Position Function:The Application Security Program Manager is responsible for leading, governing, and continuously maturing the bank's application security, identity management, fraud-related technology risk, and emerging technology risk programs within the Information Security Program. This role establishes the strategic direction, operating model, standards, risk assessment methodology, reporting, and multi-year roadmap needed to identity, assess, govern, and reduce risk across application environments.
This position has enterprise scope spanning internally developed applications, third-party hosted solutions, identity platforms, access administration processes, and critical business technologies that support customer-facing and internal operations. This role serves as a senior risk and control leader who partners across Technology, Digital Banking, Fraud, Enterprise Risk, Compliance, Internal Audit, Vendor Management, and other business leadership to align security requirements with business objectives and regulatory expectations.
They will serve as the bank's senior Subject Matter Expert (SME) in areas related to application security controls, integrations, identity controls, fraud-enabling technology threats, and the security implications of emerging technologies. The role is accountable to lead risk assessments, defining treatment plans, overseeing control effectiveness, and reporting risk posture/key metrics, and advising on enterprise decisions.
The ideal candidate will have broad experience in technology, information security, risk management, securing applications, APIs, identity management, etc. They will work closely with the business and project teams to advocate security requirements to ensure applications and related security practices align with policies, standards, and best practices, while ensuring the security architecture and practices do not infringe on the needs of the business. The position requires taking initiative to research, resource, and be self-reliant when approaching projects and tasks, in addition to being an effective communicator.
They will be responsible for:
- Developing and maintaining information security risk management processes that are clear and understandable, workable, up-to-date, and reflect regulatory and CPB-specific requirements and issues.
- Assisting in communicating such processes throughout the business, including holding training sessions where appropriate.
- Assisting with the planning, coordination, implementation, and management of security measures that manage risks to systems. and data, to prevent unauthorized modification, destruction, or disclosure of information, including outsider service providers.
- Analyzing and appraising new products and/or systems for security weaknesses and provide measures to prevent exposure and loss.
Performs all duties and interacts with internal and external customers in a manner aligned with the Company's Core Values of Voyaging Spirit and Positively Ohana; Customer Experience Competencies of Customer Interaction, Empowerment and Ownership; and Basic Skills of Listening, Oral Communication, Written Communication, Action Orientated, Thoroughness, Problem Solving.
Primary Accountabilities:- Responsible for training staff on policies and standards related to application security and identity management best practices, and training staff on methodologies in conducting risk assessments related to this area.
- Reviews/delegates work related to the governance and oversight of controls related to application security and identity management.
- Leads and motivates a team to ensure high levels of engagement, performance, and productivity.
- Sets clear goals and expectations for team members and provides guidance on how to achieve them.
- Conducts regular performance reviews to assess individual progress and provide constructive feedback.
- Identifies skills gaps and provides opportunities for professional growth through training, mentorship, or cross-functional collaboration.
- Leads a risk-based application security review program to ensure appropriate security controls are designed, implemented, and operate effectively.
- Validating application and other reference architectures for security best practices, and recommending changes to enhance security and reduce risk where applicable.
- Overseeing application risk assessments and control reviews to identify weaknesses and drives remediation plans with accountable stakeholders
- Leads security risk evaluation for emerging technologies, new business initiatives, and material changes to the application and identity ecosystem.
- Conducting or facilitating threat modeling of services and applications that tie to the risk and data associated with the application or services.
- Delivers operational security duties to include, but not limited to:
- Providing strategic oversight for application security tooling, processes and service models to support scalable coverage, risk visibility, and business enablement.
- Conducting incident response exercises with colleagues throughout the organization and incorporating lessons-learned into existing security architectures and practices.
- Conducting forensic analysis of security-related incidents in a manner consistent with best practices and the organization's counsel.
- Other departmental duties and functions include, but not limited to:
- Performing risk analyses pertaining to the security needs of the bank and preparing recommendations based on risk/exposure versus cost. Prepares and presents research findings in written and/or oral form. Presents objectives, alternatives, risk analyses, and cost/benefit analyses.
