Director, Integrated Security
Listed on 2026-07-09
-
Security
Information Security
Description
Cornerstone Capital Bancorp, Inc., headquartered in Houston, is a Texas-based financial services company dedicated to helping families, businesses, and communities thrive. Through its primary subsidiary, Cornerstone Capital Bank, the organization operates a community and business banking franchise alongside a premier national home lending, servicing, and home insurance platform-based financial services company dedicated to helping families, businesses, and communities thrive.
Guided by a core Mission, Vision and Convictions statement, Cornerstone operates 17 full-service banking locations across major Texas markets and more than 150 mortgage offices nationwide. The company has served nearly 700,000 customers through its family of brands, including Cornerstone Home Lending, Roscoe Bank, Peoples Bank, Cornerstone Servicing, and Cornerstone Insurance. Supported by 1,600 team members, Cornerstone is consistently recognized as a Fortune-certified Great Place to Work and a Top Workplace.
Formed through the combination of Cornerstone Home Lending and The Roscoe State Bank, Cornerstone brings more than a century of experience and is the highest‑capitalized new bank in Texas history.
We honor God by using our talents to make a positive difference in the lives of our Team Members, Clients, Shareholders, Communities, and the People who provide services to us.
Who we are looking forThe Director, Integrated Security, is responsible for developing, implementing, and maintaining a comprehensive information security program to protect the bank's data and systems, ensuring compliance with regulations and industry standards. Areas of oversight include Enterprise Security Governance, the Bank's policies and programs for Information Security, IT Risk Management, and Corporate Security.
What you’ll do Security Risk Framework and Policy- Establish and maintain the enterprise security risk management framework, including risk appetite statements, policies, minimum control standards, and risk taxonomies that the first line is required to implement.
- Review and challenge first‑line policies, standards, and procedures to confirm alignment with regulatory expectations, the Bank’s risk appetite, and industry frameworks (e.g., NIST CSF, FFIEC CAT, ISO 27001).
- Perform independent assessments of the first line’s identification, measurement, and management of security risks, including review of risk and control self‑assessments (RCSAs), issue management, and key risk indicators.
- Provide credible challenge to first‑line risk treatment decisions, exception requests, and risk acceptances; elevate unresolved concerns through governance committees to executive management and the Board.
- Monitor and independently assess first‑line compliance with applicable laws, regulations, and supervisory expectations (e.g., GLBA, FFIEC IT Handbook, NYDFS Part 500, SEC cybersecurity disclosure rules, state privacy laws); track remediation of regulatory findings and matters requiring attention (MRAs).
- Partner with the Chief Privacy Officer to provide oversight and challenge of the first line’s implementation of GLBA’s privacy provisions and other consumer data protection requirements.
- Establish minimum standards for the first line’s incident response, business resilience, and cyber recovery programs; review and challenge the design, testing, and continuous improvement of those programs.
- Serve in an advisory and oversight capacity during material security incidents; perform independent post‑incident reviews of first‑line response effectiveness and root‑cause remediation, and report findings to executive management and the Board.
- Establish enterprise expectations for the first line’s security awareness and role‑based training programs, and independently assess their effectiveness through metrics, phishing test results, and behavioral indicators.
- Monitor and report on the enterprise security risk culture; identify gaps and recommend improvements to executive management and the Board.
- Set…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).