> Markdown version of [/jobs/ext/1137314-evp-cio-ciso](https://www.wearedevelopers.com/jobs/ext/1137314-evp-cio-ciso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # EVP CIO & CISO - **Company:** TCM Inc - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $215,000.0 - $275,000.0 - **Contract:** Permanent contract - **Skills:** Agile Methodology, Amazon Web Services, Business Analytics Applications, Interactive Voice Response, Microsoft Azure, Cyber Security, Information Systems, Databases, Disaster Recovery, Identity and Access Management, IT Management, Intrusion Detection and Prevention, IP Pbx, Microsoft SQL Server, PCI Data Security Standards, Cloud Services, Software Vulnerability Management, Automated Information System (AIS), Computer Network Technologies, Information Technology, Data Management, CIS Benchmarks, Network Server - **Published:** July 2, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=acf21717f4ed7fdd ## About the Role * Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field required; advanced degree (MBA, MS) preferred. * 15-20 years of progressive IT leadership experience, with a minimum of 10 years in a senior leadership role with dual accountability for technology operations and information security. * Demonstrated track record of leading technology and security programs in a regulated financial services or banking environment. * Experience supporting remote and distributed workforces. * Preferred experience supporting a customer-facing contact center environment including IP PBX, IVR, Workforce Management Software, and call analytics platforms. Certifications (Required) * CISSP (ISC²) or CISM (ISACA) required; CRISC, CGEIT, or equivalent advanced certifications strongly preferred. * Additional certifications in cloud security (e.g., CCSP, AWS/Azure security) are a plus. Technical Knowledge * Deep knowledge of network technologies, architectures, topologies, hardware, software, and cloud service provider environments, including Microsoft Azure. * Expertise in systems and application technologies: servers, SANs, Microsoft SQL databases, physical security and access control systems, MFT applications, inventory management, AIS, and ITSM platforms. * Extensive knowledge of information security programs: encryption, data protection, privileged access management, and security frameworks as applied to PCI-DSS and SOC2 Type II. * Proficiency in cybersecurity industry frameworks (NIST CSF, CIS Controls, ISO 27001) and OCC audit requirements within a remote environment. * Knowledge of FFIEC and banking regulatory requirements as they apply to cybersecurity and technology solutions. Leadership & Executive Competencies * Proven ability to make high-stakes decisions with significant financial and operational impact. * Exceptional verbal and written communication skills for audiences ranging from technical teams to the Board of Directors. * Outstanding analytical, problem-solving, and strategic thinking skills in a fast-paced, high-pressure environment. * Strong results orientation in performance management, resource planning, capacity planning, and organizational leadership. * Executive presence and the credibility to represent TCM Bank with regulators, auditors, vendors, and external stakeholders. ## Description The EVP, Chief Information Officer & Chief Information Security Officer (CIO/CISO) is a business-first technology executive who serves as a core member of TCM Bank's leadership team, reporting directly to the President & CEO. TCM Bank exists with a distinctive and purpose-driven mission-serving as the primary credit card issuing partner for community banks across the country, providing a wide range of credit card products that help them better serve their own customers and communities. In this context, the CIO/CISO is not simply a technology operator; they are a strategic growth enabler whose decisions directly shape TCM Bank's ability to deliver on that mission. The CIO/CISO will work closely with the EVP and Chief Risk Officer to integrate technology and cybersecurity, partner with other executives, and regularly engage with the Board of Directors and its Technology, Product, and Risk Committees to provide strategic direction, governance, and oversight. This executive will act as the principal architect of the Bank's long-term digital evolution, spearheading the multi-year migration from a legacy, mainframe-based server infrastructure into a modernized, agile, cloud-centric bank payment provider platform. Collaborating closely with business teams and the EVP, Chief Risk Officer, the CIO/CISO will ensure this transformation is executed without compromising operational resilience, proactively mitigating regulatory and cyber risks, and continuously advancing the Bank's PCI-DSS and SOC2 Type II compliance and attestation goals. STRATEGIC VALUE OF THE COMBINED ROLE The intentional integration of the CIO and CISO functions into a single executive position reflects TCM Bank's commitment to security-by-design and technology excellence. This structure positions the Bank to respond with agility to an evolving