The Application Security Program Manager provides leadership and governance for the bank’s application security, identity management, fraud-related technology risk, and emerging technology risk programs within the Information Security Program. This role establishes standards, risk assessment methodology, reporting, and a multi-year roadmap, coordinating with Technology and business leaders to align security expectations with regulatory requirements and business objectives.
Location & Employment Details
- Location: Honolulu, HI (onsite)
- Compensation: USD 86,503 - 138,365 per year
Core Responsibilities
- Develop and maintain information security risk management processes that are clear, workable, up to date, and reflect regulatory and bank-specific requirements and issues.
- Assist with communicating risk management processes across the business, including training sessions where appropriate.
- Plan, coordinate, implement, and manage security measures that address risks to systems and data, including preventing unauthorized modification, destruction, or disclosure of information, including by outsider service providers.
- Analyze and evaluate new products and systems for security weaknesses, and provide measures to prevent exposure and loss.
- Train staff on policies and standards related to application security and identity management best practices, including methodologies for conducting related risk assessments.
- Review and delegate work tied to governance and oversight of controls for application security and identity management.
- Lead and motivate a team to support engagement, performance, and productivity, including setting goals and providing guidance.
- Conduct regular performance reviews, provide constructive feedback, identify skills gaps, and support professional growth through training, mentorship, or cross-functional collaboration.
- Lead a risk-based application security review program to ensure appropriate security controls are designed, implemented, and operating effectively.
- Validate application and related reference architectures for security best practices and recommend changes to enhance security and reduce risk where applicable.
- Oversee application risk assessments and control reviews, identify weaknesses, and drive remediation plans with accountable stakeholders.
- Lead security risk evaluations for emerging technologies, new business initiatives, and material changes to the application and identity ecosystem.
- Conduct or facilitate threat modeling for services and applications, linked to associated risk and data.
- Provide strategic oversight for application security tooling, processes, and service models to support scalable coverage and risk visibility.
- Conduct incident response exercises and incorporate lessons learned into existing security architectures and practices.
- Conduct forensic analysis of security-related incidents in a manner consistent with best practices and counsel.
- Perform risk analyses for the bank’s security needs and prepare recommendations based on risk and exposure versus cost.
- Prepare and deliver research findings in written and/or oral form, including presenting objectives, alternatives, risk analyses, and cost/benefit analyses.
- Assist with planning and directing information security activities to support compliance with internal and external audits and federal and State regulations, including FDIC, relevant sections of the Gramm-Leach-Bliley Act (GLBA), Sarbanes-Oxley Act Section 404 provisions, and other duties as assigned.
- Maintain an outward-facing, forward-looking view to ensure the Information Security Program remains current and relevant.
- Design, implement, and manage Information Security data identification, aggregation, analytics, and validation to meet department goals.
- Collaborate on application security documentation (policies, standards, procedures, templates, and related materials) used for security governance in projects and operations.
- Initiate and execute process improvements and policy/procedure updates.
- Track developments and changes in digital banking and threat environments to ensure they are addressed in security strategy plans.
- Document data flows of sensitive information within the organization (for example, PII or ePHI) and recommend controls to secure this data (such as encryption and tokenization).
- Serve as Subject Matter Expert for application security, identity management, and API security, including security planning consulting in application and related infrastructure projects.
- Partner with cross-functional teams to ensure security requirements are incorporated into processes and operations.
- Liaison with vendor management to conduct security assessments of existing and prospective vendors, particularly those involving intellectual property and regulated or protected data (including SaaS, cloud/IaaS, managed service providers, and other relevant categories).
- Own the bank’s application security, identity governance, and fraud-related technology risk programs, accountable for strategy, governance, maturity, and measurable risk outcomes.
- Establish program objectives, control standards, operating procedures, risk tolerances, and performance metrics aligned to regulatory expectations.
- Develop and maintain a multi-year roadmap for people, process, and technology capabilities, including investment priorities, control enhancements, and maturity targets.
- Provide leadership reporting and risk insights to Information Security leadership, executive stakeholders, governance committees, auditors, regulators, and other appropriate parties.
Required Qualifications
- Education: Bachelor’s Degree from a 4-year university required, preferably in Information Security, MIS, Computer Science
- Experience (Program Manager I): 7+ years of experience with information security, application security, and regulations and privacy laws related to release of information, plus security and access control technologies (or equivalent experience)
- Program Manager I Management Experience: 3+ years managing or serving as a team lead with enterprise-wide cross-functional leadership responsibilities
- Experience (Program Manager II): 10+ years of experience with information security, application security, and regulations and privacy laws related to release of information, plus security and access control technologies (or equivalent experience)
- Program Manager II Management Experience: 5+ years managing or serving as a team lead with enterprise-wide cross-functional leadership responsibilities
Preferred Certifications
- CISSP, CISA, TOGAF, SANS GCSA, or equivalent certification (indicate upon hire)
Physical Requirements & Working Conditions
- Ability to perform light physical work and to move or lift items, including boxes, files, and papers, up to 20 pounds unless otherwise indicated.
- Ability to operate and use standard office equipment, including phone, copier, personal computer, and other work-related mechanical or electronic devices and applications.
- Ability to clearly communicate verbally and in writing with internal and external customers; able to hear sufficiently for daily discussions and interactions.
- Ability to read and understand bank-related documents.
- Ability to work in a conventional office setting, involving sitting at a desk or workstation for extended periods, and adapt to different work environments as needed.