> Markdown version of [/jobs/ext/3224298-svp-chief-information-security-officer](https://www.wearedevelopers.com/jobs/ext/3224298-svp-chief-information-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SVP/Chief Information Security Officer - **Company:** FourLeaf Federal Credit Union - **Location:** Bethpage, NY, United States - **Experience:** Expert - **Salary:** $300,000.0 - $330,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Word, Microsoft Excel, Software System Penetration Testing, Microsoft Outlook, Cloud Computing Security, Cyber Security, Information Systems, Information Systems Security Architecture Professional, Microsoft Office, Microsoft PowerPoint, Security Information and Event Management, Software Vulnerability Management, Cyber Threat Analysis, Information Technology, Vulnerability Analysis - **Published:** September 10, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=69b5290378f77ad7 ## About the Role * Bachelor's Degree required; Master's degree preferred. * 12+ years of progressive information security, cybersecurity, risk management, or technology leadership experience. * 5+ years in a senior leadership role overseeing enterprise cybersecurity programs * Demonstrated experience managing security operations, incident response, vulnerability management, governance, risk, and compliance programs. * Experience overseeing third-party cyber risk and vendor security assessment programs * Certifications: Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC), Certified Cloud Security Professional (CCSP), Certified Ethical Hacker (CEH) or equivalent are all preferred. * Computer Skills: Microsoft Office (Excel, Word, PowerPoint, Outlook, Teams), Security Information and Event Management (SIEM) Tools, Vulnerability Management Tools, Threat Intelligence Platforms, Identity & Access Management (IAM) Solutions, Cloud Security Platforms, Governance Risk & Compliance (GRC) Systems, Security Monitoring & Incident Response Tools. ## Description The Senior Vice President (SVP)/Chief Information Security Officer (CISO) is responsible for establishing, executing, and continuously enhancing the Credit Union's enterprise-wide information security and cybersecurity program. The SVP/CISO provides strategic leadership and governance over information security, cyber risk management, threat intelligence, incident response, vulnerability management, third-party technology risk, and regulatory compliance. Working in close partnership with Second Line of Defense (2LOD) Risk Management and Compliance functions, the CISO ensures the Credit Union maintains a strong security posture that protects member information, critical business operations, and technology assets while enabling business growth and innovation. Core Contributions * Information Security Strategy & Governance + Develop, implement, and maintain the Credit Union's enterprise information security strategy, framework, policies, and standards. + Implement and enforce enterprise security policies, procedures, and standards jointly developed with Second Line of Defense (2LOD) Risk Management and Compliance teams. + Ensure alignment of security practices with applicable regulatory requirements, industry standards, and Credit Union business objectives. + Provide regular reporting to executive management, Board committees, and regulators regarding cybersecurity risk, security posture, emerging threats, and remediation activities. + Establish and maintain information security governance processes, metrics, and key risk indicators. * Cybersecurity Operations + Lead the Credit Union's cybersecurity operations program, ensuring effective protection of information assets and infrastructure. + Oversee enterprise threat detection, threat intelligence, security monitoring, incident response, and vulnerability management activities. + Ensure timely response to security events and coordinate communication, recovery, and post-incident reviews. + Oversee penetration testing, vulnerability assessments, security monitoring tools, and remediation programs. * Third-Party & Vendor Cyber Risk Management + Own and manage the cybersecurity vendor risk assessment process for third-party service providers, fintech partners, and technology vendors. + Evaluate and monitor the security posture of third-party technology relationships throughout the vendor lifecycle. + Collaborate with Procurement, Legal, Information Technology, and Risk Management to ensure appropriate cybersecurity due diligence and contractual protections. + Review vendor security controls, independent audit reports, penetration test results, and other security attestations. + Ensure ongoing monitoring and remediation of identified vendor security risks. * Risk Management & Compliance + Partner with 2LOD teams to identify, assess, monitor, and mitigate information security and cyber risks. + Support enterprise risk management initiatives by providing subject matter expertise on cyber and technology risks. + Ensure compliance with NCUA guidance, FFIEC cybersecurity expectations, GLBA, state privacy requirements, and other applicable regulatory standards. + Track and report remediation of audit findings and risk issues. * Leadership & Collaboration + Provide leadership and direction to information security personnel and external security partners. + Foster a culture of cybersecurity awareness and accountability across the organization. + Collaborate with Information Technology, Operations, Digital Banking, Enterprise Risk, Compliance, Internal Audit, and business line leaders to integrate security into business processes and technology initiatives. + Advise senior management on security implications of strategic initiatives, digital transformation efforts, and emerging technologies. + Oversee security awareness education and training programs for employees and stakeholders. ## Related Videos - [Developing the Rich Text Editor for DeepL.com](https://www.wearedevelopers.com/videos/1172-developing-the-rich-text-editor-for-deepl-com) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [In-depth .NET Azure Functions: Isolated mode, performance and durable AI agents](https://www.wearedevelopers.com/videos/100207-in-depth-net-azure-functions-isolated-mode-performance-and-durable-ai-agents) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)