AVP Information Security Strategy (Banking)

ACG Resources
New York, NY, United States
3 days ago
Apply on www.acgresources.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Compensation
$65,000.0 - $150,000.0
Working hours
Regular working hours

Tech stack

Cyber Security Information Security Management Information Technology ISO/IEC 27002

Job description

Governance

  • Establish and maintain Information Security policies and procedures
  • Ensure CISO roles and responsibilities are clearly delineated and documented to ensure efficiency, create synergies and ensure TISR is being properly managed across first and second lines

Stragtegy & Programs

  • Coordinate Information Security strategy in alignment with the Bank’s strategy
  • Maintain strategic initiatives tracking and associated KRIs to track progress and execution of the objectives
  • Conduct quarterly strategy reviews with the CISO team to ensure alignment and momentum continue. Adjust strategy as necessary

Risk & Compliance

  • Establish and enhance a TISR framework that consists of the appropriate components to effectively manage TISR
  • Conduct risk assessments of TISR for Projects, Third-Party, New Activities and Applications
  • Prepare response evidence for IT/IS related regulatory exams
  • Recommend changes to policy, process or procedures to align with OCC and other federal guidelines and regulations

Metrics & Reporting

  • Manage all metrics and reporting for CISO

Requirements

  • Bachelor’s degree in Business, Computer Science, Management Information Systems, Engineering, Mathematics, or related field is required
  • Minimum 5 years of work experience in Financial services Risk Management, Audit, IT/IS Operations, or other relevant functions
  • Minimum 3 years of experience in developing and executing IT/IS Risk programs, projects, and policies
  • Minimum 1 year of experience working with US Banking Regulations, financial industry standards, and industry standard IT/IS Risk Frameworks
  • Strong program, frameworks, project management development, implementation, and maintenance skills
  • Sound and practical IT/IS risk management and program knowledge
  • Familiarity with IT/IS Risk Management regulations, standards, and frameworks including NIST, ISO27002, FFIEC Guidelines, etc.
  • CISSP/CRISC/ or IT related certifications preferred

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.acgresources.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

42 sec

Energy forecasts and resource demands of information technology

Marjolein Pordon · LIVE

2:39 min

Navigating strict environments for enterprise banking

Lea Fragner · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

5:12 min

Implementing automated DevSecOps governance in banking software

Aarno Aukia · LIVE

2:46 min

Missing equipment retrieval processes for departing employees

Jasmin Azemović Jasmin Azemović · World Congress 2026 Europe

Videos

See all

Related articles

See all