POSITION PURPOSE
Β
The Information Security Program Manager is responsible for overseeing various aspects of the Information Security Program, including: 1) leading and managing information security initiatives, 2) developing and reporting operational metrics, compliance metrics, and key risk indicators (KRIs), 3) creating and maintaining information security policies, standards, and procedures, and 4) managing the Bankβs information security awareness program. This role focuses on driving continuous process improvement and fostering effective collaboration across cross-functional teams and departments to address information security challenges and opportunities throughout the Bank. The position requires a blend of technical and creative skills and reports directly to the Chief Information Security Officer (CISO).
Β
ESSENTIAL FUNCTIONS AND BASIC DUTIES
Project Portfolio Management
Information Security Awareness
Metrics and Reporting
Goal Tracking
Change Management
Best Practices
Policy, Standard, and Procedure Administration
Β
SUPERVISORY RESPONSIBILITIES:
Β
Leadership and Development
Β
QUALIFICATIONS
Education/Certification:Β Β Bachelorβs degree in computer science, information assurance, MIS, or related field, or equivalent work experience. Professional certifications including CISSP, CISM, CRISC, SANS, PMP, and Scrum a plus.
Required Knowledge:Β Β Β Β Β Thorough knowledge of financial institution products and services preferred.
Understanding of related applications, systems, and services.
Knowledge or experience working with common cybersecurity frameworks including the NIST CSF, CRI Cyber Profile, and CIS Controls.
Core understanding of fundamental project management principles and methodologies with experience in agile and Scrum preferred.
Knowledge and experience working in the full Microsoft 365 suite (i.e. Office 365, Power Platform, etc.).
Experience developing content for information security awareness communications, newsletters, phishing, and training campaigns.
Desire to maintain up-to-date knowledge of information and cyber security related products and services, regulations, and internal Bank procedures.
Experience collecting, analyzing, summarizing, and presenting department data and trend reports for second line (3 Lines of Defense).
Proven effectiveness in practicing punctuality, respecting deadlines, solving problems, and communicating honestly and with integrity.
Β
Experience Required:Β Β Β Β Β 7-10 years of professional experience in related fields.
1-3 years of experience in an information security or cybersecurity role.
1-3 years of experience in a program/project management role.
Skills/Abilities:Β Β Β Β Β Β Β Β Β Β Proven experience in program development and management.
Proven stakeholder management skills.
Proven experience facilitating and leading teams in projects, preferably agile or Scrum teams.
Competency in business document management and creation platforms.
Excellent verbal and written communication skills.
Ability to explain information security terminology and concepts to cross functional stakeholders for easy consumption.
Exceptional organizational and time-management skills.
Understands service design and delivery concepts.
Leverage subject matter expertise in security and compliance.
Possess a high level of integrity, trustworthiness, and confidence to represent the Bank with a high level of professionalism.