VP, Information Security
TrueAccord
What You'll Do:
- Develop and implement an enterprise-wide information security strategy that aligns with business objectives and regulatory requirements.
- Work closely with other departments to identify, assess, and manage risks to the organization's information systems and data.
- Evaluate and implement appropriate security controls and technologies to protect the organization's information systems and data from unauthorized access, use, disclosure, modification, or destruction.
- Lead incident response and manage security incidents to minimize impact and ensure continuity of operations.
- Monitor and measure the effectiveness of security controls and technologies, and provide regular reports to executive leadership on the state of information security.
- Develop and maintain policies, procedures, and standards related to information security, and ensure that they are communicated and enforced throughout the organization.
- Stay current with the latest developments in information security and ensure that the organization is compliant with relevant laws, regulations, and industry standards.
- Manage the information security budget and ensure that resources are allocated effectively.
What We're Looking For:
- At least 10 years of experience in information security, with at least 5 years in a leadership role.
- Bachelor's degree or equivalent relevant experience
- Experience in developing and implementing information security programs that comply with regulatory requirements as well as business continuity and disaster recovery programs.
- Thorough understanding of financial services regulatory requirements, such as the Gramm-Leach-Bliley Act (GLBA), the Sarbanes-Oxley Act (SOX), the Payment Card Industry Data Security Standard (PCI DSS), and other industry-specific regulations.
- Experience with a diverse set of industry-standard Information Security Frameworks (e.g. COBIT, ISO, CIS, ISF, NIST, SOC 2, etc.)
- Experience in assessing and managing risks to information systems and data.
- Experience in incident response and managing security incidents.
- Experience with conducting compliance assessments and audits, including working with external auditors.
- Ability to communicate effectively with regulators and auditors on matters related to information security and compliance.
- Excellent communication skills, with the ability to communicate complex information and security concepts to non-technical stakeholders.
- Ability to lead and manage a team of information security professionals.
- Relevant industry certifications, such as CISSP, CISM, or CRISC, are strongly preferred.
- Possess strong leadership qualities, including a calm demeanor, especially under pressure
Something looks off?