threat landscape while maintaining operational excellence and regulatory compliance. KEY AREAS OF ACCOUNTABILITY Technology Strategy & Digital Evolution * Develop and own the Bank's multi-year technology strategy, aligning prior investments and new initiatives with macro business needs-including a data environment that enables smarter, faster decision-making across the enterprise. * Serve as the principal architect and executive sponsor of the Bank's migration from legacy, mainframe-based server infrastructure to a modernized, agile, cloud-centric payment provider platform-delivering this transformation on time, within risk parameters, and without disruption to operations or community banking partners. * Apply strong commercial acumen to technology investment decisions-evaluating build, buy, and partner options with a clear lens on ROI, risk, and strategic fit. * Partner closely with business leaders and lead IT team to deliver technology and security capabilities that advance the Bank' strategic priorities and enhance service. Oversee enterprise IT operations-including infrastructure, cloud platforms (Microsoft Azure), networks, applications, vendor management, and end-user support-with an unwavering focus on reliability, scalability, and service quality. Cybersecurity Program Leadership * Own and continuously mature the Bank's enterprise information security program-including policies, standards, procedures, and controls-proactively staying ahead of an evolving threat landscape. * Direct cybersecurity risk management-identification, assessment, mitigation, and executive reporting-in close partnership with the EVP, Chief Risk Officer, ensuring cyber risk is managed within the Bank's defined risk appetite. * Serve as the executive commander during cybersecurity incidents-leading response, communications, and recovery with speed, clarity, and composure. * Lead security operations including threat detection, vulnerability management, incident response, identity and access management (IAM), and disaster recovery. Regulatory Compliance & Risk Governance * Ensure full compliance with applicable regulatory and legal requirements including FFIEC, OCC, Dodd-Frank, SOX, and PCI-DSS-proactively mitigating regulatory risk and advancing the programs. * Establish governance frameworks for data management, privacy, access control, and information protection that are built for scale and aligned with the Bank's strategy. * Direct swift, thorough remediation of audit and assessment findings, and manage third-party and vendor security assessments with the same rigor applied to internal controls. * Partner with Audit and Risk on enterprise cybersecurity awareness, training programs, and New Hire Security onboarding-building a culture in which compliance is understood as everyone's responsibility. Business Continuity & Operational Resilience * Develop, maintain, and regularly test business continuity and disaster recovery plans that reflect the Bank's evolving infrastructure and risk environment. * Manage enterprise technology budgets and cybersecurity investments with financial discipline, ensuring strategic vendor relationships and contract negotiations deliver maximum value. * Define and track KPIs and security metrics that provide meaningful visibility into technology performance and security posture-translating data into actionable intelligence for executive and board audiences. Executive Communication & Board Engagement * Deliver high-impact technology and cybersecurity reporting to the CEO, executive leadership team, and the Board-including the Board's technology, product, and risk committees-translating complex technical realities into clear business context and strategic direction. * Serve as a visible and credible external voice for TCM Bank's technology capabilities and security posture-instilling confidence in community banking partners, regulators, and auditors alike. * Build cross-functional relationships across the enterprise that firmly position technology and security as strategic business enablers-not gatekeepers or cost centers. People Leadership & Culture * Build and lead a high-performing technology organization-effectively managing a hybrid ecosystem of in-house talent and strategic outsourced vendor partnerships, ensuring the team is structured, skilled, and motivated to execute at the pace the Bank's transformation demands. * Develop talent pipelines, succession plans, and career pathways within the technology organization-attracting and retaining top-tier professionals in a competitive market. * Model inclusive, accountable leadership and champion a culture of continuous improvement in which security awareness and innovation are shared responsibilities across every level of the enterprise. * Perform other related duties as required. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Engineering/Manager Pendulum: Generating compound interest on your career](https://www.wearedevelopers.com/videos/100348-engineering-manager-pendulum-generating-compound-interest-on-your-career) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence)