INFORMATION SECURITY OFFICER

Commonwealth Business Bank

Los Angeles (CA)

On-site

USD 150,000 - 160,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical insurance
Dental insurance
401k retirement plan
Paid federal holidays

Job summary

Commonwealth Business Bank is seeking an Information Security Officer in Los Angeles to lead the bank's information security program. This role drives strategy, governance, and risk management to protect information assets and technology infrastructure.

The candidate will oversee policies, risk assessments, third-party security, and incident response, reporting to executive management and the board. A strong banking regulatory background and CISSP/CISM/CISA/CRISC preferred.

Qualifications

  • Bachelor's degree in a related field and 7+ years of information security leadership experience.
  • Experience with banking/financial services regulatory requirements like GLBA and FFIEC guidance.
  • Professional certifications (CISSP/CISM/CISA/CRISC) preferred.

Responsibilities

  • Develop and maintain the bank's information security strategy, architecture, and roadmap.
  • Oversee enterprise security policies, standards, and controls aligned with regulations.
  • Monitor threats, vulnerabilities, and industry trends; adapt controls accordingly.
  • Lead enterprise risk assessments and remediation tracking.
  • Coordinate cyber resilience programs with business continuity.
  • Manage third-party and cloud security risk, due diligence, and monitoring.
  • Lead identity and access management, data loss prevention, encryption, and related controls.
  • Direct incident readiness, response, and notifications to regulators and stakeholders.
  • Collaborate with auditors and regulators; provide timely security assessments.

Skills

NIST
ISO 27001
CIS Controls
SIEM
IDS/IPS
DLP
Cloud security
Encryption

Education

Bachelor's degree

Tools

CISSP
CISM
CISA
CRISC

Job description

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.

INFORMATION SECURITY OFFICER

Full Time Los Angeles, CA, US

3 days ago Requisition ID: 1109

Salary Range: $150,000.00 To $160,000.00 Annually

SUMMARY The Information Security Officer is responsible for developing, implementing, and maintaining the Bank’s information security program, strategy, and governance framework. This role provides independent oversight of information security risk and helps protect the Bank’s information assets and technology infrastructure from internal and external threats. The position leads initiatives supporting regulatory compliance, industry standards, security best practices, and a strong culture of security awareness across the organization. The position reports material information security risks, incidents, program performance, and resource needs to executive management and the Board or its designated committee.

Maintain sufficient organizational authority and independence to escal…

REQUIRED DUTIES

  • Develop, implement, and continuously enhance the Bank’s Information Security Strategy, Architecture, and Roadmap to align with business objectives, risk appetite, and regulatory requirements.
  • Establish and maintain enterprise-wide information security policies, standards, procedures, and controls consistent with industry best practices and applicable regulations.
  • Monitor emerging cybersecurity threats, vulnerabilities, and industry trends, adapting security strategies and controls to address evolving risks.
  • Develop, maintain, and oversee a documented, enterprise-wide information security risk assessment process that identifies reasonably foreseeable internal and external threats, evaluates the likelihood and potential impact of those threats, assesses the sufficiency of existing controls, prioritizes residual risks, and tracks remediation to completion.
  • Lead the Bank’s cyber resilience programs, including planning, testing, coordination, and ongoing improvement, in coordination with the Bank’s enterprise business continuity management program.
  • Oversee information security risk associated with third parties, service providers, cloud environments, and technology supply chains, including due diligence, contract requirements, ongoing monitoring, incident coordination, resilience considerations, and timely remediation of identified weaknesses.
  • Establish and oversee identity and access management, privileged access, authentication, data classification, data loss prevention, encryption, vulnerability management, secure configuration, patch management, logging, monitoring, and other key control processes based on the Bank’s risk assessment.
  • Direct cybersecurity incident preparedness, detection, response, investigation, containment, recovery, and post-incident remediation activities; coordinate required notifications to regulators, law enforcement, customers, and other stakeholders with Legal, Compliance, and executive management; and ensure lessons learned are incorporated into the information security program.
  • Coordinate with internal and external auditors, regulators, and independent assessors; provide complete and timely information for security-related reviews; track findings and corrective actions to completion; and preserve the independence of audit and other assurance functions.
  • Ensure compliance with applicable laws, regulations, and supervisory guidance, including the Gramm-Leach-Bliley Act, the Interagency Guidelines Establishing Information Security Standards, applicable FFIEC guidance, federal computer-security incident notification requirements, California privacy and breach-notification requirements, and other requirements applicable to the Bank’s activities and risk profile. Use recognized frameworks, including NIST, CIS Controls, and ISO 27001, as appropriate to support the Bank’s risk-based information security program.
  • Establish and maintain effective information security governance and provide periodic reporting to executive management and the Board or its designated committee on the Bank’s risk profile, material threats and vulnerabilities, significant incidents, control effectiveness, testing results, remediation status, third-party risks, program performance, and resource needs.
  • Serve as the primary liaison with internal and external auditors, regulators, and independent assessors, providing subject matter expertise, guidance, and oversight on security-related reviews, investigations, and assessments.
  • Develop, implement, and promote enterprise-wide security awareness and training programs to foster a strong culture of cybersecurity and accountability.
  • Provide leadership, guidance, and specialized security training to Information Technology personnel and other stakeholders on cybersecurity best practices and regulatory expectations.
  • Perform other duties and responsibilities as assigned by the Chief Risk Officer.

