INFORMATION SECURITY OFFICER

Commonwealth Business Bank
  • Los Angeles, CA
  • $150,000–$160,000 Per Year
7 days ago

Job Description

SUMMARY

The Information Security Officer is responsible for developing, implementing, and maintaining the Bank's information security program, strategy, and governance framework. This role provides independent oversight of information security risk and helps protect the Bank's information assets and technology infrastructure from internal and external threats. The position leads initiatives supporting regulatory compliance, industry standards, security best practices, and a strong culture of security awareness across the organization. The position reports material information security risks, incidents, program performance, and resource needs to executive management and the Board or its designated committee.

Maintain sufficient organizational authority and independence to escalate material information security risks, control deficiencies, incidents, and resource constraints directly to executive management and, when warranted, the Board or its designated committee.

REQUIRED DUTIES

  • Develop, implement, and continuously enhance the Bank's Information Security Strategy, Architecture, and Roadmap to align with business objectives, risk appetite, and regulatory requirements.
  • Establish and maintain enterprise-wide information security policies, standards, procedures, and controls consistent with industry best practices and applicable regulations.
  • Monitor emerging cybersecurity threats, vulnerabilities, and industry trends, adapting security strategies and controls to address evolving risks.
  • Develop, maintain, and oversee a documented, enterprise-wide information security risk assessment process that identifies reasonably foreseeable internal and external threats, evaluates the likelihood and potential impact of those threats, assesses the sufficiency of existing controls, prioritizes residual risks, and tracks remediation to completion.
  • Lead the Bank's cyber resilience programs, including planning, testing, coordination, and ongoing improvement, in coordination with the Bank's enterprise business continuity management program.
  • Oversee information security risk associated with third parties, service providers, cloud environments, and technology supply chains, including due diligence, contract requirements, ongoing monitoring, incident coordination, resilience considerations, and timely remediation of identified weaknesses.
  • Establish and oversee identity and access management, privileged access, authentication, data classification, data loss prevention, encryption, vulnerability management, secure configuration, patch management, logging, monitoring, and other key control processes based on the Bank's risk assessment.
  • Direct cybersecurity incident preparedness, detection, response, investigation, containment, recovery, and post-incident remediation activities; coordinate required notifications to regulators, law enforcement, customers, and other stakeholders with Legal, Compliance, and executive management; and ensure lessons learned are incorporated into the information security program.
  • Coordinate with internal and external auditors, regulators, and independent assessors; provide complete and timely information for security-related reviews; track findings and corrective actions to completion; and preserve the independence of audit and other assurance functions.
  • Ensure compliance with applicable laws, regulations, and supervisory guidance, including the Gramm-Leach-Bliley Act, the Interagency Guidelines Establishing Information Security Standards, applicable FFIEC guidance, federal computer-security incident notification requirements, California privacy and breach-notification requirements, and other requirements applicable to the Bank's activities and risk profile. Use recognized frameworks, including NIST, CIS Controls, and ISO 27001, as appropriate to support the Bank's risk-based information security program.
  • Establish and maintain effective information security governance and provide periodic reporting to executive management and the Board or its designated committee on the Bank's risk profile, material threats and vulnerabilities, significant incidents, control effectiveness, testing results, remediation status, third-party risks, program performance, and resource needs.
  • Serve as the primary liaison with internal and external auditors, regulators, and independent assessors, providing subject matter expertise, guidance, and oversight on security-related reviews, investigations, and assessments.
  • Develop, implement, and promote enterprise-wide security awareness and training programs to foster a strong culture of cybersecurity and accountability.
  • Provide leadership, guidance, and specialized security training to Information Technology personnel and other stakeholders on cybersecurity best practices and regulatory expectations.
  • Perform other duties and responsibilities as assigned by the Chief Risk Officer.

