Information Security Officer

Hawaiiusa-Federal-Credit-Union

Honolulu (HI)

On-site

USD 111,000 - 150,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Full health insurance coverage
Paid Time Off
401(k) with employer contribution
Tuition assistance
Flexible spending account
Opportunities for advancement

Job summary

Hawaiiusa Federal Credit Union is seeking an Information Security Officer (ISO) to oversee its information security initiatives. Based in Honolulu, this full-time role involves managing compliance with NCUA regulations and enhancing the internal security posture.

Responsibilities include conducting risk assessments, overseeing incident responses, and coordinating vendor management. The ideal candidate will have significant experience in information security within financial services and possess

Qualifications

  • 7+ years in information security or related field; financial services preferred.
  • Working knowledge of NCUA Part 748, GLBA, and risk management frameworks.
  • Leadership experience in cybersecurity or IT risk management is required.
  • Experience in building an internal info security function is a plus.
  • CISSP or CISM certification required; CRISC, CISA, GIAC, CCSK, CCSP preferred.

Responsibilities

  • Own the Information Security Program and ensure compliance.
  • Conduct risk assessments of systems and third-party vendors.
  • Oversee incident response plans and vulnerability management.
  • Lead vendor risk management for cloud and fintech relationships.
  • Deliver security awareness training to the staff and Board.

Skills

ISO Standards
Incident Response and Cyber Resilience
Access Management Governance
Regulatory Examination and Audit
Security Technologies and Architecture
Executive and Board Reporting
Attention to Detail
Identity Management Governance
Cloud and SaaS Security
Facilitation

Education

Bachelor's degree in Computer Science or Information Security

Job description

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.

Information Security Officer

Full Time Professional College Walk, Honolulu, HI, US

4 days ago Requisition ID: 1198

Salary Range: $110,667.18 To $150,000.24 Annually

The Information Security Officer (ISO) owns and is accountable for the credit union’s written Information Security Program (ISP), ensuring compliance with NCUA regulations (12 CFR Part 748), the GLBA Safeguards Rule, and applicable federal and state cybersecurity requirements. The ISO works in partnership with the credit union’s outsourced CISO partner (OneStep), the Information Security Governance Committee, and IT Security to direct the program’s execution, while retaining ultimate accountability to the Board, the VP of Enterprise Risk Management, and NCUA examiners. The ISO also partners with the VP of ERM to lead the credit union’s transition toward an internal information security department. The ISO provides independent oversight and challenge of information security and establishes information security governance and risk requirements.

Key Responsibilities

  • Own and maintain the written Information Security Program (ISP), incorporating guidance from OneStep and the Information Security Governance Committee, with accountability for the program’s adequacy to the Board, VP of ERM, and NCUA examiners.
  • Conduct annual risk assessments of information systems, third-party vendors, and data flows.
  • Oversee the incident response plan (IRP), including compliance with the NCUA 72-hour cyber incident notification rule.
  • Direct vulnerability management, penetration testing, and patch management programs, coordinating execution across external IS consultants and IT Security.
  • Lead vendor/third-party risk management for cloud, core processor, and fintech relationships, including ongoing due diligence and performance monitoring of OneStep as a critical vendor.
  • Align business continuity/disaster recovery planning with information security controls.
  • Deliver information security awareness training and phishing simulation programs to staff and the Board.
  • Serve as primary point of contact for NCUA/state examiners on IT and cybersecurity exams, including the ACET (Automated Cybersecurity Examination Tool) process.
  • Serve as the credit union’s primary internal liaison to the outsourced CISO (external consultant), translating security guidance and recommendations into internal policy, procedures, and Board reporting.
  • Serve as an active member of the Information Security Governance Committee, coordinating between external consultant’s CISO recommendations and internal execution via IT Security.
  • Partner with the VP of Enterprise Risk Management to lead the transition from outsourced information security support (external consultant) to an internal information security department, including org design, staffing plan, and phased capability build-out.
  • Collaborate with the VP of ERM on decisions regarding which functions remain outsourced to external consultant versus insourced as the department matures.
  • Integrate information security risk into the enterprise risk register and ERM reporting cycle, in coordination with the VP of Enterprise Risk Management.
  • Ensure escalation to the Board/Risk Committee is preserved: ISP updates and material risk findings are escalated through the VP of ERM for inclusion in Board/Risk Committee reporting at least annually, with direct Board access maintained for significant incidents or unresolved risk disagreements.
  • Establish Information Security requirements for cloud, SaaS hosted, and externally managed environments, including identity, encryption, logging, configuration management, data protection, and third-party connectivity.
  • Monitor cybersecurity threats, vulnerabilities, regulatory alerts, financial-sector threat intelligence, and emerging technology risks, and assess their relevance and potential impact to the credit union.

