Chief Information Security Officer

Description
The Chief Information Security Officer is responsible for managing the information and cyber security function within the IT department of The Federal Savings Bank. This position defines strategy, plans and executes projects, oversees vendors, performs hands-on technology work, monitors and analyzes operational results of the technology environment, and responds to information security incidents. The CISO is an expert in multiple IT functions and is responsible for implementing best practices for technology architecture and IT processes. This role is based out of The Federal Savings Bank Chicago, IL headquarters and reports directly to the Chief Information Officer.
Qualified candidates must be available to work a hybrid schedule (3 days onsite/2 days remote).
What We Offer:
- Holidays and Paid Time Off that increases with length of employment
- Company culture that fosters work/life harmony
- Health, Dental, and Vision insurance plans
- FSA and HSA plan options
- Company-paid life insurance
- Employee Home Loan Discount
- 401k with partial match
- In-house virtual training opportunities to broaden your industry knowledge
- Career advancement
- Big bank capability with a national footprint, small-bank feel
Duties and Responsibilities
Information Security:
- Responsible for the strategy, design and oversight of the Bank’s Information Security technology infrastructure implemented by the bank’s technology services providers
- Provide subject matter expertise for network security topics related to network, server and client technology architectures such as intrusion detection and prevention, antivirus and APT, data loss prevention, firewall, Internet proxy, VPN, etc.
- Develop documentation to support ongoing security systems operations, maintenance and specific problem resolution
- Research and review new and emerging technologies and trends
- Administer the bank’s information security technology
- Design and build a Computer Incident Response Team (CIRT) and response process for the Bank; lead the CIRT for information security incidents
- Monitor the department’s responsiveness to requests, problems and disasters and ensure that IT processes are followed
Policy, Project, and Team Management:
- Coordinate users, Bank IT resources, and service provider staff to implement solutions that will meet or exceed customer, management, and regulator expectations
- Manage and own project delivery within budget, scope, quality, and time requirements
- Manage information security analyst personnel, daily activities, and project delivery
- Identify and manage risk and issues throughout each information security project
- Monitor project progress, ensure deliverables are met, and communicate status to sponsors for information security projects
- Create appropriate documentation for projects include task plans, Gantt charts, resource plans, status reports, risk logs, etc.
- Develop implementation test plans and assist implementation vendors with information security applications, hardware and systems testing as needed
- Facilitate integration among different technical teams for planning and executing projects
- Develop and implement Bank Information Security policies
- Apply corporate policies to information security practices
- Lead the remediation of vulnerability assessments related to technology infrastructure
- Lead the development and implementation of Information Security controls
- Lead the review and development of information security technology standards
Other:
- Oversee hardware, software, and service selection processes for information security solutions
- Negotiate pricing with vendors
- Define departmental budget and track expenditures
- Approve all technology purchases
- Manage vendor services/vendor relationships to ensure delivery of products and services level targets
- Clearly communicate performance expectations of staff
- Actively seek suggestions for improvement of IT performance from IT staff and all TFSB employees
- Identify best practices and design policies and processes for the bank’s information security function
- Mentor technical staff on information security functions
- Maintain a training plan for IT staff on information security functions
- Maintain a positive work environment
Requirements
SKILLS REQUIRED:
- Expert knowledge of Active Directory/LDAP Directory Services and Windows Server, Linux OS, and m365 administration and security
- Knowledge of SQL Server
- Expert knowledge of Authentication Protocols, MFA
- Expert knowledge of DNS, DHCP, SMTP, SNMP, TCP/IP, UDP
- Familiar with common security tools
- Familiar with penetration testing concepts
- Familiar with vulnerability scanning
- Familiar with firewalls/routers/IPS/IDS
- Experience with creating technical documentation
- Proficient in Microsoft applications (Access, Excel, Word, Project)
- Familiar with a variety of the field’s concepts, practices and procedures
- Familiar with VOIP technologies and implementations
- Understanding of computer systems security issues
- Ability to work well with other technicians
- Expert project management skills
- Excellent verbal and written communication skills; ability to develop polished communications for the entire bank, senior management and IT staff
- Ability to define complex problems and propose solutions
- Ability to effectively coach employees and lead and direct the work of others
- Ability to establish and maintain effective work relationships both internally and externally with employees and senior executives
EDUCATION AND EXPERIENCE:
- Bachelor’s degree in Computer Science, Information Technology specialty, or related field
- Minimum 10 years’ information security management experience
- 5+ years of department management experience
- Banking/FFIEC regulatory experience required
- Mortgage Banking experience preferable
- Information Security industry certifications a plus
- CISM or CISSP certification preferable
The Federal Savings Bank is an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status.
You'll be redirected to
the company's application page