SKILL AND EXPERIENCE REQUIREMENTS

  • Strong knowledge of cybersecurity principles, frameworks, and technologies, including NIST, ISO 27001, CIS Controls, SIEM, IDS/IPS, DLP, encryption, cloud security, and other industry-standard security practices.
  • Exceptional leadership, communication, and interpersonal skills, with a demonstrated ability to collaborate across business and technology functions and influence stakeholders at all organizational levels.
  • Strong analytical, critical thinking, and problem-solving capabilities, with the ability to assess complex risks and make sound, risk-based decisions in a dynamic and fast-paced environment.
  • Proven ability to lead, mentor, and develop high-performing cybersecurity teams while fostering a culture of accountability, continuous improvement, and operational excellence.

EDUCATION AND PROFESSIONAL QUALIFICATION

  • Bachelor's degree from an accredited university in Computer Science, Information Technology, Cybersecurity, or a related field.
  • Minimum of seven years of progressively responsible experience in information security or cybersecurity, including leadership responsibility for developing, implementing, and managing information security programs.
  • Experience in banking or financial services, including practical knowledge of the Gramm-Leach-Bliley Act, the Interagency Guidelines Establishing Information Security Standards, FFIEC information technology guidance, regulatory examinations, incident-notification requirements, third-party risk management, and applicable California privacy and breach-notification obligations.
  • One or more relevant professional certifications, such as CISSP, CISM, CISA, CRISC, or an equivalent credential, is preferred and may be required within a defined period after hire based on the candidate's experience.
  • Proven ability to align cybersecurity strategies with business objectives, regulatory expectations, and organizational risk management practices.

We offer a competitive total rewards package, including but not limited to Medical, Dental, Vision, and Life Insurance, 401k retirement savings plan, and paid federal holidays, for this full-time position within the annual salary range of $150,000 - $160,000. Annual pay ranges are determined based on qualifications, level, and location. Exact compensation may vary based on your skills and experience.

Must be authorized to work in the US.

We are an Equal Opportunity Employer. All applicants will receive consideration for employment without regard to race, color, ancestry, religion, sex, national origin, sexual orientation, age, marital status, disability, gender identity, gender expression, genetic information, or military or Veteran status, or any other characteristic protected by law.

Numbers & Facts

LocationLos Angeles, CA
Salary$150,000–$160,000 Per Year

Skills

  • Analysis Skillsunmatched
  • Authenticationunmatched
  • Best Practicesunmatched
  • Business Continuity Planning (BCP)unmatched
  • Cloud Computingunmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Configuration Managementunmatched
  • Continuous Improvementunmatched
  • Contract Requirementsunmatched
  • Corrective Actionunmatched
  • Cryptographyunmatched
  • Due Diligenceunmatched
  • Enterprise Protectionunmatched
  • Establish Prioritiesunmatched
  • External Auditunmatched
  • ISO (International Organization for Standardization)unmatched
  • Identity Data Managementunmatched
  • Industry Standardsunmatched
  • Industry/Trade Analysisunmatched
  • Information Assetsunmatched
  • Information Technology & Information Systemsunmatched
  • Information/Data Security (InfoSec)unmatched
  • Insuranceunmatched
  • Internal Auditunmatched
  • Internet Securityunmatched
  • Interpersonal Skillsunmatched
  • Intrusion Detection Systemsunmatched
  • Intrusion Prevention Systemsunmatched
  • Law Enforcementunmatched
  • Leadershipunmatched
  • Loss Preventionunmatched
  • Maintain Complianceunmatched
  • Mentoringunmatched
  • Operational Improvementunmatched
  • Problem Solving Skillsunmatched
  • Program Planningunmatched
  • Regulationsunmatched
  • Regulatory Complianceunmatched
  • Regulatory Requirementsunmatched
  • Reporting Skillsunmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Risk Managementunmatched
  • Security Analysisunmatched
  • Security Architectureunmatched
  • Security Information and Event Management (SIEM)unmatched
  • Security Monitoringunmatched
  • Software Patchesunmatched
  • Team Playerunmatched
  • Time Managementunmatched
  • Training Programunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder