What are the responsibilities and job description for the Chief Information Security Officer position at Conference of State Bank Supervisors?
CSBS Corporate, Washington, District Of Columbia, United States of America
Do not pass up this chance, apply quickly if your experience and skills match what is in the following description.
Job Description
Posted Thursday, April 11, 2024 at 4 : 00 AM
This position is responsible for providing vision, leadership, oversight, and management of CSBS cyber security policies, procedures, and practices. He / she directs, coordinates, plans, and organizes security activities throughout CSBS. Responsible for managing information security risks that affect the organization-wide strategic objectives through ongoing risk assessment. The Chief Information Security Officer (CISO) acts as the focal point for all communications related to security, both with internal staff and third parties, and works with a wide variety of people from different internal organizational units, bringing them together to manifest controls that reflect workable compromises as well as proactive responses to current and future information security risks compliant with relevant laws and regulations. The CISO also provides thought leadership in conjunction with his / her engagement in industry and government forums, and collaboration with state and federal cyber security experts and practitioners. Guidance, direction, and authority for information security activities are centralized for the entire CSBS organization with the CISO.
Essential Functions
To perform this job successfully, an individual must be able to perform each essential duty and responsibility satisfactorily. Reasonable accommodations may be made to enable an individual with disabilities to perform the essential functions. Other duties may be assigned to meet business needs.
- Member of the Senior Leadership Team (SLT) – The SLT is a group of peers with individual leadership roles at CSBS and a commitment to working across business units to achieve organizational goals. SLT members collaborate to ensure priorities and resources are aligned to successfully implement CSBS strategies. They are responsible for delivering on those strategies while also demonstrating our values to reinforce a positive and collaborative CSBS culture.
- People Manager – At CSBS, people managers lead and engage staff to maximize organizational performance. Understanding and implementing the organization’s strategies, people managers lead their teams through change with a focus on CSBS’ mission and vision and a commitment to our VIBE. People managers actively participate in the growth and development of their teams – delegating responsibility effectively and providing timely and actionable feedback on performance. Responsible for planning and organizing their team’s activity, people managers are also responsible for creating a positive employee experience while developing high-performing and innovative teams.
- Develop an information security vision and strategy that is aligned to organizational priorities and enables and facilitates the organization's business objectives, and ensures senior stakeholder buy-in and mandate.
- Develop and maintain the CSBS strategic security program and plan, taking into consideration business, fiduciary, and legal requirements, risk (likelihood and impact), and criticality; and building consensus among stakeholders. Monitor the effectiveness of the information security program and make recommendations for improvements.
- Develop and enhance an up-to-date information security management framework based on the National Institution of Standards and Technology Cyber Security Framework.
- Develop, maintain, and enforce CSBS’ cyber security policies and practices designed to protect sensitive corporate assets, ensure data privacy, and comply with laws and regulations, including the Federal Information Security Management Act (FISMA), Payment Card Industry (PCI) and the Criminal Justice Information System (CJIS) and other applicable -security laws.
- Maintain familiarity with AICPA System and Organization Control Reports such as SOC for Cybersecurity. Conduct periodic audits and assessments to ensure that the company is meeting its obligations under these regulations.
- Create a framework for roles and responsibilities with regard to information ownership, classification, accountability, and protection of information assets.
- Manage contractors and outsourcers providing technology services to CSBS, including managed security services, infrastructure engineering, operations, desktop support, and software development. Ensure compliance with the appropriate policies, laws, and regulations.
- Create a risk-based process for the assessment and mitigation of any information security risk at CSBS consisting of supply chain partners, vendors, consumers, and any other third parties.
- Work effectively with business units to facilitate information security risk assessment and risk management processes and empower them to own and accept the level of risk they deem appropriate for their specific risk appetite.
- Develop, maintain, and enforce CSBS security policies and procedures, for example :
- Identification of sensitive data and policies / practices regarding the identification of sensitive data as well as practices for information labeling, handling, and storage.
- Personnel security, including role-appropriate pre-employment background checks and security awareness training, ensuring necessary and appropriate content and compliance with requirements for each employee to take the training as well as the frequency of updated training.
- Network, infrastructure, and application security.
- Ensure technology solutions adhere to appropriate security practices and meet security requirements, including Software-as-a-Service (SaaS) contracts, Infrastructure-as-a-Service (IaaS) contracts, Platform-as-a-Service (PaaS) contracts, and customized software development solutions.
- Provide guidance and make recommendations to CSBS management and the Board of Directors with regard to the security characteristics (i.e., advantages and disadvantages) of various technologies and business practices.
- Ensure contracts with third parties contain appropriate security language, including data privacy and protection language required by state and federal laws. Develop, maintain, and manage a third-party security assessment program for key vendor relationships and third-party providers.
- Manage the CSBS incident response plan. Perform incident response planning, including developing, maintaining, and enforcing the CSBS incident response plan in addition to managing security incidents if / when they occur. This would include coordinating incidents, if applicable, with associated third-party providers and, if applicable, multiple regulatory organizations and stakeholders.
- Coordinate, provide leadership and management for security related audits and inspections. Interface as the primary contact with state and federal regulators and third-party contractors with regard to CSBS’ security posture and practices.
- Collaborate and liaise with the Chief Privacy Officer to ensure that data privacy requirements are included where applicable.
- Facilitate a metrics and reporting framework to measure the efficiency and effectiveness of the program, facilitate appropriate resource allocation, increase the maturity of the information security, and review it with stakeholders at the executive and board levels.
- Brief leadership and the Board of Directors annually, and as needed, on the security risk posture of the organization.
- Manage the information security budget, ensuring that resources are allocated appropriately to address the most critical risks. This includes identifying and prioritizing security initiatives and working with other leaders in the company to secure funding for these initiatives.
Additional Responsibilities
Minimum Qualifications
To perform this job successfully, an individual should possess the knowledge, skills, and abilities listed and meet the amount of education, training and / or work experience required.
Education and Experience
Knowledge, Skills, and Abilities
Requirements
Values Instilled Behaviors for Excellence
Member / Customer Service
Teamwork
Respect / Trust
Ownership / Engagement
Core Leadership Competencies
Achievement Oriented Thinking
Change Management
J-18808-Ljbffr