Summary of Position Serves as a strategic advisor and operational anchor to the Chief Security Officer and Information Security leadership team. Drives organizational effectiveness by owning security program management, cyber resilience, and executive-level business operations enabling the CSO and direct reports to operate at maximum strategic impact.
Job Duties and Responsibilities - Owns the Security organization's program portfolio, ensuring initiatives are tracked, prioritized, and delivered against defined OKRs and milestones. Establishes and maintains program governance frameworks, risk registers, and status reporting cadences across the Security organization. Partner with CSO directs to identify cross-functional dependencies and remove execution blockers.
- Leads the enterprise Cyber Resiliency program, defining the strategy and roadmap for the organization's ability to anticipate, withstand, recover from, and adapt to cyber threats and disruptions. Drives maturity assessments against established frameworks (e.g., NIST CSF, CISA CPGS) and translate findings into prioritized, measurable improvement plans.
- Coordinates threat-informed resilience exercises -- tabletops, red team integration, and crisis simulations -- ensuring lessons learned are embedded into program improvements. Serves as the primary owner of cyber resiliency metrics and reporting for executive, board, and regulatory audiences, including FFIEC and OCC expectations for financial institutions. Aligns Cyber Resiliency investments with BC/DR, Incident Response, and third-party risk programs to ensure an integrated, defense-in-depth posture.
- Supports the CSO and direct reports in budget planning, forecasting, and variance analysis for the Security organization. Partners with Finance to manage headcount, vendor spend, and capital project tracking; surface risks and opportunities proactively.
- Facilitates the annual Security strategy planning process; synthesizes inputs into cohesive roadmaps and executive presentations. Prepares board-level and executive committee materials, including security metrics, risk posture summaries, and program updates. Drive operating rhythms -- staff meetings, QBRs, leadership offsites -- ensuring outcomes are documented and actioned.
- Manages the annual performance management and merit processes for direct and indirect reports. Coaches and develops team members and builds a work environment where team members are engaged and feel a positive sense of achievement about their role in the firm.
- Meets all the client's financial needs, both business and personal, and refers clients to other specialty areas such as Trust, Investments, Insurance, Treasury Management, etc. as appropriate.
- Assists other team members as needed to ensure delivery of distinctive service.
- Performs other related duties and responsibilities as required.
Each team member is expected to be aware of risk within their functional area. This includes observing all policies, procedures, laws, regulations and risk limits specific to their role. Additionally, they should raise and report known or suspected violations to the appropriate Company authority in a timely fashion.
The information on this description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of employees assigned to this job.
Minimum Education:- Bachelor's degree Computer Science, Business Administration, Cybersecurity.
Minimum Experience:- 10 years of progressive experience in information security, risk management, or a related field within a regulated industry (financial services preferred) including experience in cyber resiliency program development, enterprise incident response, and BC/DR program ownership.
Required Knowledge, Skills, & Abilities:- Familiarity with NIST CSF, CISA CPGs, FFIEC CAT, and related frameworks as applied in financial services environments.
- Strong financial acumen with experience supporting budget management for large technology or security organizations.
- Exceptional executive communication skills -- ability to synthesize complex topics for board, C-suite, and regulator audiences.