> Markdown version of [/jobs/ext/3030259-information-security-officer](https://www.wearedevelopers.com/jobs/ext/3030259-information-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Officer - **Company:** HawaiiUSA Federal Credit Union - **Location:** United States - **Experience:** Experienced - **Salary:** $110,667.0 - $150,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Software as a Service, Cloud Computing, Cloud Computing Security, Configuration Management, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Information Systems, Disaster Recovery, Identity and Access Management, Information Security Management, Information Systems Security Architecture Professional, Microsoft Security Essentials, Phishing, Data Streaming, Software Vulnerability Management, Data Logging, Cyber Threat Analysis, Information Technology, Performance Monitor, Patch Management - **Published:** September 22, 2026 - **Apply:** https://www.thejobnetwork.com/job/f7aa5b72-3147-4910-874c-7f471334bcc5/information-security-officer ## About the Role * ISO Standards * Presentations * Access Management Governance * Incident Response and Cyber Resilience * Regulatory Examination and Audit Management * Executive and Board Reporting * Control Objectives for Information and Related Technologies (COBIT) * Security Technologies and Architecture * Risk Management Frameworks * Attention to Detail * Continuous Learning * Facilitation * Vendor Management * Identity Management Governance * Cloud and SaaS Security, * 7+ years of progressively responsible experience in information security, cybersecurity, technology risk, information security governance, or a related discipline, with financial-services experience strongly preferred and credit-union experience highly desirable. * Working knowledge of NCUA Part 748, GLBA, FFIEC guidance, and the ACET, NIST or equivalent framework. * Three plus years in a leadership or supervisory capacity within information security, IT risk, or a related discipline required (e.g., team lead, security manager, or comparable supervisory role) recommended. * Experience building or scaling an internal information security function, including staffing and organizational design, strongly preferred. * Experience working within an enterprise risk management framework preferred. * CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager) or equivalent senior information security certification required, CISSP and CISM combination preferred. * CRISC (Certified in Risk and Information Systems Control) preferred. * CISA (Certified Information Systems Auditor) preferred. * GIAC (Global Information Assurance) / GSEC (GIAC Security Essentials) certifications preferred. * CCSK (Certificate of Cloud Security Knowledge) /CCSP (Certified Cloud Security Professional) preferred. * CGRC (Certified in Governance, Risk and Compliance) preferred. * Computer Science (Bachelor's degree) or Information Security (Bachelor's degree) or Information Technology (Bachelor's degree) or equivalent experience. ## Description The Information Security Officer (ISO) owns and is accountable for the credit union's written Information Security Program (ISP), ensuring compliance with NCUA regulations (12 CFR Part 748), the GLBA Safeguards Rule, and applicable federal and state cybersecurity requirements. The ISO works in partnership with the credit union's outsourced CISO partner (OneStep), the Information Security Governance Committee, and IT Security to direct the program's execution, while retaining ultimate accountability to the Board, the VP of Enterprise Risk Management, and NCUA examiners. The ISO also partners with the VP of ERM to lead the credit union's transition toward an internal information security department. The ISO provides independent oversight and challenge of information security and establishes information security governance and risk requirements., * Own and maintain the written Information Security Program (ISP), incorporating guidance from OneStep and the Information Security Governance Committee, with accountability for the program's adequacy to the Board, VP of ERM, and NCUA examiners. * Conduct annual risk assessments of information systems, third-party vendors, and data flows. * Oversee the incident response plan (IRP), including compliance with the NCUA 72-hour cyber incident notification rule. * Direct vulnerability management, penetration testing, and patch management programs, coordinating execution across external IS consultants and IT Security. * Lead vendor/third-party risk management for cloud, core processor, and fintech relationships, including ongoing due diligence and performance monitoring of OneStep as a critical vendor. * Align business continuity/disaster recovery planning with information security controls. * Deliver information security awareness training and phishing simulation programs to staff and the Board. * Serve as primary point of contact for NCUA/state examiners on IT and cybersecurity exams, including the ACET (Automated Cybersecurity Examination Tool) process. * Serve as the credit union's primary internal liaison to the outsourced CISO (external consultant), translating security guidance and recommendations into internal policy, procedures, and Board reporting. * Serve as an active member of the Information Security Governance Committee, coordinating between external consultant's CISO recommendations and internal execution via IT Security. * Partner with the VP of Enterprise Risk Management to lead the transition from outsourced information security support (external consultant) to an internal information security department, including org design, staffing plan, and phased capability build-out. * Collaborate with the VP of ERM on decisions regarding which functions remain outsourced to external consultant versus insourced as the department matures. * Integrate information security risk into the enterprise risk register and ERM reporting cycle, in coordination with the VP of Enterprise Risk Management. * Ensure escalation to the Board/Risk Committee is preserved: ISP updates and material risk findings are escalated through the VP of ERM for inclusion in Board/Risk Committee reporting at least annually, with direct Board access maintained for significant incidents or unresolved risk disagreements. * Establish Information Security requirements for cloud, SaaS hosted, and externally managed environments, including identity, encryption, logging, configuration management, data protection, and third-party connectivity. * Monitor cybersecurity threats, vulnerabilities, regulatory alerts, financial-sector threat intelligence, and emerging technology risks, and assess their relevance and potential impact to the credit union. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [MFA? Game over! Watch your protection collapse – live](https://www.wearedevelopers.com/videos/100322-mfa-game-over-watch-your-protection-collapse-live) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [11 Best Practices For PHP Security](https://www.wearedevelopers.com/magazine/90-11-best-practices-for-php-security) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)