VP Information Security Manager

Bank of the Sierra

California (MO)

On-site

USD 80,000 - 100,000

Full time

34 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Bank of the Sierra is seeking an Information Security Manager to provide independent oversight of IT security controls and oversee physical security, risk management, and business continuity across the organization. The role partners with IT, Operations, and Enterprise Risk Management to align with regulatory expectations and industry best practices.

Responsibilities include coordinating physical security, developing a robust business continuity program, conducting risk assessments, monitoring

Qualifications

  • Bachelor's degree from an accredited college or university with seven+ years in financial institution operations and information/cyber security.
  • Knowledge of security frameworks and regulatory expectations (e.g., CRI, NIST CSF, FFIEC, GLBA, CCPA, PCI DSS).
  • Ability to assess control design and operating effectiveness.
  • Advanced knowledge of bank operations, systems, products, and services.
  • Excellent communication and analytical skills.

Responsibilities

  • Coordinate with senior leaders to maintain an effective physical security program across locations.
  • Develop and maintain a robust business continuity program including BIA, risk assessment, and testing.
  • Perform risk assessments including inherent risk, control effectiveness, and residual risk determinations.
  • Evaluate design and operating effectiveness of security controls and drive remediation of gaps.
  • Review and maintain security policies to align with regulatory requirements and risk appetite.
  • Assist with audits/regulatory examinations and ensure deficiencies are remediated.
  • Provide advisory oversight for third-party information security risk management and cyber risk remediation.
  • Prepare information security and physical security reports for Management and Board/Committees or working groups.

Skills

Security governance
Regulatory compliance
Risk assessment
Incident response oversight
Vendor risk management

Education

Bachelor's degree in a related field

Tools

Microsoft Office

Job description

Job Summary

The Information Security Manager supports the Senior Information Security Officer and works with enterprise stakeholders, such as IT, Operations, and Enterprise Risk Management, to provide independent oversight of the organization\'s IT security controls, ensuring information security risks are identified, measured, monitored, and reported in alignment with regulatory expectations, internal risk appetite, and industry best practices. The Information Security Manager will have primary responsibility for managing the Bank\'s physical security and business continuity programs.


Responsibilities Include, But Are Not Limited To


  • Coordinate with the Director of Community Banking, branch leadership, IT, and Facilities to ensure the Bank maintains an effective physical security program at all locations.

  • Work with business leaders to develop and maintain a robust business continuity program, including business impact analysis, risk assessment, continuity and recovery strategies, training and communication, and testing.

  • Perform annual updates to the R-SAT and CRI profile. Conduct and/or review information security and IT risk assessments, including inherent risk, control effectiveness, and residual risk determinations.

  • Evaluate the design and operating effectiveness of information and physical security and controls through appropriate monitoring and testing. Partner with stakeholders to identify root cause and appropriately mitigate any identified gaps.

  • Review and maintain review of information and physical security policies, standards, and guidelines to ensure alignment with regulatory requirements and risk appetite.

  • Assists with audits and regulatory examinations, including coordinating responses, providing required documentation, and ensuring identified deficiencies are remediated.

  • Provide second-line input of third-party information security risk management, including review of vendor risk assessments, due diligence results, and cyber risk remediation.

  • Provide advisory oversight for cybersecurity incidents by reviewing root cause analysis, corrective action plans, incident trends, and systemic control weaknesses, and validating that lessons learned are incorporated into risk assessments, controls, and policies.

  • Creates or assists with the preparation of information security and physical reports for Management and Board/Board Committees.

  • Participates in IT, Security, Deposit, AI, and Lending Working Groups.

  • Works with business partners to ensure appropriate information and cybersecurity risks are considered with new products, services, delivery channels, and technology initiatives.

  • Creates or assists with the preparation of information and physical security communications and training materials.

  • Coordinate with internal stakeholders and subject matter experts, third-party vendors, and external legal counsel, as needed, to identify, report, track, and remediate issues and incidents.

  • Acts as a subject matter resource on information and physical security regulatory expectations and industry best practices.

  • Monitor for and communicate risks and potential risk mitigation strategies to address emerging threats.

  • Ensures consistent application of information and physical security policies, procedures, and regulatory requirements.

  • Performs other duties as assigned.


Education And/Or Experience

Bachelor\'s degree from an accredited college or university and a minimum of seven years of experience in financial institution operations and information/cyber security; or an equivalent combination of education and experience.


Required Knowledge, Skill, And Ability


  • Strong understanding of security frameworks and regulatory expectations (e.g., CRI, NIST CSF, FFIEC, GLBA, CCPA, PCI DSS).

  • Demonstrated ability to assess control design and operating effectiveness.

  • Advanced technical and banking information security knowledge.

  • Advanced knowledge of bank operations, systems, products, and services.

  • Strong analytical and problem-solving skills.

  • Detail-oriented, with the ability to manage multiple tasks and prioritize work in a fast-paced environment.

  • Ability to work independently while performing duties, with excellent organizational and time management skills.

  • Advanced personal computer skills, including proficiency in Microsoft Office products.

  • Excellent verbal, written, and interpersonal communication skills.

  • Exercises awareness with regard to possible suspicious activity, money laundering, or fraudulent behavior.


Physical Demands

The physical demands described herein are representative of those that an employee must meet to perform the essential functions of this job successfully. Reasonable accommodations may be made to enable individuals with disabilities to perform essential functions. While performing the duties of this job, the employee is regularly required to sit. The employee is frequently required to talk or hear. The employee is occasionally required to stand, walk, and reach with hands and arms. The employee must occasionally lift and/or move up to ten pounds. Specific vision abilities this job requires include close vision and the ability to adjust focus.


Work Environment

This job operates in a professional office environment. This role routinely uses standard office equipment such as computers, phones, photocopiers, scanners, filing cabinets, and fax machines. The noise level in the work environment is usually moderate. The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform essential functions.


Bank of the Sierra is proud to be an equal opportunity workplace and is an affirmative action employer committed to equal employment opportunities regardless of race, color, religion, sex, sexual orientation, gender identity, national origin, veteran, or disability status.


Salary Range: $80,000 - $100,000

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Manger
Information Security Manger

Bank of the Sierra • California (MO), Northern (KY)

Hybrid
USD 80,000 - 100,000
Information Security Engineer
Information Security Engineer

Farmers & Merchants Bank of Long Beach • Seal Beach (CA)

On-site
USD 114,000 - 194,000
Information Security Manager
Information Security Manager

Alpine Bank • Denver (CO), Grand Junction (CO), Rifle (CO)

On-site
USD 107,000 - 137,000
Information Security Analyst
Information Security Analyst

TowneBank • Suffolk (VA)

On-site
USD 55,000 - 65,000
Information Security Analyst
Information Security Analyst

TowneBank • Suffolk (VA)

On-site
USD 55,000 - 65,000
Information Security Officer
Information Security Officer

City First Bank • Inglewood (CA)

On-site
USD 100,000 - 140,000
Security Administrator
Security Administrator

SAFE FCU • Sumter (SC)

On-site
USD 60,000 - 80,000
Remote VP, Information Security & Continuity
Remote VP, Information Security & Continuity

Bank of the Sierra • California (MO), Northern (KY)

Hybrid
USD 80,000 - 100,000
Information Security Officer
Information Security Officer

City First Bank • Washington

On-site
USD 90,000 - 130,000
Security Administrator
Security Administrator

Grbbank • City of Rochester (NY), Northern (KY)

On-site
USD 94,000 - 106,000