Director, Information Security

University Federal Credit Union
Austin, TX, United States
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Cloud Computing Cyber Security Information Systems Disaster Recovery Identity and Access Management Software Vulnerability Management Information Technology

Job description

Experteer Overview As Director of Information Security, you will lead UFCU’s enterprise cyber risk program and shape security strategy to enable secure innovation. You will partner with senior leaders to align security priorities with business goals, risk tolerance, and regulatory expectations. You will serve as a trusted advisor to executives and the Board, fostering a member-first, security-by-design culture. Based in Austin, you’ll drive cross-functional collaboration and operational resilience at scale. Compensation / Benefits * Define and own the enterprise information security and cyber risk strategy, roadmap, and policies aligned with business aims and regulatory expectations * Oversee design, implementation, and operation of a comprehensive security program (governance, architecture, infrastructure, cloud, IAM, vulnerability management, SOC) * Embed security-by-design into digital banking and member-facing platforms in collaboration with Technology, Product, and Risk teams * Establish and maintain information security governance standards and leadership forums; ensure regulatory and industry framework compliance * Lead risk assessments, audits, remediation, and sustained closure of findings * Manage continuity, disaster recovery, cyber resilience, and enterprise operational resilience initiatives * Oversee day-to-day security operations, incident response, and crisis management with executive reporting * Lead third-party risk management and data protection efforts in collaboration with Legal and Data teams * Build and develop a high-performing security organization across Governance, Risk, Compliance, Engineering, Architecture, and Operations * Collaborate across technology, risk, and business units to balance security with experience and innovation * Translate technical risk into clear business impact and investment decisions for executives and the Board * Develop and monitor information security budgets and resource planning * Participate in strategic planning to drive department and organizational goals Tasks * Bachelor’s degree in Information Security, Computer Science, Information Systems, Engineering, Business, or equivalent * Minimum 10 years of information security/tech experience * Minimum 7 years of management and supervisory leadership experience * 5-7+ years leading cybersecurity teams with strategy, budget, and vendor management * Senior security leadership experience in financial services or regulated environments * Experience supporting regulatory examinations and remediation activities * Relevant industry certifications (CISSP, CISM, CISA, CRISC, GIAC or equivalent) Key requirements *

Requirements

  • to drive department and organizational goals Tasks * Bachelor’s degree in Information Security, Computer Science, Information Systems, Engineering, Business, or equivalent * Minimum 10 years of information security/tech experience * Minimum 7 years of management and supervisory leadership experience * 5-7+ years leading cybersecurity teams with strategy, budget, and vendor management * Senior security leadership experience in financial services or regulated environments * Experience supporting regulatory examinations and remediation activities * Relevant industry certifications (CISSP, CISM, CISA, CRISC, GIAC or equivalent) Key requirements *

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo · WWC 2024

2:14 min

Crafting an effective disaster recovery and communication plan

Mihaela-Roxana Ghidersa · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all