CISO: Strategy, Programs & GRC Leader

Bocusa

New York (NY)

On-site

USD 65,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Bank of China in New York, NY seeks an information security leader to drive Strategy, Programs, Governance, Risk, and Compliance for the US operations. You will coordinate security strategy, manage CISO projects, and oversee policy development, training, and metrics to ensure strong governance and regulatory alignment.

You will conduct risk assessments, manage privacy programs, and coordinate audits while guiding cross-functional teams to implement robust controls aligned with NIST/FFIEC

Qualifications

  • Bachelor’s degree in a relevant field.
  • Minimum 5 years of work experience in Risk Management, Audit, IT/IS Operations, or related functions.
  • Minimum 3 years of experience developing and executing IT/IS Risk programs, projects, and policies.
  • Minimum 1 year of experience with US Banking Regulations and IT/IS Risk Frameworks.
  • Strong program, frameworks, project management, development, and maintenance skills.
  • Strong writing skills for governing documents (policies/standards).
  • Excellent verbal and interpersonal skills across stakeholders including senior management.
  • Familiarity with IT/IS Risk Management regulations, standards, and frameworks (NIST, ISO27002, FFIEC).

Responsibilities

  • Coordinate Information Security strategy aligned with the branch strategy.
  • Maintain initiative tracking and KRIs to monitor progress.
  • Conduct quarterly strategy reviews with CISO team and adjust as needed.
  • Provide end-to-end project management for CISO-led projects.
  • Manage Information Security Program, Data Privacy Program, and Training & Culture Program, including phishing campaigns and tabletop exercises.
  • Establish and maintain Information Security policies; define roles and responsibilities.
  • Refresh CISO policy guidance with updated controls; monitor adherence and metrics.
  • Oversee administrative support for the Information Security Committee and sub-committees.
  • Develop and execute a TISR risk framework; conduct risk assessments for projects, third-party, new activities, and applications.
  • Track remediation of TISR issues from audits and regulatory exams; refresh policies annually.
  • Support audit requests and prepare evidence for regulatory examinations.
  • Ensure privacy policy compliance and oversee privacy risk assessments.
  • Coordinate with cross-functional teams to align access governance with organizational goals.

Skills

Project management
Policy writing
Stakeholder management
Regulatory knowledge
Risk assessment
Communication
IT/IS risk management
CISSP/CRISC preferred

Education

Bachelor’s Degree in Business, Risk, Data, Computer Science, Management Information Systems, Engineering, Mathematics, or related field

Job description

Bank of China in New York, NY seeks an information security leader to drive Strategy, Programs, Governance, Risk, and Compliance for the US operations. You will coordinate security strategy, manage CISO projects, and oversee policy development, training, and metrics to ensure strong governance and regulatory alignment.

You will conduct risk assessments, manage privacy programs, and coordinate audits while guiding cross-functional teams to implement robust controls aligned with NIST/FFIEC

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

CISO Strategy & Governance Lead — Programs, GRC & Risk
CISO Strategy & Governance Lead — Programs, GRC & Risk

Bank of China Limited, New York Branch • Town of New Windsor (NY)

On-site
USD 42,000 - 90,000
Strategic CISO - Programs, Strategy & GRC
Strategic CISO - Programs, Strategy & GRC

Bank of China USA • New York (NY)

On-site
USD 65,000 - 150,000
Strategic CISO — Programs, GRC & Policy Leadership
Strategic CISO — Programs, GRC & Policy Leadership

Bank of China Limited, New York Branch • Town of New Windsor (NY)

On-site
USD 65,000 - 150,000
Chief Information Security Office-Strategy, Programs & GRC AVP
Chief Information Security Office-Strategy, Programs & GRC AVP

Bank of China Limited, New York Branch • Town of New Windsor (NY)

On-site
USD 65,000 - 150,000
Chief Information Security Office-Strategy, Programs & GRC Associate
Chief Information Security Office-Strategy, Programs & GRC Associate

Bank of China Limited, New York Branch • Town of New Windsor (NY)

On-site
USD 42,000 - 90,000
Chief Information Security Office-Strategy, Programs & GRC AVP
Chief Information Security Office-Strategy, Programs & GRC AVP

Bank of China USA • New York (NY)

On-site
USD 65,000 - 150,000
Chief Information Security Office-Strategy, Programs & GRC AVP
Chief Information Security Office-Strategy, Programs & GRC AVP

Bocusa • New York (NY)

On-site
USD 65,000 - 150,000
US CISO: Crypto, AI & GRC Strategy
US CISO: Crypto, AI & GRC Strategy

Socket.dev • Palo Alto (CA)

Hybrid
USD 250,000 - 400,000
Strategic BISO - Cyber Resilience & Compliance Leader
Strategic BISO - Cyber Resilience & Compliance Leader

RBC • Jersey City (NJ)

On-site
USD 160,000 - 275,000
Total Rewards program
Flexible benefits
Stock options where applicable
+1
CISO - FinTech Security Leader, Hybrid NYC
CISO - FinTech Security Leader, Hybrid NYC

DriveWealth • New York (NY)

Hybrid
USD 300,000 - 375,000
Base salary
Bonus
Equity
+2