Information Security Officer
Listed on 2026-10-03
-
IT/Tech
Cybersecurity, Information Security & Data Protection
If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.
INFORMATION SECURITY OFFICERFull Time Los Angeles, CA, US
3 days ago Requisition
Salary Range: $ To $ Annually
SUMMARY The Information Security Officer is responsible for developing, implementing, and maintaining the Bank’s information security program, strategy, and governance framework. This role provides independent oversight of information security risk and helps protect the Bank’s information assets and technology infrastructure from internal and external threats. The position leads initiatives supporting regulatory compliance, industry standards, security best practices, and a strong culture of security awareness across the organization.
The position reports material information security risks, incidents, program performance, and resource needs to executive management and the Board or its designated committee.
Maintain sufficient organizational authority and independence to escal…
REQUIRED DUTIES
- Develop, implement, and continuously enhance the Bank’s Information Security Strategy, Architecture, and Roadmap to align with business objectives, risk appetite, and regulatory requirements.
- Establish and maintain enterprise-wide information security policies, standards, procedures, and controls consistent with industry best practices and applicable regulations.
- Monitor emerging cybersecurity threats, vulnerabilities, and industry trends, adapting security strategies and controls to address evolving risks.
- Develop, maintain, and oversee a documented, enterprise-wide information security risk assessment process that identifies reasonably foreseeable internal and external threats, evaluates the likelihood and potential impact of those threats, assesses the sufficiency of existing controls, prioritizes residual risks, and tracks remediation to completion.
- Lead the Bank’s cyber resilience programs, including planning, testing, coordination, and ongoing improvement, in coordination with the Bank’s enterprise business continuity management program.
- Oversee information security risk associated with third parties, service providers, cloud environments, and technology supply chains, including due diligence, contract requirements, ongoing monitoring, incident coordination, resilience considerations, and timely remediation of identified weaknesses.
- Establish and oversee identity and access management, privileged access, authentication, data classification, data loss prevention, encryption, vulnerability management, secure configuration, patch management, logging, monitoring, and other key control processes based on the Bank’s risk assessment.
- Direct cybersecurity incident preparedness, detection, response, investigation, containment, recovery, and post-incident remediation activities; coordinate required notifications to regulators, law enforcement, customers, and other stakeholders with Legal, Compliance, and executive management; and ensure lessons learned are incorporated into the information security program.
- Coordinate with internal and external auditors, regulators, and independent assessors; provide complete and timely information for security-related reviews; track findings and corrective actions to completion; and preserve the independence of audit and other assurance functions.
- Ensure compliance with applicable laws, regulations, and supervisory guidance, including the Gramm-Leach-Bliley Act, the Interagency Guidelines Establishing Information Security Standards, applicable FFIEC guidance, federal computer-security incident notification requirements, California privacy and breach-notification requirements, and other requirements applicable to…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).