Job Skills

  • ISO Standards
  • Presentations
  • Access Management Governance
  • Incident Response and Cyber Resilience
  • Regulatory Examination and Audit Management
  • Executive and Board Reporting
  • Control Objectives for Information and Related Technologies (COBIT)
  • Security Technologies and Architecture
  • Attention to Detail
  • Facilitation
  • Identity Management Governance
  • Cloud and SaaS Security

Qualifications & Experience

  • 7+ years of progressively responsible experience in information security, cybersecurity, technology risk, information security governance, or a related discipline, with financial-services experience strongly preferred and credit-union experience highly desirable.
  • Working knowledge of NCUA Part 748, GLBA, FFIEC guidance, and the ACET, NIST or equivalent framework.
  • Three plus years in a leadership or supervisory capacity within information security, IT risk, or a related discipline required (e.g., team lead, security manager, or comparable supervisory role) recommended.
  • Experience building or scaling an internal information security function, including staffing and organizational design, strongly preferred.
  • Experience working within an enterprise risk management framework preferred.
  • CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager) or equivalent senior information security certification required, CISSP and CISM combination preferred.
  • CRISC (Certified in Risk and Information Systems Control) preferred.
  • CISA (Certified Information Systems Auditor) preferred.
  • GIAC (Global Information Assurance) / GSEC (GIAC Security Essentials) certifications preferred.
  • CCSK (Certificate of Cloud Security Knowledge) /CCSP (Certified Cloud Security Professional) preferred.
  • CGRC (Certified in Governance, Risk and Compliance) preferred.
  • Computer Science (Bachelor's degree) or Information Security (Bachelor's degree) or Information Technology (Bachelor's degree) or equivalent experience.

Minimum Physical Requirements and Working Conditions

  • Sitting for prolonged periods at a desk working on a computer.
  • Frequent prolonged meetings in person or online.
  • Traveling to various branches on occasion.
  • Reaching, bending, twisting, turning on occasion.
  • Lifting, pulling, pushing, and carrying up to 30 pounds on occasion.
  • We’ll make reasonable accommodations for qualified applicants and employees with disabilities.

Benefits and Pay

The expected pay for the Information Security Officer (ISO) is $110,667.18 to $150,000.24 per year.

This pay reflects the compensation we reasonably expect to offer for this role based on typical qualifications and market data. Offered pay may vary depending on the candidate’s experience, skills, and other relevant factors.

We cover 100% of employees single medical, drug, vision, and dental monthly health insurance premiums. Employees also love receiving paid volunteer time and our pay it forward program. Tuition assistance for higher education is another special way we invest in our workforce. Benefits include, Paid Time Off, 401(k) and 3% Employer Contribution, Health insurance, Paid time off, Vision insurance, Dental insurance, Prescription drug insurance, Tuition reimbursement, Life insurance, Flexible spending account, Disability insurance, Health savings account, Opportunities for advancement, Employee assistance program, Referral program, Retirement plan, Employee discount, Paid training, Professional development assistance, AD&D insurance, Volunteer time off, Credit union membership, Paid orientation, and more.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Officer
Information Security Officer

HawaiiUSA FCU • Honolulu (HI)

On-site
USD 111,000 - 150,000
Health insurance
401(k) plan with company contribution
Tuition reimbursement
+3
VP, Information Security Officer
VP, Information Security Officer

ADP, Inc. • Littleton (MA)

Hybrid
USD 190,000 - 251,000
Basic life and AD&D insurance
PTO 15+ days per year
Volunteer time off (VTO)
+5
VP, Information Security Officer
VP, Information Security Officer

Workers' Credit Union Inc. • Littleton (MA)

On-site
USD 188,000 - 251,000
Life insurance
PTO (paid time off)
Volunteer time off
+5
VP, Information Security Officer
VP, Information Security Officer

Workers Federal Credit Union • Littleton (MA)

Hybrid
USD 188,000 - 251,000
401(k)
Tuition Reimbursement
Mental health resources
+2
VP, Information Security Officer
VP, Information Security Officer

Workers Credit Union • Littleton (MA)

Hybrid
USD 188,000 - 251,000
Healthcare coverage
401(k) plan
Paid time off
Information Security Officer: Lead Internal ISP & Risk
Information Security Officer: Lead Internal ISP & Risk

Hawaiiusa-Federal-Credit-Union • Honolulu (HI)

On-site
USD 111,000 - 150,000
Full health insurance coverage
Paid Time Off
401(k) with employer contribution
+3
Enterprise Security Analyst II
Enterprise Security Analyst II

Associated Credit Union • Peachtree Corners (GA)

On-site
Security Administrator
Security Administrator

SAFE FCU • Sumter (SC)

On-site
USD 60,000 - 80,000
Information Security Officer
Information Security Officer

The Dime Bank Honesdale PA • Honesdale

On-site
USD 120,000 - 180,000
Information Security Officer
Information Security Officer

Paylocity • Honesdale, Northern (KY)

On-site
USD 120,000 - 190,000