensure: cross departmental integration; efficient internal functioning of the organization; strong...


  • Mt Rainier, United States On-Ramps Full time

    About the Organization Since 1971, the Southern Poverty Law Center has pursued racial justice and human rights for all people. From a small law office in Montgomery to a multi-state organization known nationwide for championing equity, the SPLC owes our 52 years of growth, change and triumph to the communities we serve, our dedicated staff, and committed...


  • Mt Rainier, United States Consumer Financial Protection Bureau Full time

    Washington, D.C. The Consumer Financial Protection Bureaus Acting Director Mick Mulvaney announced today that he has named Kirsten Sutton chief of staff for the agency. Ms. Sutton has been serving as staff director of the House Financial Services Committee under Chairman Jeb Hensarling. "I am pleased to announce Ms. Sutton as the new chief of staff at the...


  • Mt Rainier, United States Quadrant Full time

    Job ID: 24-04211 Security Engineer Washington, DC (Hybrid) Pay From: $140,000 per year MUST: Top Secret Clearance required Experienced Security Engineer 3 years relevant experience as a Security Architect in previous companies with a total of 5 years in Engineering or Architecture Proactive leader, helping to drive cross domain and security maturity...