Bank of Oklahoma

Chief Information Security Officer

Bank of Oklahoma$166K — $200K *
Tulsa, OK 74133In-Person
Finance & Insurance
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or related field.
  • 15+ years in information security or cybersecurity roles, with 8-10+ years in leadership.
  • Deep expertise in cybersecurity and information security governance.
  • Strong understanding of financial services regulations (SEC, FINRA).
  • Professional certifications like CISSP or CISM preferred.

Responsibilities

  • Lead the development and implementation of the enterprise information security strategy.
  • Define and communicate the organization's cyber-risk profile to executives and the Board.
  • Direct security operations including incident response and vulnerability management.
  • Serve as Privacy Officer, overseeing privacy governance and incident response.
  • Govern cloud security practices and incident response strategies.
  • Engage with third-party vendors for cyber risk management and compliance.
  • Build and lead a high-performing security leadership team.

Benefits

  • Strong focus on employee development and success.
  • Access to competitive professional growth opportunities.
  • Inclusive culture that values leadership at every level.
  • Innovative work environment that embraces technology advancements.
  • Direct visibility and influence at the executive level.
Full Job Description
Req ID: 78435

Location: Tulsa -TUL

Areas of Interest: Risk Management; Information Security

Pay Transparency Salary Range: Not Available

Bonus Type

Discretionary

Summary

Protect what matters most at a $54 billion financial institution.

This is a senior executive role with enterprise-wide visibility, positioned to define how BOK Financial protects its systems, data and the customers who trust us with their financial lives.

As Chief Information Security Officer, you will lead the enterprise information security strategy and build a security program sized to our complexity - a bank, SEC-registered investment advisers, FINRA-supervised broker-dealers, and trust and fiduciary businesses, with more than $120 billion in assets under management or administration. You will also serve as the organization's Privacy Officer, owning the enterprise privacy program end to end.

Reporting to the Chief Risk Officer, you will partner directly with executive leadership and the Board to define, assess and communicate our cyber-risk profile - inherent risk, control effectiveness, residual risk and where the trajectory is heading. You will lead security engineering, cyber threat management and response, identity and access management, and security risk and compliance, while shaping how we govern emerging risk across cloud and artificial intelligence.

If you are energized by operating at scale, translating complex risk into decisions executives can act on, and building a security culture that holds up under regulatory scrutiny, this role offers exceptional visibility and real influence over the future of the enterprise.

Job Description

The Chief Information Security Officer (CISO) is responsible for leading the enterprise information security strategy and protecting the organization's systems, data, customer information, and information assets from compromise, unauthorized access, disclosure, or disruption. This role designs, implements, and matures an enterprise-wide information security program aligned to the organization's size, complexity, risk profile, regulatory obligations, and business strategy.

BOKF's information security program must also support the risk and regulatory complexity associated with more than $120B in assets under management or administration, two SEC-registered investment advisers, and two FINRA-supervised broker-dealer affiliates/subsidiaries.

The CISO is expected to support SEC and FINRA regulatory readiness by coordinating with affiliate compliance, legal, supervision, and business leaders on cybersecurity examinations, incident escalation and response, customer and client data protection, books-and-records considerations, third-party risk oversight, remediation tracking, and evidence-based demonstration of effective security governance across regulated advisory and broker-dealer affiliates.

The CISO also serves as the organization's Privacy Officer and is responsible for overseeing the enterprise privacy program, including privacy governance, privacy risk management, regulatory readiness, customer/client information protection, privacy incident response, breach notification coordination, and alignment of privacy controls with cybersecurity, data governance, business, and regulated affiliate requirements.

The CISO partners closely with executive leadership, the Board, Risk, Information Technology, Compliance, Legal, Audit, business leaders, and external partners to identify, assess, monitor, and communicate the organization's cyber-risk profile. This includes oversight of inherent risk, control effectiveness, residual risk, risk trajectory, security incidents, regulatory expectations, third-party risk, and emerging threats. The role is accountable for ensuring the organization maintains a strong security culture, operates within established risk thresholds, and has the leadership, governance, resources, controls, and response capabilities needed to protect the organization and its customers.

Team Culture

At BOK Financial, your potential is our priority. We invest in people, not just positions, because when you succeed, we all do.

