VP, Information Security Risk Officer (ISRO)

Hudson
Houston, TX, United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Compensation
$150,000.0 - $180,000.0
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Information Systems Disaster Recovery Information Security Management Information Technology Audit IT Management Information Technology

Job description

Seeking a senior Information Security Risk Officer (ISRO) to lead enterprise cybersecurity, IT governance, risk management, regulatory compliance, vendor management, and digital transformation initiatives within a financial services environment., Information Security & Technology Leadership

Lead enterprise information security and technology strategy.

Oversee cybersecurity posture, IT governance, and risk management programs.

Align technology initiatives with business objectives.

Lead technology steering committees and strategic planning efforts.

Present technology and risk updates to executive leadership and boards.

Risk Management & Compliance

Serve as the primary contact for IT audits, regulatory examinations, and compliance reviews.

Ensure compliance with FFIEC, GLBA, NIST, ISO 27001, SOC 2, and related regulatory frameworks.

Monitor evolving cybersecurity and banking regulations.

Manage risk assessments, control testing, and remediation efforts.

Lead incident response, disaster recovery, and business continuity initiatives.

Policy & Governance

Develop, maintain, and review IT policies, procedures, standards, and governance frameworks.

Translate regulatory requirements into internal controls and policies.

Maintain risk and control documentation, process maps, and governance records.

Lead periodic policy reviews and updates.

Vendor & Operational Oversight

Oversee technology vendors and managed service providers.

Conduct vendor due diligence, risk assessments, and contract reviews.

Evaluate security risks associated with new business initiatives.

Ensure effective IT operational controls and documentation.

Requirements

Do you have experience in Vendor relationship management?, Do you have a Bachelor’s degree?, 10+ years of Information Security, Cybersecurity, IT Risk, Compliance, or IT Leadership experience.

Financial Services, Banking, Wealth Management, Trust Company, or related regulated industry experience.

Experience leading IT Risk Management and Information Security programs.

Strong knowledge of FFIEC regulations and examination requirements.

Experience with GLBA, NIST, ISO 27001, SOC 2, and cybersecurity frameworks.

Experience managing regulatory audits and examinations.

Experience developing IT governance policies and procedures.

Experience with business continuity, disaster recovery, and incident response programs.

Strong vendor risk management experience.

Executive-level communication and leadership experience.

Preferred Qualifications

CISSP Certification

CISM Certification

CCISO Certification

Bachelor’s Degree in Information Systems, Cybersecurity, Computer Science, Business Administration, or related field

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:53 min

Managing infrastructure limitations with managed Amazon Aurora databases

Dharin Shah Dharin Shah · WWC 2025

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

2:14 min

Crafting an effective disaster recovery and communication plan

Mihaela-Roxana Ghidersa · LIVE

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

5:00 min

Managing complex state with scope-based resource management

Bjarne Stroustrup · WWC 2022

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · WWC Europe 2026

Videos

See all

Related articles

See all