SKILL AND EXPERIENCE REQUIREMENTS

  • Strong knowledge of cybersecurity principles, frameworks, and technologies, including NIST, ISO 27001, CIS Controls, SIEM, IDS/IPS, DLP, encryption, cloud security, and other industry-standard security practices.
  • Exceptional leadership, communication, and interpersonal skills, with a demonstrated ability to collaborate across business and technology functions and influence stakeholders at all organizational levels.
  • Strong analytical, critical thinking, and problem-solving capabilities, with the ability to assess complex risks and make sound, risk-based decisions in a dynamic and fast-paced environment.
  • Proven ability to lead, mentor, and develop high-performing cybersecurity teams while fostering a culture of accountability, continuous improvement, and operational excellence.

EDUCATION AND PROFESSIONAL QUALIFICATION

  • Bachelor’s degree from an accredited university in Computer Science, Information Technology, Cybersecurity, or a related field.
  • Minimum of seven years of progressively responsible experience in information security or cybersecurity, including leadership responsibility for developing, implementing, and managing information security programs.
  • Experience in banking or financial services, including practical knowledge of the Gramm-Leach-Bliley Act, the Interagency Guidelines Establishing Information Security Standards, FFIEC information technology guidance, regulatory examinations, incident-notification requirements, third-party risk management, and applicable California privacy and breach-notification obligations.
  • One or more relevant professional certifications, such as CISSP, CISM, CISA, CRISC, or an equivalent credential, is preferred and may be required within a defined period after hire based on the candidate’s experience.
  • Proven ability to align cybersecurity strategies with business objectives, regulatory expectations, and organizational risk management practices.

We offer a competitive total rewards package, including but not limited to Medical, Dental, Vision, and Life Insurance, 401k retirement savings plan, and paid federal holidays, for this full-time position within the annual salary range of $150,000 - $160,000. Annual pay ranges are determined based on qualifications, level, and location. Exact compensation may vary based on your skills and experience.

Must be authorized to work in the US.

We are an Equal Opportunity Employer. All applicants will receive consideration for employment without regard to race, color, ancestry, religion, sex, national origin, sexual orientation, age, marital status, disability, gender identity, gender expression, genetic information, or military or Veteran status, or any other characteristic protected by law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Engineer
Information Security Engineer

Farmers & Merchants Bank of Long Beach • Seal Beach (CA)

On-site
USD 114,000 - 194,000
Sr. Security Engineer
Sr. Security Engineer

Jobot • Seal Beach (CA)

On-site
USD 130,000 - 185,000
Benefits package
Profit sharing
Flexible work environment
+1
Information Security Officer
Information Security Officer

City First Bank • Inglewood (CA)

On-site
USD 100,000 - 140,000
Senior Info Security Engineer
Senior Info Security Engineer

Us Bank • Minneapolis (MN)

On-site
USD 119,765 - 140,900
Healthcare (medical, dental, vision)
401(k) and employer-funded retirement plan
Paid vacation
+2
Application Security Program Manager I-II (On-Site)
Application Security Program Manager I-II (On-Site)

CPB Group Pty • Honolulu (HI), Northern (KY)

Hybrid
USD 87,000 - 138,000
Application Security Program Manager I-II (On-Site)
Application Security Program Manager I-II (On-Site)

Central Pacific Bank (HI) • Honolulu (HI)

On-site
USD 87,000 - 138,000
Information Security Officer
Information Security Officer

City First Bank • Washington

On-site
USD 120,000 - 170,000
Senior Information Security Analyst
Senior Information Security Analyst

Golden-1-Credit-Union • California (MO)

Hybrid
USD 112,000 - 120,000
FVP & Information Security Team Leader
FVP & Information Security Team Leader

ADP, Inc. • Los Angeles (CA)

On-site
USD 91,000 - 159,000
Medical, Dental, & Vision
Life, AD&D, & LTD
Flexible Spending Account
+4
FVP & Information Security Team Leader
FVP & Information Security Team Leader

Open Bank • Los Angeles (CA)

Hybrid
USD 91,000 - 159,000
Medical/Dental/Vision
Life Insurance & Disability
FSA
+4