×
Register Here to Apply for Jobs or Post Jobs. X

Chief Information Security Office-Strategy, Programs & GRC AVP

Job in New York, New York County, New York, 10261, USA
Listing for: Bank of China USA
Full Time position
Listed on 2026-07-27
Job specializations:
  • IT/Tech
    Information Security & Data Protection, Cybersecurity
Salary/Wage Range or Industry Benchmark: 65000 - 150000 USD Yearly USD 65000.00 150000.00 YEAR
Job Description & How to Apply Below
Location: New York

Established in 1912, Bank of China is one of the largest banks in the world, with over $3 trillion in assets and a footprint that spans more than 60 countries and regions. Our long-term outlook, institutional weight and global breadth provide our clients with a stable and reliable financial partner, whether in Corporate or Personal Banking or our Trade Services, Commodities, Financial Institutions and Global Markets lines of business.

Overview

This incumbent will provide Strategy, Programs, Governance, Risk and Compliance functions as required to fulfill BOCNY information security program requirements. This incumbent will provide Strategy Coordination, CISO Projects Management, Training & Culture, Metrics & Reporting, Governance, Risk Assessments, Compliance, Data Privacy and Identity functions as detailed below.

Strategy
  • Coordinate Information Security strategy in alignment with the BOCNY branch strategy.
  • Maintain strategic initiatives tracking and associated KRIs to track progress and execution of the objectives.
  • Conduct quarterly strategy reviews with the CISO team to ensure alignment and momentum continue. Adjust strategy as necessary.
  • Provide end-to-end project management function for all CISO led projects.
Programs
  • Manage all CISO programs, including but not limited to:
    Information Security Program, Data Privacy Program, and Training & Culture Program including Security Training, Phishing Campaigns, and Tabletop Exercises.
Governance
  • Establish and maintain Information Security policies and procedures.
  • Ensure CISO roles and responsibilities are clearly delineated and documented to ensure efficiency, create synergies and ensure TISR is being properly managed across first and second lines.
  • Periodically refresh and update TISR controls guidance in relevant policies and supporting procedures with detailed implementation guidance.
  • Develop, monitor, and track CISO policy adherence measures and metrics.
  • Provide all administrative functions for the Information Security Committee and all its sub-committees.
Risk
  • Establish and enhance a TISR framework that consists of the appropriate components to effectively manage TISR.
  • Conduct risk assessments of TISR for Projects, Third-Party, New Activities and Applications.
  • Develop and execute an TISR annual work plan of risk identification, assessment, and control evaluation and testing activities.
  • Review and contribute to the development and maintenance of the taxonomy for Risk, Process and Controls for TISR domains.
  • Catalog and oversee remediation of TISR issues include those arising from Audit and Regulatory exams, ITRM deep dives, root cause analyses and control testing.
  • Track observed control gaps and root causes and annually refresh CISO policy and procedures to reflect new and enhanced controls.
Compliance
  • Prepare and submit Audit Requests for evidence.
  • Anticipate audit requests and prepare comprehensive approach to for CISO policy and standards and associated implementation.
  • Prepare response evidence for IT/IS related regulatory exams.
  • Recommend changes to policy, process or procedures to align with OCC and other federal guidelines and regulations.
  • Evaluate and provide evidence of compliance for BOCNY Branch.
  • Liaison with LCD/RAO/IAD to ensure collaboration and partnership so that CISO can meet regulatory IT/IS requirements.
Data Privacy
  • Develop and implement strategies to ensure compliance with relevant privacy laws and regulations.
  • Stay up-to-date with changes in data privacy legislation and industry best practices.
  • Assist in the development and maintenance of privacy policies, standards and procedures.
  • Provide oversight and monitoring of privacy risk assessments by the FLUs.
  • Ensure all relevant processes reflect privacy requirements and comply with laws and regulations.
  • Plan and implement privacy training programs and communications.
  • Identify and assess privacy risks within the organization.
Metrics & Reporting
  • Manage all metrics and reporting for CISO, including:
    Operational, Executive & Board, Budget & Headcount, Dashboards.
Identity & Access Management
  • Establish and periodically update policies, procedures, and guidelines related to access recertification, incorporating industry…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary