VP, Information Security

2 weeks ago


Raleigh, United States Local Government Federal Credit Union Full time
Job DescriptionJob Description
Description:

CIVIC CULTURE

Our organizations believe we can all do well by doing good. We value the contributions of diverse minds and prioritize the success and well-being of our employees. We also believe every person in our organization plays a role in supporting a healthy environment and helping to achieve our goal of prosperity for all. To this end, we recruit bright, energetic, and talented people to be members of our team. In return, we offer a dynamic workplace that presents opportunities for professional advancement and individual growth. We strive to always display integrity, self-awareness, courage, and respect for one another while continuing to seek opportunities to learn. We really believe that when our employees succeed, our community wins.


ABOUT THE POSITION

The VP, Information Security and Risk Governance will build, implement, and execute the Credit Union's Information Security Program. This role will be responsible for identifying, evaluating, and monitoring the overall security risk profile across the organization by assessing the effectiveness of information security controls and processes. This person will be defining and aligning information security governance and risk strategies for the Information Security Committee and ensuring exposures to cyber risks are identified and managed at an acceptable level. The VP, Information Security and Risk Governance will serve as the Information Security Officer for the organization, driving it to achieve its cyber security objectives through the proactive evaluation and enhancement of the organization's Information Security Program, activities and controls that prevent or mitigate the impact of compliance risk.


NORMAL DAY-TO-DAY WORK

  1. Collaborate with Legal, Risk, Compliance and key business leaders to identify information management and protection laws and regulations; implement actions to ensure compliance.
  2. Identify information security regulatory, legislative, and industry specific compliance requirements.
  3. Establish annual and long-term goals for the proper maintenance and security of information across the organization, defining risk and governance strategies, metrics, and reporting mechanisms.
  4. Develop strategies and action plans to drive security maturity improvement in areas where controls do not adequately mitigate risks.
  5. Develop executive and board-level communications as it relates to the organization's cybersecurity posture.
  6. Develop, document, and assess measures, metrics, and internal controls related to the maturity of the organization's information security program.
  7. Lead the development and implementation of effective and reasonable policies and practices to secure sensitive data and ensure security and compliance with contracts, regulatory requirements, and industry standards.
  8. Develop and manage the organization's cybersecurity risk management strategy, framework and approach.
  9. Integrate cyber security risk reporting and aggregate reporting into the organization's overall enterprise risk framework.
  10. Develop and maintain a Security Risk Management Framework (SRMF) per industry standards and applicability (e.g. NIST CSF), to include but not limited to, performing an annual Security Risk Assessment.
  11. Recommend programs to enhance the overall maturity of the organization's Information Security Program and tracking of its progress.
  12. Evaluate existing information security risk monitoring metrics and tools, develop metrics and insights where appropriate, and seek to enhance the maturity of information security analytics.
  13. Monitor compliance controls and catalog risk assessments utilized by the organization as it pertains to security risk, and then evaluate those assessments for best practices and gaps.
  14. Display integrity, self-awareness, courage, and respect for staff while ensuring learning agility and flexibility communicating and delegating effectively. Work effectively, collaboratively, and creatively in a team-oriented environment both internally and externally.
  15. Take ownership for actions, decisions, and results; openly accept feedback and demonstrate both the willingness and ability to improve.

JOB QUALIFICATIONS

Here are a few skills you MUST have to be qualified for this position.

  1. Minimum 10-12 years of progressive IT, networking, server administration, auditing, investigations, strategic risk management, and/or business/management consulting.
  2. Minimum 4-6 years of experience managing cross-functional, multi-business unit projects reflective of management or leadership role.
  3. Bachelor's degree in Information Security, Information Systems, Information Technology or Computer Science.
  4. Experience building and/or growing an IT Security practice with direct hands-on technology skillsets.
  5. Ability to function in a Consumer business office environment and utilize standard office equipment including but not limited to: PC, copier, telephone, etc.
  6. Ability to lift a minimum of 25 lbs. (file boxes, computer).
  7. Travel required on occasion.

Here are a few qualities we'd LIKE for you to have to make you more suited for this position.

  1. Certified Information Systems Security Professional (CISSP) or equivalent certification.


If you have questions about this position description, please feel welcome to ask. You can reach our HR Department at:

Civic Human Resources

3600 Wake Forest Road, Raleigh, NC 27609

careers@civicfcu.org

Requirements:




PI56306510682b-25405-35880327



  • Raleigh, North Carolina, United States Local Government Federal Credit Union Full time

    About the RoleThe Local Government Federal Credit Union is seeking a highly skilled and experienced professional to fill the position of VP, Information Security and Risk Governance. This role will be responsible for building, implementing, and executing the organization's Information Security Program.Key ResponsibilitiesCollaborate with Legal, Risk,...


  • Raleigh, United States Local Government Federal Credit Union Full time

    Description:CIVIC CULTUREOur organizations believe we can all do well by doing good. We value the contributions of diverse minds and prioritize the success and well-being of our employees. We also believe every person in our organization plays a role in supporting a healthy environment and helping to achieve our goal of prosperity for all. To this end, we...


  • Raleigh, United States Local Government Federal Credit Union Full time

    Job DescriptionJob DescriptionDescription:CIVIC CULTUREOur organizations believe we can all do well by doing good. We value the contributions of diverse minds and prioritize the success and well-being of our employees. We also believe every person in our organization plays a role in supporting a healthy environment and helping to achieve our goal of...


  • Raleigh, North Carolina, United States Local Government Federal Credit Union Full time

    About the RoleCivic Culture is a core value at Local Government Federal Credit Union, where we believe that doing well by doing good is essential to our success. We're seeking a highly skilled and experienced professional to join our team as the VP, Information Security and Risk Governance. This role will be responsible for building, implementing, and...


  • Raleigh, North Carolina, United States Local Government Federal Credit Union Full time

    About the RoleThe VP, Information Security and Risk Governance will be responsible for developing and implementing the Credit Union's Information Security Program. This includes identifying, evaluating, and monitoring the overall security risk profile across the organization, assessing the effectiveness of information security controls and processes, and...


  • Raleigh, North Carolina, United States Sunstates Security Full time

    Director of Information TechnologySunstates Security is seeking an experienced Director of Information Technology to lead our corporate IT department in Raleigh, NC. The ideal candidate will have a strong background in IT leadership, system implementations, and problem-solving.Key Responsibilities:Develop and implement IT strategies to support business...


  • Raleigh, North Carolina, United States Sunstates Security Full time

    Director of Information TechnologySunstates Security is seeking an experienced Director of Information Technology to lead our corporate headquarters in Raleigh, NC. The ideal candidate will have a strong background in IT leadership, system implementations, and problem-solving.Key Responsibilities:Develop and implement IT strategies to support business...


  • Raleigh, North Carolina, United States Sunstates Security Full time

    Director of Information TechnologySunstates Security is seeking an experienced Director of Information Technology to join our team at our corporate headquarters in Raleigh, NC. This key leadership position will drive the business and management of the entire IT department.Key Responsibilities:Coordinate technology infrastructure, enterprise applications, and...


  • Raleigh, United States Raleigh-Durham International Airport (RDU) Full time

    About Us: Welcome aboard the Raleigh-Durham Airport Authority team, where our work environment resembles a well-oiled aviation crew. As operators of the Raleigh-Durham International Airport, we connect central and eastern North Carolina to people and places that matter the most, serving 14.5 million passengers in 2023 and supporting over 85,000 local and...


  • Raleigh, North Carolina, United States Sunstates Security Full time

    Director of Information Technology Job DescriptionSunstates Security is seeking an experienced Director of Information Technology to lead our IT department at our corporate headquarters in Raleigh, NC.The Director of IT will be a key member of senior leadership, driving business growth and managing the entire IT department. This role requires a leader with...


  • Raleigh, North Carolina, United States UMB Bank Full time

    About the RoleWe are seeking a highly skilled Sr. Information Security Risk Analyst to join our Corporate Information Security and Privacy (CISP) team at UMB Bank. As a key member of our team, you will play a critical role in identifying threats, vulnerabilities, and risks, and helping to protect the people, information, and services within our...


  • Raleigh, North Carolina, United States Local Government Federal Credit Union Full time

    About the RoleThe Chief Information Security Officer will be responsible for building, implementing, and executing the Credit Union's Information Security Program. This includes identifying, evaluating, and monitoring the overall security risk profile across the organization by assessing the effectiveness of information security controls and processes.Key...


  • Raleigh, North Carolina, United States First Citizens Bank Full time

    Job SummaryWe are seeking a highly skilled Senior Manager Information Security to join our team at First Citizens Bank. This is a critical role that requires a strong background in information security and the ability to lead and manage a team of security professionals.Key ResponsibilitiesDevelop and implement information security strategies and roadmaps to...


  • Raleigh, North Carolina, United States Wells Fargo Full time

    Mainframe Security Expert WantedWe are seeking a highly skilled Mainframe Security Expert to join our team at Wells Fargo. As a key member of our Mainframe Security Team, you will be responsible for providing complex technical analysis and support of mainframe security in a large, complex Multi-LPAR RACF environment.Key Responsibilities:Provide technical...


  • Raleigh, North Carolina, United States First Citizens Bank Full time

    Job SummaryWe are seeking a highly skilled Senior Manager Information Security to join our team at First Citizens Bank. This role will be responsible for managing the Container Vulnerability Management team and activities, partnering with leadership and stakeholders to make Container VM easy for container owners while maturing the program.Key...


  • Raleigh, North Carolina, United States Global Channel Management Full time

    Project Manager Information Security Role SummaryAs a seasoned Information Security Project Manager at Global Channel Management, you will oversee the execution of complex projects that require advanced project management and technology knowledge. With a minimum of 6 years of experience in project management and a strong background in information security,...


  • Raleigh, United States James River Management Company Full time

    Information Security Operations Analyst II (Information Technology) Raleigh, NC, USA * Richmond, VA, USA * Virtual Req #132Monday, August 12, 2024Come grow with James River Insurance! James River Insurance is an excess and surplus lines segment of James River Group Holdings, Ltd. and operates on an approved non-admitted basis in 50 states and Washington,...


  • Raleigh, United States JR Group Full time

    Come grow with James River Insurance! James River Insurance is an excess and surplus lines segment of James River Group Holdings, Ltd. and operates on an approved non-admitted basis in 50 states and Washington, DC. Since 2003, James River has provided thousands of commercial property and casualty customers with innovative and creative solutions for...


  • Raleigh, North Carolina, United States Pierce Technology Corp Full time

    Job DescriptionAt Pierce Technology Corp, we are seeking a highly skilled Senior Information Security Analyst to join our team. This role is responsible for defining and implementing strategic security goals by identifying optimal approaches and determining the necessary tools, technologies, tasks, processes, and metrics for execution.Key...


  • raleigh, United States FUJIFILM Diosynth Biotechnologies Full time

    About UsWe are a trusted CDMO partner for life. At FUJIFILM Diosynth Biotechnologies (FDB), we encourage you to discover what inspires you every day, to follow your passion and your power – what we call Genki. The work we do has the potential to transform people’s lives and to impact where it matters most.Each day is an opportunity to push the boundaries...