- Assists with the planning and directing of information security activities of the bank to ensure compliance with internal/external audits, and to federal and State regulations, which include FDIC, relevant sections of the Gramm-Leach-Bliley Act (GLBA), and Sarbanes-Oxley Act Section 404 provisions, and other duties to be assigned.
- Maintains an outward-facing and forward-looking view to provide solutions to ensure that the bank's Information Security Program is current and relevant.
- Designs, implements, and manages Information Security data identification, aggregation, analytics, and validation to meet department goals.
- Collaborates in developing and maintaining application security documentation (policies, standards, procedures, templates, etc.) that may be applied towards security governance in projects and operations:
- Initiates and executes on process improvements, policy/procedure updates, etc.
- Tracks developments and changes in the digital banking and threat environments to ensure they are adequately addressed in security strategy plans.
- Documents data flows of sensitive information within the organization (e.g., PII or ePHI) and recommends controls to ensure this data is adequately secured (e.g., encryption, tokenization, etc.).
- Serves as the Subject Matter Expert in providing guidance in the areas of application security, identity management, and API security:
- Participates in application and related infrastructure projects to provide security planning consulting.
- Partners with cross-functional teams to ensure security requirements are incorporated into processes and operations.
- Liaisons with the vendor management team to conduct security assessments of existing and prospective vendors, especially those with which the organization shares intellectual property, PII, ePHI, regulated or other protected data, including SaaS providers, cloud/infrastructure as a service (IaaS) providers, managed service providers, etc.
- Program Manager Responsibilities:
- Owns the bank's application security, identity governance, and fraud-related technology risk programs, and is accountable for strategy, governance, maturity, and measurable risk outcomes.
- Establishes program objectives, control standards, operating procedures, risk tolerances, and performance metrics to ensure program effectiveness and regulatory alignment.
- Develops and maintains multi-year roadmap for people, process, and technology capabilities, including investment priorities, control enhancements, and maturity targets.
- Provides leadership reporting and risk insights to Information Security leadership, executive stakeholders, governance committees, auditors, regulators, and others as appropriate.
Minimum Qualifications:Education:
- Bachelor's Degree from a 4-year university required, preferably in Information Security, MIS, Computer Science
Experience:
Application Security Program Manager I:
- 7+ years of experience and working knowledge in information security, application security, and regulations and privacy laws pertaining to release of information, and security and access control technologies, or equivalent experience required
- 3+ years of experience in management or as a team lead with enterprise-wide cross-functional leadership responsibilities required
- 1+ years of experience in financial services preferred
- 2+ years of experience in leading risk assessments including control analysis, risk articulation, remediation planning, and executive communication preferred
- 2+ years of experience presenting to senior management, governance committees, and regulators preferred
- 1+ years of experience in data processing or analytics and related technical experience preferred
- 1+ years of experience with identity governance and administration platforms and solutions preferred
Application Security Program Manager II:
- 10+ years of experience and working knowledge in information security, application security, and regulations and privacy laws pertaining to release of information, and security and access control technologies, or equivalent experience required
- 5+ years of experience in management or as a team lead with enterprise-wide cross-functional leadership responsibilities required
- 2+ years of experience in financial services preferred
- 2+ years of experience in leading risk assessments including control analysis, risk articulation, remediation planning, and executive communication preferred
- 2+ years of experience presenting to senior management, governance committees, and regulators preferred
- 1+ years of experience in data processing or analytics and related technical experience preferred
- 1+ years of experience with identity governance and administration platforms and solutions preferred
License/Certification:
- CISSP, CISA, TOGAF, SANS GCSA, or equivalent certification (Indicate Upon Hire) preferred
Physical Requirements & Working Conditions:- Must be able to perform light physical work and to move or lift items including but not limited to boxes, files and papers up to 20 pounds unless otherwise as indicated.
- Must be able to operate and proficiently use standard office equipment, including phone, copier, personal computer and/or other work related mechanical or electronic devices and applications.
- Must be able to clearly communicate verbally and in writing with all internal and external customers. Must also be able to hear sufficiently to engage in daily discussions and interactions.
- Must be able to read and understand bank-related documents.
- Must be able to work in a conventional office setting, involving sitting at a desk or workstation for long periods of time. Must also be able to adapt to different work environments as needed to perform the job.