CORPORATE IT SECURITY MANAGER - CORPORATE IT SECURITY - FIRSTBANK PR

Wepay

• $100K — $120K *
Finance & Insurance
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree in Information Technology, Computer Science, Engineering, or Business required.
  • Minimum of 6 years of Information Security experience, preferably in banking.
  • CISSP, CISM, or similar certification preferred but not required.
  • Master's degree in Computer Science, Information Systems, or Engineering preferred.
  • Strong understanding of Information Security Frameworks like COBIT 5, ISO 27001, NIST required.
  • 7+ years of related work experience in IT or Information Security, ideally in financial services.
  • Minimum of 3 years of relevant experience at a financial services company or as an advisor to one.

Responsibilities

  • Lead Cyber Defense strategy and continuous improvement initiatives.
  • Oversee SOC/MDR performance and incident response activities.
  • Manage the Information Security Incident Response Plan and related processes.
  • Chair the Patch Management Board and ensure effective vulnerability management.
  • Establish AI security operations to monitor emerging threats and attack techniques.
  • Develop cyber-risk metrics and executive reports for management and governance committees.
  • Coordinate with various departments to ensure comprehensive security measures.

Benefits

  • Comprehensive health and wellness programs.
  • Professional development and training opportunities.
  • Flexible work arrangements and work-life balance initiatives.
  • Retirement savings plan with company match.
  • Employee assistance programs for personal and professional support.
Full Job Description
CORPORATE IT SECRITY MANAGER

Or Company

A Brief Overview

The IT Secrity Manager leads the Corporation's cyber-defense program and is accontable for secrity monitoring, detection and response, incident management, vlnerability and exposre management, endpoint, email, network, application, data-loss prevention, and managed secrity service oversight. The role translates cyber risk into prioritized operational action and provides timely reporting and recommendations to the CSO Management and governance committees.

What yo'll do

Cyber Secrity Operations
• Lead Cyber Defense strategy, operating procedres, staffing, service delivery, technology administration, and continos improvement.
• Oversee SOC/MDR performance, secrity monitoring, alert triage, investigation qality, escalation, threat hnting, and incident closre.
• Own the Information Secrity Incident Response Plan and coordinate preparation, response, containment, recovery, commnications, evidence preservation, and lessons learned.
• Oversee vlnerability, configration-hardening, penetration-testing, patch, and exposre-management activities sing risk-based prioritization.
• Chair or spport the Patch Management Board and related governance, ensring material vlnerabilities, exceptions, mitigating controls, and overde remediation are escalated.
• Oversee endpoint, email, network, WAF, DLP, vlnerability-scanning, and other cyber-defense capabilities and ensre they operate as intended.
• Establish AI secrity operations to monitor AI-enabled threats, misse, data exposre, agent activity, and emerging attack techniqes.
• Expand DLP governance and operations, inclding monitoring, tning, investigation, exception management, and reporting.
• Manage critical secrity service providers, contract and control performance, service-level compliance, remediation, and escalation.
• Develop cyber-risk metrics, dashboards, threat briefings, and exective reports for the CSO Management, management committees, aditors, reglators, and the Board, as reqired.
• Coordinate with Secrity Architectre, IAM Governance, Access Management Operations, GRC, Technology, Legal, Privacy, ERM, and bsiness leaders.
• Lead and develop Cyber Defense personnel, define accontabilities, establish coverage and on-call expectations, and maintain sccession plans.
• Spport new initiatives and technology implementations by identifying operational secrity reqirements and validating readiness.

Secrity Incident Management
• Responsible for the Information Secrity Incident Response Plan.
• Serve as a sbject matter expert for Incident handling and response.
• Establishes and administers a process for investigating and acting on secrity incidents which may reslt in a informaiton breaches.
• Condct Incident Management preparedness.
• Assist in forensic investigations regarding Information Secrity incident or events

Information Secrity Project Management
• Assist the Project Management Office with the Project Delivery Lifecycle to ensre Information Secrity practices are maintained in each step: Reqirement, Design, Testing, Implementation, etc.
• Ensre key secrity milestones are completed for each project (where applicable): Vlnerability scans, Code Review, Penetration Tests, Logging capabilities, Role-based Access, etc.
• Server as a Sbject Matter Expert and provide recommendations for remediating vlnerabilities identified throgh Penetration tests and Vlnerability Scans.
• Ascertain hardening standards are contemplated as part of each project implementation. Management of Compliance scan to ensre new applications comply with Corporate Standards.
• Active participant of the Infrastrctre Steering Committee.

