Chief Information Security Officer

CorServ

United States

Hybrid

USD 140,000 - 180,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Competitive compensation
Company-paid benefits (medical, dental
Remote-friendly environment
401k match
Generous PTO

Job summary

CorServ is seeking a senior cybersecurity leader to establish and govern a comprehensive security program across the enterprise. You will align security with business objectives, regulatory requirements, and client expectations, while guiding risk-based decisions and remediation strategies.

The role requires deep expertise in governance, architecture, incident response, vulnerability management, and compliance with PCI DSS and SOC 2.

Qualifications

  • 10+ years of progressive experience in information security or related disciplines.
  • Strong knowledge of governance, risk management, security architecture, incident response, and operations.
  • Deep understanding of NIST, PCI DSS, and SOC 2.

Responsibilities

  • Establish a cybersecurity governance framework aligned with business objectives and regulatory requirements.
  • Set security priorities and a roadmap based on risk, technology needs, and threats.
  • Lead enterprise cybersecurity risk assessments and remediation decisions.
  • Maintain a security program aligned with PCI DSS, SOC 2, and banking requirements.
  • Oversee PCI and SOC compliance activities, training, and regular reviews.
  • Provide leadership for regulatory examinations, audits, pen tests, and third-party reviews.
  • Oversee third-party cybersecurity risk management and vendor monitoring.
  • Provide security architecture oversight across applications, APIs, databases, networks, and cloud.
  • Establish security architecture principles for confidentiality, integrity, availability, resilience.
  • Ensure operation of firewalls, IDS/IPS, encryption, DLP, file integrity, and vulnerability management.
  • Oversee IAM controls including privileged access, MFA, and access reviews.
  • Lead vulnerability management across infrastructure and applications with risk-based prioritization.
  • Oversee security monitoring to detect unauthorized activity and emerging threats.
  • Partner with Technology and Dev teams to remediate vulnerabilities within risk timelines.
  • Own the incident response program with tested plans and clear communication protocols.
  • Promote a security-conscious culture and responsible handling of company/client data.

Skills

Security governance
Risk management
Security architecture
Incident response
Vulnerability management
Security operations
Data protection
IAM / access control
Endpoint security
Network security
Cloud security
Threat monitoring

Education

Bachelor's degree in Cybersecurity/IT/CS/IS/Engineering
CISSP, CISM, CRISC, CCSP or equivalent

Job description

DUTIES AND RESPONSIBILITIES
  • Establish a cybersecurity governance framework aligned with business objectives, regulatory requirements, client expectations, and industry best practices.
  • Establish security priorities and a security roadmap based on business risk, evolving technology requirements, and emerging threats; advise on risks, vulnerabilities, threats and recommended mitigation strategies.
  • Lead enterprise cybersecurity risk assessments and ensure identified risks are appropriately documented, prioritized, remediated, or accepted.
  • Maintain a security program aligned with applicable frameworks and standards, including PCI DSS, SOC 2, and relevant banking and financial institution requirements.
  • Oversee activities required to maintain PCI and SOC compliance, including, but not limited to, security awareness training, weekly security scan reviews, and recurring monthly, quarterly, and annual compliance activities.
  • Provide security leadership and oversight for regulatory examinations, client audits, penetration testing, vulnerability assessments, and third-party security reviews, and participate directly in the evaluation and remediation of significant findings.
  • Oversee security due diligence and third-party cybersecurity risk management, including responses to vendor and partner requests, as well as ongoing monitoring of critical vendors.
  • Provide oversight of security architecture across applications, APIs, databases, networks, cloud environments, identity systems, endpoints, and third-party integrations.
  • Establish security architecture principles and standards supporting confidentiality, integrity, availability, resilience, and scalability.
  • Ensure effective operation of security technologies and controls including firewalls, intrusion detection and prevention, endpoint security, encryption, data loss prevention, file integrity monitoring, vulnerability management, and security monitoring.
  • Ensure effective identity and access management controls, including privileged access, authentication, authorization, MFA, and periodic access reviews.
  • Establish and oversee a comprehensive vulnerability management program across infrastructure, applications, endpoints, and other technology assets including internal and external scanning, penetration testing, remediation tracking, and risk-based prioritization.
  • Oversee security monitoring and detection capabilities designed to identify unauthorized activity, anomalous behavior, and emerging threats.
  • Partner with Technology, Network Operations, and Development teams to ensure vulnerabilities are remediated within established risk-based timelines.
  • Own the cybersecurity incident response program and ensure documented plans, roles, escalation procedures, and communication protocols are maintained and regularly tested.
  • Promote a security-conscious culture and ensure employees understand their responsibilities for protecting company and client information.
REQUIREMENTS
  • 10+ years of progressive experience in information security, cybersecurity, infrastructure security, security engineering, or related disciplines.
  • Strong knowledge of cybersecurity governance, risk management, security architecture, incident response, vulnerability management, and security operations.
  • Deep understanding of NIST cybersecurity frameworks, PCI DSS, and SOC 2.
  • Hands-on experience with data protection, encryption, DLP, identity and access management, endpoint security, firewalls, intrusion detection/prevention, and security monitoring technologies.
  • Experience working with external auditors, regulators, financial institutions, clients, and third-party vendors on cybersecurity matters.
  • Ability to balance security requirements with business objectives and make risk-based decisions in a fast-paced technology environment.
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Engineering, or a related discipline.
  • Relevant professional certification such as CISSP, CISM, CRISC, CCSP.
  • Ability to work within CorServ's footprint (AL, FL, GA, IA, KY, NE, NC, TN, TX, WI, WY)
ABOUT CORSERV

CorServ is a credit card technology and portfolio management company that was founded in 2009. With decades of experience in payment systems, we enable financial institutions to enter or expand their credit card program with our open-source technology platform. Our global headquarters is in Atlanta, GA. We offer a competitive compensation package and company-paid benefits package including medical, dental, and vision. We also offer a generous PTO plan, 401k match, and the opportunity to work in a remote environment.

CorServ is an Equal Opportunity employer-All qualified applicants/employees will receive consideration for employment without regard to that individual's age, race, color, religion or creed, national origin or ancestry, sex (including pregnancy), sexual orientation, gender, gender identity, physical or mental disability, veteran status, genetic information, ethnicity, citizenship, or any other characteristic protected by law. CorServ is firmly committed to upholding EEO principles. As part of our standard pre-employment process, we conduct screenings for drugs, credit, and backgrounds in accordance with legal requirements and industry best practices. These measures help us maintain a safe, secure, and inclusive work environment for all employees.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Chief Information Security Officer
Chief Information Security Officer

Corserv Solutions, Inc. • Atlanta (GA)

On-site
USD 220,000 - 320,000
Remote environment
Competitive compensation
PTO
+1
IT Systems Administrator
IT Systems Administrator

Corserv Solutions, Inc. • Atlanta (GA), Northern (KY)

Hybrid
USD 70,000 - 95,000
Remote work option
Generous PTO
401k match
+1
Senior Systems Administrator
Senior Systems Administrator

Corserv Solutions, Inc. • Atlanta (GA)

Hybrid
USD 90,000 - 125,000
Medical, Dental, Vision
401k Match
Remote-friendly environment
+1
Senior Systems Administrator
Senior Systems Administrator

CorServ • United States

Hybrid
USD 90,000 - 130,000
Remote environment
401k match
Medical, dental, vision
Processor Integration Specialist
Processor Integration Specialist

Corserv Solutions, Inc. • Atlanta (GA)

On-site
USD 75,000 - 110,000
Medical, dental, and vision insurance
PTO (paid time off)
401(k) match
+1
Sr. Cybersecurity Governance, Risk, and Compliance (GRC) Associate
Sr. Cybersecurity Governance, Risk, and Compliance (GRC) Associate

Corient • Austin (TX)

On-site
USD 90,000 - 120,000
401(k) Plan with Employer Matching
Paid Medical, Dental, Vision Insurance
Paid Maternity & Parental Leave
+2
Information Security Engineer II
Information Security Engineer II

Merrick Bank • Town of Woodbury (NY)

On-site
USD 88,000 - 108,000
Competitive pay
Medical, Dental, Vision
401(k) with match
+2
Information Security Engineer II
Information Security Engineer II

CardWorks Servicing LLC • Town of Woodbury (NY)

On-site
USD 83,000 - 112,000
Bonus Target/Variable Pay
Medical, Dental, Vision
401(k) Match
+6
Security Engineer
Security Engineer

CI Financial • Denver (CO)

On-site
USD 100,000 - 160,000
401(k) Match
Medical Plan options
Dental, Vision & Life Insurance
+3
Information Security Engineer II
Information Security Engineer II

CardWorks, Inc. • Town of Woodbury (NY), Northern (KY)

Hybrid
USD 83,000 - 112,000
Competitive pay
Bonus target
Medical, dental & vision
+3