Information Security Officer

The Dime Bank Honesdale PA

Honesdale (Wayne County)

On-site

USD 120,000 - 180,000

Full time

8 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

The Dime Bank Honesdale PA is seeking an Information Security Officer to develop, implement, and manage the bank's Information Security Program. You will lead governance, risk management, regulatory compliance, and incident response to safeguard bank information assets.

Ideal candidates have 5+ years in information security with leadership experience, knowledge of NIST CSF/ISO standards, and banking regulatory familiarity. Strong communication and collaboration with the Board are essential.

Qualifications

  • Bachelor's degree in information security, cybersecurity, IT, risk management, CS or related field required; Master's preferred.
  • Skills include strong written and verbal communication, interpersonal skills, and knowledge of information security regulations and controls.
  • Experience: 5+ years in information security/risk management; 3+ years in leadership; security certs (CISSP/CISM/CCSP) preferred; banking experience preferred.

Responsibilities

  • Develop and manage the bank's information security strategy, policies, and risk management.
  • Lead cybersecurity governance, risk reporting to execs and Board.
  • Oversee incident response, third-party risk, and regulatory compliance.
  • Coordinate risk assessments and information security testing and validation.
  • Ensure IAM, data classification, encryption, and monitoring align with frameworks.
  • Direct security training, awareness, and program metrics for senior leadership.

Skills

Leadership
Cybersecurity governance
Regulatory compliance
Incident response
NIST CSF
Communication

Education

Bachelor's degree in information security or related field
Master's degree preferred

Job description

Description

The Information Security Officer (ISO) shall be responsible for developing, implementing, and managing the Bank's Information Security Program and policies to ensure the confidentiality, integrity, and availability of bank information assets. ISO serves as the primary leader for cybersecurity governance, risk management, regulatory compliance, incident response, and security awareness initiatives. This position ensures compliance with applicable banking regulations, including FFIEC guidance, GLBA, Pennsylvania Department of Banking, Interagency Guidelines Establishing Information Security Standards, state regulations, and cybersecurity best practices.

As a key member of the Bank's risk management framework, the ISO provides independent oversight and possesses independent authority for information security risk reporting to executive management and the Board of Directors.

