> Markdown version of [/jobs/ext/1459174-chief-information-security-office-strategy-programs-grc-avp](https://www.wearedevelopers.com/jobs/ext/1459174-chief-information-security-office-strategy-programs-grc-avp). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Chief Information Security Office-Strategy, Programs & GRC AVP - **Company:** Bank of China Limited, New York Branch - **Location:** New York, NY, United States - **Experience:** Expert - **Salary:** $65,000.0 - $150,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Identity and Access Management, Information Security Management, Phishing, IAd (Apple'S Advertising Platform), Information Technology, ISO/IEC 27002 - **Published:** July 27, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=537f37a66e9649fb ## About the Role * Bachelor's Degree in Business, Risk, Data, Computer Science, Management Information Systems, Engineering, Mathematics, or related field * Minimum 5 years of work experience in Risk Management, Audit, IT/IS Operations, or other relevant functions * Minimum 3 years of experience in developing and executing IT/IS Risk programs, projects, and policies * Minimum 1 year of experience working with US Banking Regulations, financial industry standards, and industry standard IT/IS Risk Frameworks * Strong program, frameworks, project management development, implementation, and maintenance skills * Strong writing skills, especially in the context of governing documents, such as policies and standards * Strong verbal and interpersonal skills when working with a diverse group of stakeholders that can include senior management, business staff, and technical staff * Creative problem-solving skills * Strong organizational understanding and ability to navigate complex organizations * Results oriented and metrics driven * Understanding of financial services business and related processes and IT/IS risks and how to mitigate with well-designed, commercially sound controls * Operational and IT/IS risk assessment and management skills in first, second, and/or third line capacity * Sound and practical IT/IS risk management and program knowledge * Financial / banking industry, business line, and product knowledge * Familiarity with IT/IS Risk Management regulations, standards, and frameworks including NIST, ISO27002, FFIEC Guidelines, etc. * Risk identification and assessments of different types that are commensurate with the size and complexity of the financial institution * IT/IS risk management and audit principles and industry standard practices * CISSP/CRISC/ or IT related certifications preferred ## Description Strategy * Coordinate Information Security strategy in alignment with the BOCNY branch strategy. * Maintain strategic initiatives tracking and associated KRIs to track progress and execution of the objectives. * Conduct quarterly strategy reviews with the CISO team to ensure alignment and momentum continue. Adjust strategy as necessary. * Provide end-to-end project management function for all CISO led projects. Programs * Manage all CISO programs, including but not limited to: Information Security Program, Data Privacy Program, and Training & Culture Program including Security Training, Phishing Campaigns, and Tabletop Exercises. Governance * Establish and maintain Information Security policies and procedures. * Ensure CISO roles and responsibilities are clearly delineated and documented to ensure efficiency, create synergies and ensure TISR is being properly managed across first and second lines. * Periodically refresh and update TISR controls guidance in relevant policies and supporting procedures with detailed implementation guidance. * Develop, monitor, and track CISO policy adherence measures and metrics. * Provide all administrative functions for the Information Security Committee and all its sub-committees. Risk * Establish and enhance a TISR framework that consists of the appropriate components to effectively manage TISR. * Conduct risk assessments of TISR for Projects, Third-Party, New Activities and Applications. * Develop and execute an TISR annual work plan of risk identification, assessment, and control evaluation and testing activities. * Review and contribute to the development and maintenance of the taxonomy for Risk, Process and Controls for TISR domains. * Catalog and oversee remediation of TISR issues include those arising from Audit and Regulatory exams, ITRM deep dives, root cause analyses and control testing. * Track observed control gaps and root causes and annually refresh CISO policy and procedures to reflect new and enhanced controls. Compliance * Prepare and submit Audit Requests for evidence. * Anticipate audit requests and prepare comprehensive approach to for CISO policy and standards and associated implementation. * Prepare response evidence for IT/IS related regulatory exams. * Recommend changes to policy, process or procedures to align with OCC and other federal guidelines and regulations. * Evaluate and provide evidence of compliance for BOCNY Branch. * Liaison with LCD/RAO/IAD to ensure collaboration and partnership so that CISO can meet regulatory IT/IS requirements. Data Privacy * Develop and implement strategies to ensure compliance with relevant privacy laws and regulations. * Stay up-to-date with changes in data privacy legislation and industry best practices. * Assist in the development and maintenance of privacy policies, standards and procedures. * Provide oversight and monitoring of privacy risk assessments by the FLUs. * Ensure all relevant processes reflect privacy requirements and comply with laws and regulations. * Plan and implement privacy training programs and communications. * Identify and assess privacy risks within the organization. Metrics & Reporting * Manage all metrics and reporting for CISO, including: Operational, Executive & Board, Budget & Headcount, Dashboards. Identity & Access Management * Establish and periodically update policies, procedures, and guidelines related to access recertification, incorporating industry best practices. * Manage the end-to-end process of user access reviews, including planning, execution, tracking, and resolution of identified issues. * Conduct periodic User Recertification & Access Reviews throughout all BOC applications to ensure consistency and accuracy. * Collaborate with cross-functional teams, including IT, OSD, and business units, to align access governance with broader organizational goals. * Conduct periodic assessments of user access governance processes, identifying opportunities for improvement and implementing necessary enhancements. ## Related Videos - [Enterprise-Cloud-Native - Fast-Paced Development & Deployment in a Highly Secure Banking Environment](https://www.wearedevelopers.com/videos/671-enterprise-cloud-native-fast-paced-development-deployment-in-a-highly-secure-banking-environment) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Getting under the skin: The Social Engineering techniques](https://www.wearedevelopers.com/videos/38-getting-under-the-skin-the-social-engineering-techniques) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Data Analyst Salary in Switzerland](https://www.wearedevelopers.com/magazine/276-data-analyst-salary-in-switzerland) - [Software Developer Salary in Switzerland [2023]](https://www.wearedevelopers.com/magazine/215-software-developer-salary-in-switzerland-2023)