Information Security Officer

Fortis Bank

Denver (CO)

On-site

USD 180,000 - 240,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Fortis Bank, based in Denver/Salt Lake City markets, seeks an Information Security Officer responsible for protecting sensitive data, ensuring regulatory compliance, and minimizing risk in a changing threat landscape. The role requires expertise in banking regulations, FDIC examinations, and audits for mid-sized banks.

The successful candidate will lead security strategy, governance, risk assessments, and incident response, while coordinating with regulators, executives, and cross‑functional

Qualifications

  • Bachelor’s degree in information security, CS or related field (Master’s preferred).
  • 7–10 years in information security with at least 3 years in a leadership role within banking/financial services.
  • Proven experience with FDIC examinations, including preparation, participation, and follow‑up on findings for banks with assets in the $1–2 billion range.
  • Experience conducting and managing audits (financial statements, IT general controls, compliance) per GLBA/FFIEC/BSA/AML for mid‑sized community banks.
  • Professional certifications such as CISSP, CISM, CRISC or equivalent.
  • Hands‑on experience with security technologies (firewalls, IDS/IPS, encryption, endpoint protection).

Responsibilities

  • Develop, implement, and maintain information security policies, procedures, and standards aligned with regulatory requirements and best practices.
  • Lead risk assessments, vulnerability management, and security incident response; coordinate with internal teams and external partners.
  • Oversee design and execution of security controls for IT systems, networks, cloud environments, and third‑party vendors.
  • Conduct regular security audits, IT risk assessments, penetration testing, and compliance reviews; identify and remediate weaknesses.
  • Collaborate with senior leadership to integrate security into business processes, including new product launches and tech acquisitions.
  • Manage security awareness training programs for employees and ensure ongoing education on threats.
  • Prepare and present reports on security metrics, risks, and compliance status to executive management and the board.
  • Manage the business continuity / disaster recovery program, including annual tabletop exercises.
  • Stay abreast of evolving threats, regulatory changes, and tech advancements to enhance security posture.
  • Coordinate with regulators during examinations and audits; respond to findings and implement corrective actions.

Skills

Leadership experience
Regulatory knowledge
Risk assessment
Security governance
Communication skills
Incident response coordination
Vendor management

Education

Bachelor's degree in Information Security, Computer Science, or related field
Master's degree preferred
CISSP
CISM
CRISC

Tools

Firewalls
IDS/IPS
Encryption
Endpoint protection

Job description

Summary

The ISO will be responsible for protecting the bank's sensitive data, ensuring compliance with regulatory requirements, and mitigating risks in an evolving threat landscape. This role requires a strategic thinker with deep expertise in banking regulations, including mandatory experience in FDIC examinations and audits for mid‑sized banks. The ideal candidate will foster a culture of security awareness while implementing robust frameworks to safeguard our operations, customers, and assets.

Responsibilities
  • Develop, implement, and maintain the bank's information security policies, procedures, and standards in alignment with regulatory requirements and industry best practices.
  • Lead risk assessments, vulnerability management, and security incident response efforts, including coordination with internal teams and external partners during security incidents.
  • Oversee the design and execution of security controls for IT systems, networks, cloud environments, and third‑party vendors.
  • Conduct regular security audits, IT risk assessments, penetration testing, and compliance reviews to identify and remediate potential weaknesses.
  • Collaborate with senior leadership to integrate security into business processes, including new product launches and technology acquisitions.
  • Manage security awareness training programs for employees and ensure ongoing education on emerging threats.
  • Prepare and present reports on security metrics, risks, and compliance status to executive management and the board of directors.
  • Manage the business continuity / disaster recovery program for the bank, including annual tabletop exercises.
  • Stay abreast of evolving cyber threats, regulatory changes, and technological advancements to proactively enhance the bank's security posture.
  • Coordinate with regulators during examinations and audits, ensuring timely response to findings and implementation of corrective actions.
Minimum Qualifications
  • Bachelor's degree in Information Security, Computer Science, or a related field; Master's degree preferred.
  • Minimum of 7–10 years of experience in information security, with at least 3 years in a leadership role within the banking or financial services industry.
  • Proven experience with FDIC examinations, including preparation, participation, and follow‑up on findings for banks with assets in the $1–2 billion range.
  • Demonstrated expertise in conducting and managing other relevant audits, such as financial statement audits, IT general controls audits, and compliance reviews typical for mid‑sized community banks (e.g., under GLBA, FFIEC guidelines, and BSA/AML frameworks).
  • Hands‑on experience implementing cybersecurity frameworks, including CRI Profile of NIST Cybersecurity Framework (CSF) 2.0 and CIS 8.1, with a track record of mapping controls to regulator requirements.
  • Professional certifications such as CISSP, CISM, CRISC, or equivalent.
  • Strong knowledge of security technologies, including firewalls, intrusion detection / prevention systems, encryption, and endpoint protection.
  • Excellent communication skills, with the ability to translate complex technical concepts to non‑technical stakeholders.
  • Ability to work in a fast‑paced environment and manage multiple priorities effectively.
  • Strong organizational time‑management skills, problem‑solving skills, and the ability to quickly grasp concepts and processes with limited guidance from management.
  • Strong written and verbal communication skills.
  • Must be able to work in a team environment with the ability to interact well, and in a positive manner, with co‑workers and management.
  • Versatility, flexibility, and a willingness to work on consistently changing priorities with enthusiasm.
Reporting Structure

Reports to the SVP, Chief Information Officer.

Office Requirements

This position is required to be in the office five days per week. The position is open in the Denver and Salt Lake City markets.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Officer
Information Security Officer

Fortis Private Bank • Denver (CO)

On-site
USD 190,000 - 200,000
Chief Information Security Officer
Chief Information Security Officer

Quest Technology Management • United States

Hybrid
USD 180,000 - 280,000
Chief Information Security Officer
Chief Information Security Officer

Jobtailor • Sacramento (CA)

On-site
USD 180,000 - 260,000
Chief Information Security Officer
Chief Information Security Officer

The Security Executive Council • Houston (TX), Northern (KY)

Hybrid
USD 180,000 - 280,000
Chief Information Security Officer (CISO)
Chief Information Security Officer (CISO)

Pibank USA • Miami (FL)

On-site
USD 180,000 - 260,000
Information Security Officer
Information Security Officer

German American • Jasper (IN)

On-site
USD 90,000 - 115,000
Medical insurance
25 days paid time off
Education Assistance Program
+2
Information Security Officer
Information Security Officer

German American • Owensboro (KY)

On-site
USD 90,000 - 120,000
Medical, dental, vision insurance
25 days paid time off
Education Assistance Program
+1
Information Security Officer
Information Security Officer

German American • Evansville (IN)

On-site
USD 90,000 - 130,000
Medical, dental, vision insurance
25 days paid time off
Education Assistance Program
Information Security Officer
Information Security Officer

City First Bank • Inglewood (CA)

On-site
USD 100,000 - 140,000
Chief Information Security Officer
Chief Information Security Officer

originbank • Ruston (LA)

On-site
USD 180,000 - 280,000
Dream Manager program
Wellness coaching
Access to certified financial planners