Cybersecurity Risk Lead
Listed on 2026-08-01
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant
Join Camden National Bank
If you're looking to build your career at a forward-thinking organization with deep community roots and a vision for growth, success, and giving back, you've come to the right place.
We're your local community bank—and have been since 1875—that is committed to providing excellent customer service and giving back to our communities. We foster a collaborative, inclusive work environment as part of a close-knit team where your voice is valued and heard. Our highly engaged employees are rewarded for their performance and have ample opportunities for cross-training and advancement within the organization.
We've been named one of the best places to work in Maine, and offer robust benefits focused on your holistic well-being.
Position Summary:
The Cybersecurity Risk Lead is responsible for aligning cybersecurity capabilities, processes, and controls with regulatory requirements, industry frameworks, and organizational risk objectives. This role serves as the primary cybersecurity subject matter expert for technology risk analysis, architecture review, security strategy, control effectiveness, and framework alignment. The position partners with technology teams, business stakeholders, and third-party providers to ensure cybersecurity initiatives support the Bank's overall risk management strategy.
Essential Duties and Responsibilities:
- Align cybersecurity capabilities and controls with regulatory and industry frameworks including NIST CSF, GLBA, FFIEC guidance, and applicable banking regulations.
- Conduct cybersecurity risk assessments for technologies, projects, systems, and third-party solutions.
- Participate in security reviews of vendor technologies, SaaS platforms, cloud services, and technology integrations.
- Analyze and recommend security controls throughout system acquisition, development, implementation, and change management processes.
- Conduct threat modeling, attack path analysis, and architecture risk reviews using frameworks such as STRIDE, MITRE ATT&CK, or similar methodologies.
- Contribute to the administration, effectiveness, and continuous improvement of enterprise security controls and technologies, including firewalls, SIEM/SOAR, email security, incident response, vulnerability management, and data loss prevention.
- Develop and maintain cybersecurity standards, governance requirements, and security control frameworks.
- Provide cybersecurity guidance for enterprise initiatives involving cloud services, artificial intelligence, identity management, and emerging technologies.
- Partner with technology and business stakeholders to ensure security requirements are integrated into project planning and solution development.
- Assess the effectiveness of existing security controls and recommend improvements based on risk and business objectives.
- Support the development and maintenance of cybersecurity strategy, roadmap, and long-term security initiatives.
- Identify emerging risks, regulatory changes, and technology trends impacting the organization.
- Assist in the evaluation of compensating controls and risk acceptance decisions.
- Support audit, examination, and regulatory activities related to cybersecurity governance and risk management.
Basic Qualifications:
- Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or related field
- 5 years of cybersecurity, information security, technology risk, security architecture, or governance experience
- Experience with Firewalls, SIEM/SOAR, Email security, Incident Response, Vulnerability Management, and Data Loss Prevention
- Working knowledge of NIST CSF, GLBA, FFIEC guidance, and cybersecurity governance practices
- Experience with development, implementation, operation, and testing of information technology within regulated environments
- Understanding of security controls across cloud, network, identity, endpoint, and application domains
- Experience assessing technology implementations and recommending risk-based security controls.
Preferred Qualifications:
- CISSP, CRISC, CISM, CCSP, or similar certification
- Risk management experience
- Experience with Zero Trust, SASE/SSE, ZTNA, or cloud security architecture
- Understanding of securing AI tools, AI integrations, and AI oversight
- Experience with third-party risk management and vendor security assessments
- Prior experience working in a regulated environment or financial services industry
Skills and Abilities:
- Strong risk analysis and problem-solving skills
- Ability to translate complex cybersecurity concepts into business-focused recommendations
- Technical writing expertise
- Strategic planning and project management capabilities
- Strong Stakeholder relationship management skills
- Ability to balance security requirements with business objectives
- Ability to influence and collaborate across teams
The statements contained herein reflect general details as necessary to describe the principal functions for this job, the level of knowledge and skill typically required, and the scope of responsibility, but should not be…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).