Director, Information Technology & Security

September 28, 2026
Application ends: December 27, 2026

Job Description

REQUIREMENTS

  • Minimum of 10 years of experience in information technology, and security and technology risk management, with a proven track record of moving between strategic planning and hands-on technical execution.
  • Demonstrated experience designing and implementing information security programs compliant with FDIC and FFIEC standards.
  • Strong familiarity with third-party risk frameworks and financial services cybersecurity expectations.
  • Experience leading incident response, penetration testing, and security operations in cloud-based and hybrid environments.
  • Proven ability to communicate complex technical topics to executive leadership, the Board, and regulators.
  • Strong leadership, analytical, and problem-solving skills with a risk-based and pragmatic approach to decision-making.
  • Deep expertise in cloud-native infrastructure (AWS/GCP), DevOps practices, and software-defined security controls.
  • Demonstrated ability to “roll up sleeves” and contribute directly to the technology build while simultaneously managing executive stakeholders and regulators.

Core Competencies

  • Expert knowledge of information security principles, frameworks, and regulatory requirements.
  • Strategic thinker with strong operational execution and control discipline.
  • Effective communicator capable of influencing across technical and business functions.
  • Collaborative leader who fosters a culture of accountability, awareness, and continuous improvement.

RESPONSIBILITES

  • Oversee infrastructure design and IT Engineering
  • Information Security Program Development
  • Design, implement, and maintain a comprehensive Information Security Program consistent with FDIC guidance (e.g., FIL-66-2019, FIL-13-2021) and the Interagency Guidelines Establishing Information Security Standards.
  • Develop and oversee policies, standards, and procedures governing cybersecurity, data protection, and incident response.
  • Ensure alignment with the Bank’s overall risk management and governance frameworks.
  • Provide regular reporting to executive management and the Board on the Bank’s security posture, emerging risks, and mitigation efforts.
  • Lead the technical build phase of the Bank’s infrastructure, providing direct oversight and hands-on guidance for cloud security and DevOps integration.
  • Partner deeply with Engineering to define and implement secure technical architectures, including network segmentation, encryption standards, and identity governance.
  • Cybersecurity and Threat Management
  • Establish and manage a threat monitoring and detection capability to identify, assess, and respond to cybersecurity risks.
  • Oversee implementation of layered security controls (e.g., network segmentation, encryption, access controls, endpoint protection, vulnerability management).
  • Lead the Bank’s Incident Response Program, ensuring timely escalation and coordination with regulators when required.
  • Maintain relationships with information-sharing groups (e.g., FS-ISAC) and law enforcement to stay informed of emerging threats.
  • Third-Party and Affiliate Risk Oversight
  • Evaluate the information security posture of third-party and affiliate service providers in accordance with the Bank’s Vendor Management Program and FDIC third-party risk guidance.
  • Establish due diligence, ongoing monitoring, and contractual requirements for vendors handling sensitive data or performing critical services.
  • Coordinate with Operations, Compliance, and Internal Audit to ensure third-party risks are identified, assessed, and mitigated.
  • Manage the technical lifecycle of security-critical third-party service providers, ensuring rigorous operational oversight of vendors handling sensitive financial data.
  • Data Governance and Privacy Protection
  • Ensure compliance with applicable privacy and data protection requirements (e.g., GLBA, Regulation P, state privacy laws).
  • Implement processes to safeguard customer information and prevent unauthorized access, disclosure, or misuse.
  • Partner with business and technology teams to integrate privacy-by-design principles into new products and services.
  • Business Continuity and Resilience
  • Assist Risk Officer in development and testing of the Bank’s Business Continuity and Disaster Recovery (BC/DR) plans, ensuring they are integrated with information security objectives.
  • Coordinate regular testing and simulations to validate readiness for cyber incidents and system disruptions.
  • Support resilience planning for key systems, vendors, and communication protocols.
  • De Novo and Pre-Opening Readiness
  • Build and document the Bank’s technology and information security program as part of the de novo application process.
  • Establish security architecture, monitoring tools, and vendor relationships prior to launch.
  • Prepare readiness materials for FDIC and state examinations related to cybersecurity and operational resilience.
  • Ensure security risk assessments and third-party reviews are completed and incorporated into pre-opening milestones.
  • Leadership and Culture
  • Serve as the Bank’s senior advocate for cybersecurity and data protection, promoting a culture of security awareness and accountability.
  • Provide training and guidance across the organization to enhance information security awareness.
  • Collaborate with peers in Risk, Compliance, Operations, and Technology to align security priorities with business strategy.
  • Build and lead a capable, mission-driven security team to support the Bank’s evolving needs.

Are you interested in this position?


Apply by clicking on the “Apply Now” button below!

#CrossChannelJobs #JobSearch
#CareerOpportunities #HiringNow
#Employment #JobOpenings
#JobSeekers

Related Jobs