Essential Duties
  • Develop and maintain the bank’s information security strategy, risk tolerance, policies and information security exception management for alignment with business objectives.
  • Conduct risk assessments and report findings to senior management and the board.
  • Ensure alignment of security controls with business objectives and regulatory requirements.
  • Monitor third-party vendor security practices.
  • Provide employee and board training and awareness programs.
  • Establish and maintain the Bank’s cybersecurity strategic roadmap.
  • Provide cyber risk appetite and operational resilience reporting
  • Ensure the Bank’s Information Security Program aligns with Information security frameworks (NIST Cybersecurity Framework (CSF 2.0), CIS Critical Security Controls (CIS Controls), and ISO/IEC 27001)
Ancillary Duties
  • Present cybersecurity risk assessments, program updates, significant cybersecurity incident reporting, third party cyber risks, emerging threats, remediation efforts and strategic information security initiatives to executive management and the Board.
  • Maintain Information Security compliance standards (GLBA Safeguards Rule compliance, customer information protection, security awareness program effectiveness, policy exception management, annual Information Security Program review.
  • Develop mitigation plans for identified vulnerabilities and threats.
  • Develop and oversee security control testing and validation efforts, for existing Information Security Technology, upgrades and enhancements.
  • Responsible for leading the bank’s information security risk assessments (ISRA, GLBA, Privacy)
  • Lead the Bank’s Incident Response Program. Coordinate response activities during security incidents. Ensure proper breach notification and regulatory reporting procedures are followed.
  • Conduct post-incident reviews and lessons-learned sessions. Maintain cyber resilience and recovery procedures.
  • Participate in vendor due diligence reviews. Assess SOC reports, penetration test results, and security questionnaires. Monitor vendor cybersecurity performance and remediation efforts. Support contract language related to cybersecurity requirements.
  • Working with the Information Technology Management Team, oversee security monitoring and threat detection activities.
  • Review and manage cybersecurity alerts and incident investigations.
  • Responsible for reviewing key performance indicators for the information security program. These include but are not limited to the following:
  • Completion of annual risk assessments
  • Reduction of critical vulnerabilities
  • Regulatory examination results
  • Audit finding remediation timelines
  • Employee phishing test performance
  • Third-party risk assessment completion rates
  • Incident detection and response metrics
  • Security awareness training completion rates
  • Compliance with Board-approved security objectives
  • Develop and maintain cybersecurity metrics, key risk indicators (KRIs), and executive dashboards for Board reporting.
  • Responsible for ensuring the Bank’s Identity and Access Management (IAM) processes use industry best practices and risk management controls.
  • Ensure appropriate vulnerability management processes are maintained.
  • Review application deployment and change management processes to ensure security standards are adhered to.
  • Maintain threat intelligence and cyber threat monitoring processes, including participation in FS-ISAC and other financial sector information-sharing organizations.
  • Direct penetration testing and independent security assessments.
  • Maintain and oversee cybersecurity supply-chain risk management practices for critical vendors, fintech partners, cloud providers, and service providers.
  • Ensure standards are documented and adhered to for data encryption at rest and in motion.
  • Responsible for creating and maintaining the Bank’s data classification standards, data retention requirements, secure disposal procedures for hardware and software, and maintaining the bank’s sensitive data inventory, and ensure hardware, software and information asset inventories are in place and updated.
  • Ensure Password policy standards are documented and adhered to for all systems, including multi-factor authentication for all software with customer or sensitive bank information.
  • Ensure compliance with federal incident notification requirements, including 36-hour notification requirements for qualifying computer-security incidents.
  • Collaborate as a member of the Business Continuity Planning (BCP) Committee with business continuity team members to ensure cyber resilience is developed in all departmental BCP plans.
  • Coordinate and conduct annual cyber recovery testing, ransomware recovery exercises and all relevant tabletop exercises.
  • Chair or participate in the Information Security Committee.
  • Lead security-related projects and initiatives. Including Conducting periodic NIST CSF information security maturity assessments, gap analyses, and program effectiveness reviews.
  • Responsible for coordinating all regulatory examinations, independent audits, and security assessments related to information security and cybersecurity and for ensuring management responses and corrective action plans are completed in a timely manner.
  • Perform tasks which are supportive in nature of the essential functions of the job, but which may be altered or re-designed depending upon individual circumstances.
Requirements

Education/Training: A bachelor’s degree in information security, Cybersecurity, Information Technology, Risk Management, Computer Science, or related field required. Master's degree preferred.

Skill(s): Proficient reading, writing, and grammar skills; proficient interpersonal relations and communicative skills; proficient information technology skills, including information security and applicable regulations; visual and auditory skills; valid driver's license.

Experience: A minimum of five (7) years of information security, information technology risk management, cybersecurity, audit, or related experience, including at least three (3) years in a leadership role. Relevant security certifications are preferred (CISSP, CISM, CCSP) but not required. Banking or regulated financial institution experience strongly preferred

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Officer
Information Security Officer

Paylocity • Honesdale, Northern (KY)

On-site
USD 120,000 - 190,000
Information Security Officer
Information Security Officer

The Dime Bank • Honesdale

On-site
USD 110,000 - 140,000
Information Security Officer
Information Security Officer

Planters Bank • Tyler (TX)

On-site
USD 120,000 - 180,000
Information Security Officer
Information Security Officer

Planters Bank • New Orleans (LA)

On-site
USD 110,000 - 170,000
Information Security Officer
Information Security Officer

Planters Bank • Shreveport (LA)

Hybrid
USD 120,000 - 180,000
Information Security Officer
Information Security Officer

Planters Bank • Germantown (TN)

Hybrid
USD 120,000 - 180,000
Information Security Officer
Information Security Officer

City First Bank • Inglewood (CA)

On-site
USD 100,000 - 140,000
Banking Information Security Leader | Risk, Compliance & Response
Banking Information Security Leader | Risk, Compliance & Response

Paylocity • Honesdale, Northern (KY)

Hybrid
USD 120,000 - 190,000
Information Security Officer
Information Security Officer

Fortis Bank • Midvale (UT)

On-site
USD 150,000 - 210,000
Great Place to Work certification
In-office 5 days a week
Bank Information Security Officer
Bank Information Security Officer

TransPecos Financial Corporation • San Antonio (TX)

Hybrid
USD 120,000 - 160,000