> Markdown version of [/jobs/ext/997238-vp-information-security-risk-officer-isro](https://www.wearedevelopers.com/jobs/ext/997238-vp-information-security-risk-officer-isro). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # VP, Information Security Risk Officer (ISRO) - **Company:** Hudson - **Location:** Houston, TX, United States - **Experience:** Expert - **Salary:** $150,000.0 - $180,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Disaster Recovery, Information Security Management, Information Technology Audit, IT Management, Information Technology - **Published:** June 17, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=11c6b2b79f56859f ## About the Role Do you have experience in Vendor relationship management?, Do you have a Bachelor's degree?, 10+ years of Information Security, Cybersecurity, IT Risk, Compliance, or IT Leadership experience. Financial Services, Banking, Wealth Management, Trust Company, or related regulated industry experience. Experience leading IT Risk Management and Information Security programs. Strong knowledge of FFIEC regulations and examination requirements. Experience with GLBA, NIST, ISO 27001, SOC 2, and cybersecurity frameworks. Experience managing regulatory audits and examinations. Experience developing IT governance policies and procedures. Experience with business continuity, disaster recovery, and incident response programs. Strong vendor risk management experience. Executive-level communication and leadership experience. Preferred Qualifications CISSP Certification CISM Certification CCISO Certification Bachelor's Degree in Information Systems, Cybersecurity, Computer Science, Business Administration, or related field ## Description Seeking a senior Information Security Risk Officer (ISRO) to lead enterprise cybersecurity, IT governance, risk management, regulatory compliance, vendor management, and digital transformation initiatives within a financial services environment., Information Security & Technology Leadership Lead enterprise information security and technology strategy. Oversee cybersecurity posture, IT governance, and risk management programs. Align technology initiatives with business objectives. Lead technology steering committees and strategic planning efforts. Present technology and risk updates to executive leadership and boards. Risk Management & Compliance Serve as the primary contact for IT audits, regulatory examinations, and compliance reviews. Ensure compliance with FFIEC, GLBA, NIST, ISO 27001, SOC 2, and related regulatory frameworks. Monitor evolving cybersecurity and banking regulations. Manage risk assessments, control testing, and remediation efforts. Lead incident response, disaster recovery, and business continuity initiatives. Policy & Governance Develop, maintain, and review IT policies, procedures, standards, and governance frameworks. Translate regulatory requirements into internal controls and policies. Maintain risk and control documentation, process maps, and governance records. Lead periodic policy reviews and updates. Vendor & Operational Oversight Oversee technology vendors and managed service providers. Conduct vendor due diligence, risk assessments, and contract reviews. Evaluate security risks associated with new business initiatives. Ensure effective IT operational controls and documentation. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Convincing Product teams to Adopt Gitops in a Large Org](https://www.wearedevelopers.com/videos/1936-convincing-product-teams-to-adopt-gitops-in-a-large-org) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [How should you format your IT resume?](https://www.wearedevelopers.com/magazine/68-how-should-you-format-your-it-resume) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)