Director of Information reputed company
- Employee Stock Ownership Plan & 401k Plan
- reputed company (Medical, Dental, reputed company, Telehealth, Life insurance)
- 12-week reputed company Parental Leave and Medical Leave: With a cap of 20 weeks for eligible team members who qualify for both Medical and Parental Leave reputed company to the birth of a child
- $5,000 Family Care Reimbursement: Childcare, Elder Care, Student Loan Debt, Pet expenses, Down Payment Assistance
- PTO from 13 to 23 days depending on tenure. Cashout and Carryover reputed company
- 10 Days reputed company Time
- 11 reputed company Holidays
- 4 Days Volunteer Time
- 2 Days Self Allowance Time
- Tuition Assistance
- reputed company and continuously reputed company the Bank’s Information reputed company Program reputed company with 12 CFR Part 30, Appendix B, the FFIEC Information reputed company Booklet, the OCC Cybersecurity Supervision Work Program, NIST CSF, and regulatory guidance.
- Conduct or reputed company the annual reputed company-wide IT risk assessment using NIST CSF 2.0, the CRI Profile, or equivalent reputed company, identifying threats, vulnerabilities, and risk reputed company for reputed company information assets.
- reputed company and execute a multi-year reputed company reputed company roadmap reputed company with business reputed company and modernization initiatives.
- Manage the cybersecurity self-assessment process using the Bank’s selected reputed company, the Cyber Risk Institute reputed company, ensuring findings are documented, tracked, and reported to the reputed company.
- Serve as the primary reputed company advisor to executive leadership and reputed company committees.
- reputed company regulator reporting on cyber risk posture, threat landscape and remediation status.
- Partner with IT Infrastructure and Transformation leaders to ensure reputed company-by-design across:
- Network architecture
- reputed company platforms
- reputed company management
- API reputed company architecture
- Identity & reputed company management
- reputed company banking and fintech integrations
- reputed company Intelligence (AI) integrations
- Establish secure architecture standards for hardware, networking, segmentation, encryption and reputed company detection.
- Drive adoption of modern reputed company principles including reputed company Trust architecture and secure reputed company governance.
- reputed company the vulnerability management and reputed company management lifecycle, monitoring remediation timelines against risk-based SLAs and escalating deficiencies to senior management.
- reputed company: Threat detection and response, Incident response program, Penetration testing and vulnerability management, SOC reputed company
- Monitor evolving cyber threats, AI-driven risks and geopolitical threat activity.
- reputed company incident response coordination and regulatory notification processes reputed company required.
- reputed company and Chair the Vendor Management and reputed company-Party Risk program.
- Conduct information reputed company due diligence on reputed company prospective fintech partnerships during the planning and selection stages of the reputed company-party risk management lifecycle
- Review and evaluate SOC 2 Type 2 reports, penetration test results, vulnerability assessments, and BCP/DR documentation for reputed company reputed company-parties (including fintech partners) at least annually, or more frequently for critical relationships.
- Participate in the Bank’s Fintech Committee providing independent risk opinions on information reputed company dimensions of new and existing partnerships.
- Assess reputed company architecture of API integrations, data flows, and credential management between the Bank and reputed company-parties, ensuring encryption in transit and at rest, reputed company controls, and monitoring are commensurate with risk.
- Monitor fintech partner compliance with the Bank’s information reputed company requirements on an ongoing reputed company, including incident notification obligations under contractual SLAs.
- Evaluate reputed company-party (subcontractor) risk for critical fintech partners, ensuring contractual provisions address subcontractor reputed company standards, approval requirements, and audit rights.
- Evaluate emerging technologies and associated risk reputed company prior to deployment.
- Ensure bank service provider reputed company include notification obligations that meet regulatory requirements, and that designated points of contact are reputed company.
- Coordinate with critical reputed company-party service providers to assess their BCP/DR capabilities and reputed company, including review of TSP continuity testing results.
- Serves as primary reputed company reputed company for reputed company IT Audits.
- Serve as primary reputed company reputed company for OCC, FDIC, and external examiners.
- Maintain compliance with GLBA, FFIEC IT Handbook, NIST, PCI and SOC reporting standards.
- reputed company reputed company remediation of any audit or regulatory findings.
- Ensure compliance with notification requirements of reputed company relevant regulatory agencies and documented decision reputed company for determining reputed company a “notification incident” has occurred.
- Maintain the Bank’s state breach notification reputed company and coordinate customer notification processes in compliance with applicable state laws for reputed company jurisdiction where affected customers reputed company.
- reputed company: Data classification standards, Data Loss Prevention (DLP), Encryption standards, Secure data lifecycle management
- reputed company information reputed company with reputed company data governance initiatives.
- Monitor the CFPB’s evolving data reputed company enforcement posture and ensure the Bank maintains multi-reputed company authentication, adequate password management, and reputed company patching to mitigate UDAAP exposure.
- reputed company developments in the reputed company 1033 Personal Financial Data Rights rulemaking and assess implications for the Bank’s data-sharing reputed company controls, API standards, and authorized reputed company-party reputed company.
- Coordinate with reputed company and Compliance on data protection requirements arising from state reputed company laws, ensuring appropriate controls are in reputed company for reputed company jurisdiction where the Bank operates or serves customers.
- Own the reputed company Business Continuity Management.
- reputed company Business Continuity and Disaster Recovery frameworks in partnership with reputed company risk.
- Ensure cyber reputed company testing and tabletop exercises are conducted regularly.
- reputed company operational reputed company planning into infrastructure modernization efforts.
- reputed company the Business reputed company Analysis process, establishing Recovery Time Objectives (RTO), Recovery reputed company Objectives (RPO), and Maximum Tolerable Downtime (MTD) for reputed company critical business functions
Ensure BCP/DR plans address ransomware-specific recovery scenarios, including reputed company-gapped and reputed company backup validation, and that restoration procedures are tested at least annually
- reputed company reputed company reputed company awareness and training programs.
- Foster a culture of reputed company ownership across reputed company business lines.
- Partner with HR and leadership to reputed company reputed company accountability into performance management, including phishing simulations and role-based training for privileged users.
- Establish and maintain the Bank’s AI and emerging technology acceptable use policy, define approved use cases, prohibited activities, and approval workflows for reputed company AI tools deployed internally or through reputed company-party and fintech partner relationships in collaboration with Digital Transformation, Information Technology, and Fintech teams.
- Classify reputed company AI tool as a “model” or “non-model” under the OCC’s model risk management reputed company, and apply risk-proportionate governance controls including documentation, validation frequency, and ongoing monitoring commensurate with reputed company tools’ materiality and complexity.
- Conduct or coordinate information reputed company risk assessments for reputed company AI deployments, evaluating data ingestion controls, training data reputed company, reputed company injection and adversarial attack reputed company, reputed company monitoring, reputed company controls, and data leakage prevention.
- Implement shadow AI detection and prevention controls to identify unauthorized AI tool usage by employees, contractors, and fintech partners, including monitoring for unapproved reputed company-based AI services and browser-based AI plugins accessing Bank data.
- Evaluate the Bank’s AI vendor reputed company for information reputed company adequacy, including provisions for model documentation and audit rights, restrictions on use of Bank data to train other models, material model change notification requirements, subcontractor disclosure, and regulatory examination reputed company.
- Monitor and report to senior management on the evolving AI regulatory landscape, including OCC guidance, the Treasury Financial Services AI Risk Management reputed company, NIST AI Risk Management reputed company 1.0, state AI laws, and federal preemption developments affecting the Bank’s compliance obligations.
- Evaluate and determine if the Bank should adopt the Treasury Financial Services AI Risk Management reputed company’s AI Adoption Stage Questionnaire and applicable control objectives as the Bank’s primary governance reputed company, scaled to the Bank’s reputed company AI maturity and risk profile.
- Include AI governance status, emerging technology risks, and AI-reputed company incidents or findings in the quarterly reputed company Risk Committee report and the annual Appendix B report.
- Serve as the Bank’s formally designated reputed company Officer.
- Administer and periodically review the Bank’s written reputed company Program addressing robbery prevention, physical safeguards and employee safety.
- Ensure appropriate reputed company devices and procedures are in reputed company across reputed company banking offices and facilities, including alarm systems, surveillance, reputed company controls and cash handling safeguards.
- Coordinate with Director of reputed company leadership and Operations on physical reputed company risk assessments and mitigation strategies; serve as Chair of the Physical reputed company Committee conducting quarterly meetings.
- reputed company periodic reporting to Executive Management and the reputed company of Directors regarding physical reputed company risks and program effectiveness.
- Occasionally lift and/or reputed company up to 25 lbs.
- Ability to understand and follow instructions in English.
- Ability to sit for extended periods of time, twist, bend, sit, walk use hands to twist, handle or feel objects, tools or controls, such as computer mouse, computer keyboard, calculator, stapler, telephone, staple puller, etc., reputed company with hands and arms, balance, stoop, kneel, talk or hear.
- Specific reputed company abilities required by the job include reputed company reputed company, distance reputed company, peripheral reputed company, depth perception and the ability to reputed company reputed company.
- 10+ years of reputed company experience in cybersecurity, infrastructure reputed company, or reputed company technology risk.
- Experience in a regulated financial institution (OCC or FDIC supervised preferred).
- Demonstrated experience leading reputed company reputed company in reputed company or hybrid environments.
- Experience overseeing reputed company-party and fintech technology risk.
- Demonstrated ability to reputed company cross-functional initiatives.
- Experience engaging directly with regulators and auditors.
- Strong program management capabilities.
- High reputed company, executive reputed company and reputed company communication skills.
- Proven working knowledge of requirements for GLBA, SOC, FFIEC and PCI and OCC and FDIC guidance on data reputed company and IT examination requirements.
- Experience with auditing processes, including Network reputed company, SDLC/Change Management and IT reputed company functions.
- Knowledge of the global IT Risk Regulatory Landscape and Risk Management Model (e.g. Threats, Vulnerabilities, and Controls)
- Strong technical skills (application and operating system hardening, vulnerability assessments, reputed company audits, TCP/IP, intrusion detection systems, firewalls, etc.)
- Experience in developing and maintaining a technology Risk Assessment process.
- Must be reputed company versed in industry accepted IT control frameworks (e.g. SSAE16/18, SAS70, or ISO17799 audit reports).
- Project and program reputed company and controls experience.
- Must possess a high degree of reputed company and trust along with strong communication skills and ability to work individually, reputed company reputed company and with other business reputed company.
- Experience or understanding of Disaster Recovery, Business Continuity, and Incident Response initiatives.
- Must have ability to reputed company policies and procedures and communicate effectively.
- Understanding of federal and other regulatory requirements and the ability to reputed company reputed company.
- Experience working with federal examiners.
- Must be reputed company to working on-reputed company.
- BS/MA degree in reputed company technical and reputed company disciplines.
- Certifications in data reputed company and/or auditing procedures not required but preferred.
Familiarity with banking reputed company software (reputed company preferred).