Threat Intelligence
• Ensre the Corporation receives adeqate Threat Intel throgh different forms, sch as working knowledge of FS-ISAC and similar open/commercial threat intelligence feeds.
• Process both internal and external Cyber Threat Intel for determination of potential threat and impact, and implementation of mitigating actions.
• Escalate with vendors any otstanding event that may hamper or negatively affect the Corporations IT Assets.
• Follow p with It / Information Secrity Vendors to ensre pdates and pgrades have been implemented.

Additional Responsibilities
• Performs other tasks as reqested by the Corporate Secrity Officer.
• Performs/Spports highly technical tasks sch as:

o Systems and procedres review and implementation

o Policies Awareness training

o Special Investigations (Forensic)

o Root Case Analysis Process
• Performs special tasks in order to assist internal, external aditors and reglators in their procedres.
• Monitors compliance with contined edcation reqirements.
• Safegards information related to dties.

What Yo'll Need to Scceed
• A Bachelor's Degree in Information Technology, Compter Science, Engineering, or Bsiness is reqired.
• The incmbent mst have at least six (6) years of Information Secrity experience or experience in a similar position within the banking indstry.
• CISSP, CISM or any other similar certification is highly desired bt not reqired.
• A Master's degree in Compter Science, Information Systems, Engineering is preferred.
• Strong nderstanding of Information Secrity Frameworks sch as COBIT 5, ISO 7, NIST, and others is reqired.
• 7 or more years of related work experience in IT, Information Secrity topics, or developing, implementing or architecting information secrity systems, in the banking indstry highly preferred
• Minimm of 3 years of relevant experience at a financial services company or comparable experience working as an advisor to a financial services company.

Competencies
• Strong nderstanding of Information Secrity Frameworks sch as COBIT 5, ISO 7, NIST, and others is reqired.
• Strong nderstanding of Information Secrity reglatory reqirements and compliance isses, previos experience with applicable reglations from the FDIC, FFIEC, SOX, etc.
• Proficient in EXCEL, WORD, OTLOOK, ACCESS, POWER POINT
• Knowledge of general secrity concepts and methods sch as vlnerability assessments, privacy assessments, intrsion detection, incident response, secrity policy creation, enterprise secrity strategies, architectres and governance
• Experience in project management of information secrity projects inclding development of project charters and plans; management of project exection and sccessfl implementation of the planned soltion
• Spervisory, interpersonal commnication, leadership and team skills
• Able to work in a team oriented, highly demanding and fast paced environment
• Exercise excellent written commnication skills with direct experience drafting gidance docmentations
• nderstand complex bsiness and Information Technology / Information Secrity processes
• Familiarity with vlnerability assessment and penetration testing best practices
• Organization and prioritization skills
• Strong analytical skills and problem-solving skills
• Strong analytical skills (analytical thinker) and self-starter
• Wide information technology knowledge within the Banking Indstry
• nderstand and be proficient in common cyber threat terminology, methodologies, possess basic nderstanding of cyber incident and response, and related crrent events
• Knowledge in databases, Web Applications, Network and commnication Infrastrctre, operating systems (ex. IBM, nix, Linx and Windows), secrity technologies (firewalls, IDS/IPS, etc.)
• Hands-on skills in adit planning, development of adit programs, fieldwork and wrap-p
• Experience in process definition, workflow design and process mapping
• Committed to accracy. Mst be able to provide ot of the box thinking soltions to highly complex isses

Disclaimer: The above statements are intended to describe the general natre and level of work being performed by people assigned to this job. They are not intended to be an exhastive list of all responsibilities, dties, skills reqired of personnel so classified. The reporting relationship may not reflect the most recent changes to the corporate reporting strctre.

Similar Jobs

More Jobs at Wepay

More Finance & Insurance Jobs

Find similar CORPORATE IT SECURITY MANAGER - CORPORATE IT SECURITY - FIRSTBANK PR jobs: