SonicJobs Logo
Left arrow iconBack to search

Bank Information Security Officer

Transpecos Banks SSB
Posted 5 days ago, valid for 22 days
Location

San Antonio, TX, US

Salary

Competitive

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • The Bank Information Security Officer (BISO) will support the Chief Technology Officer in managing the bank's Information Security Program, overseeing security monitoring and incident response.
  • Candidates should have a minimum of 5 years of experience in information security, with a preference for those with supervisory experience in a regulated industry.
  • The BISO will be responsible for developing and enforcing security policies, managing risks, and supervising the Information Security Analyst.
  • This salaried, exempt position is primarily based in San Antonio, but remote candidates will also be considered.
  • The role requires a bachelor's degree in a related field and familiarity with information security frameworks and regulatory requirements.

Job Description

Job Title: Bank Information Security Officer (BISO)

Preference is for a candidate based in or near our San Antonio headquarters; remote candidates will be considered for this role.

Summary: The Bank Information Security Officer (BISO) supports the Chief Technology Officer, who serves as the bank's designated Information Security Officer (ISO), in the day-to-day management and execution of the bank's Information Security Program. This role bridges strategic security direction and hands-on operational execution, overseeing security monitoring, IS incident response, and risk assessments, and directly supervising the Information Security Analyst, while ensuring the bank's information security practices align with regulatory expectations, including the GLBA Safeguards Rule (16 CFR 314) and FFIEC Information Security guidance.

Wage Type: Salaried, Exempt

Essential Duties & Responsibilities:

To perform this job successfully, an individual must be able to perform each of the essential duties satisfactorily. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

  • Manage the day-to-day operations of the bank's Information Security Program on behalf of the Chief Technology Officer / Information Security Officer.
  • Identify, assess, and manage information security risks; ensure ongoing security monitoring and IS incident response readiness.
  • Develop, maintain, and enforce information security policies, procedures, standards, and employee training/awareness programs.
  • Evaluate, recommend, and help implement security technologies and controls to safeguard information assets.
  • Coordinate information security assessments and reviews with IT, Compliance, Internal Audit, and external examiners/auditors.
  • Lead IS incident response activities, including investigation, containment, remediation, and post-incident reporting.
  • Monitor the regulatory and threat landscape and advise the Chief Technology Officer on emerging security threats, trends, vulnerabilities, and regulatory changes.
  • Maintain the bank's information security risk register, control testing, and remediation tracking.
  • Supervise and develop the Information Security Analyst, providing guidance, performance management, and professional development.
  • Prepare metrics, dashboards, and reports on the information security program for the Chief Technology Officer, senior management, and the Board as needed.
  • Serve as a backup point of contact for information security matters in the Chief Technology Officer's absence.
  • Carries out responsibilities in a manner consistent with our values and operating principles, in accordance with policy and applicable laws, and with a commitment to continuous improvement and process excellence.
  • Any other duties as assigned.

Key Deliverables:

  • Day-to-day execution of a compliant Information Security Program.
  • Timely IS incident detection, response, and remediation.
  • Accurate and up-to-date information security risk register and control testing.
  • Development and performance management of the Information Security Analyst.

Organizational Structure:

Reports to: Chief Technology Officer

Supervises: Information Security Analyst

Qualifications:

Education:

  • Bachelor's degree in Information Security, Computer Science, Information Technology, or related field preferred.

Experience:

  • 5+ years of experience in information security, with demonstrated experience in security operations, risk assessment, or GRC.
  • 2+ years of experience with supervisory or team-lead responsibilities preferred.
  • Experience in financial services or a highly regulated industry preferred.
  • Applicable certifications a plus (e.g., CISSP, CISM, GSEC, Security+).

Required Knowledge/Skills:

  • Solid understanding of information security frameworks and regulatory requirements (GLBA, FFIEC, NIST CSF, PCI DSS).
  • Working knowledge of security monitoring, incident response, and vulnerability management practices.
  • Strong analytical, organizational, and documentation skills.
  • Ability to manage and develop staff.
  • Excellent written and oral communication skills, with the ability to translate technical security topics for non-technical audiences.

Desired Experiences:

  • Experience supporting or reporting to a CISO or Information Security Officer in a banking or financial services environment.
  • Experience with GRC tools, SIEM platforms, or vulnerability management tools.

Talents:

  • Strong positivity.
  • Mission driven, competitive, goal oriented, and motivated to develop themselves and others.
  • Energetic, resourceful, and appropriate work intensity to get the work done.
  • Strong people acumen and relationship skills; Naturally pre-disposed to quickly establish positive personal and professional relationships.

Other:

  • Ability to interpret a variety of instructions furnished in written, oral, diagram or schedule form.
  • Must be able to lift to 20 pounds.

TransPecos Banks will not accept unsolicited resumes from any source other than the candidate. We will consider any candidate for whom an Agency submits an unsolicited resume, to have been referred to us by the Agency free of any charges or fees, other than those agencies we engage on a specific search. TransPecos Banks will not pay a fee for any placement resulting from the receipt of an unsolicited resume.




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.