You will be joining a culture that values:
  • Enterprise mindset - aligning teams and priorities to protect clients and the business as one organization
  • Innovation with discipline - advancing cloud, AI and modern security capabilities while maintaining strong governance
  • Leadership at every level - empowering teams while influencing across a matrixed, highly regulated organization
  • Continuous evolution - staying ahead of threats, technologies and regulatory expectations

This is a team where leaders are accessible, decisions get made, and the impact of your work is visible all the way to the Board.

How You'll Spend Your Time

  • Lead the enterprise information security program - policies, standards, controls, governance and reporting.
  • Define the organization's cyber-risk profile, including inherent risk, control effectiveness, residual risk and risk trajectory against Board-approved thresholds.
  • Report security strategy, program effectiveness, incidents, and audit and examination outcomes to executive leadership and the Board.
  • Direct enterprise security operations - threat monitoring, vulnerability management, incident response, remediation and regulatory notification.
  • Serve as the organization's Privacy Officer, owning privacy governance, risk assessments, training, incident response and breach notification.
  • Govern cloud security across SaaS, PaaS and IaaS, from architecture and identity to encryption, monitoring, resilience and cloud incident response.
  • Establish cybersecurity governance for AI and generative AI, including acceptable use, sensitive data protection and third-party AI risk.
  • Oversee third-party cyber risk from due diligence and contracting through ongoing monitoring, control validation and incident coordination.
  • Partner with affiliate compliance, legal and business leaders to drive SEC and FINRA regulatory readiness.
  • Secure a defensible, risk-based security budget by quantifying cyber risk in financial terms.
  • Build a high-performing security leadership team with strong talent pipelines, succession planning and a culture of accountability.


Education & Experience Requirements

Bachelor's degree in Computer Science, Information Security, Information Assurance, Technology, Risk Management, Business, or a related field, with 15+ years of progressively responsible experience in information security, cybersecurity, technology risk, or related disciplines, including 8-10+ years in senior cybersecurity leadership roles; or an equivalent combination of education and experience.

Strongly preferred experience includes leadership of enterprise cybersecurity, privacy, cloud security, AI governance, technology risk, incident response, third-party risk management, and regulatory compliance programs within a large regulated financial services organization, including SEC-registered, FINRA-regulated, wealth management, fiduciary, and banking environments. Experience presenting to executive leadership and Boards, supporting regulatory examinations, and leading security program transformation initiatives is preferred.

Professional certifications such as CISSP, CISM, CISA, CRISC, GIAC, or related security, risk, audit, or privacy certifications are preferred.
  • Deep expertise in cybersecurity, information security governance, risk management, security operations, cloud security, data protection, identity and access management, incident response, and third-party risk management.
  • Strong knowledge of financial services regulations and industry frameworks, including banking, privacy, cybersecurity, SEC, FINRA, and other applicable regulatory and compliance requirements.
  • Understanding of AI, generative AI, and emerging technology governance, including data protection, third-party risk, regulatory considerations, and cybersecurity controls.
  • Expertise in cloud security governance and architecture, including SaaS, PaaS, IaaS, access management, encryption, monitoring, resilience, and cloud service provider oversight.
  • Strong knowledge of privacy governance and Privacy Officer responsibilities, including data protection, privacy risk management, breach response, regulatory compliance, and customer information protection.
  • Ability to develop and execute cybersecurity strategy, communicate complex risks to executive leadership, Boards, regulators, and business stakeholders, and align security initiatives with organizational objectives and risk appetite.
  • Proven leadership, collaboration, and decision-making skills, with the ability to build high-performing teams, lead through cyber incidents and regulatory events, influence across functions, and adapt security programs to evolving threats, technologies, and regulatory requirements.

About Bank of Oklahoma

Bank of Oklahoma is a regional bank headquartered in Tulsa, Oklahoma. The bank was founded in 1910 and has over 100 branches in Oklahoma, Texas, Kansas, and Missouri. Bank of Oklahoma provides a range of financial services, including personal and business banking, wealth management, and insurance. The bank is committed to supporting the communities it serves and has donated millions of dollars to charitable organizations. Bank of Oklahoma is a subsidiary of BOK Financial Corporation, which is a publicly traded company on the NASDAQ stock exchange.
Learn more about Bank of Oklahoma
Size
5,000 employees
Industry

Similar Jobs

More Jobs at Bank of Oklahoma

More Finance & Insurance Jobs

Find similar Chief Information Security Officer jobs: