Demo

Director, InfoSec and Compliance

Soni Resources
Malvern, PA Full Time
POSTED ON 2/26/2025
AVAILABLE BEFORE 5/18/2025

Our client is seeking a hands-on and forward-thinking individual to be their Director of Information Security & Compliance. This role will be responsible for leading and overseeing the company's information security governance program. This position demands deep technical knowledge and skills to actively assess and test the adequacy of the technical security architecture as a key component of the role.

Reporting to the Chief Risk Officer (CRO) and collaborating closely with key technology stakeholders, this role will develop and implement comprehensive information security governance strategies, policies, and procedures. These efforts will ensure the organization's information assets-including internal data, devices, SaaS platforms, customer PII, and third-party interfaces-are monitored, controlled, and safeguarded in alignment with regulatory requirements for financial services companies.

Key Responsibilities

Information Security Governance

  • Create, implement, and oversee the company's information security governance plan and program to establish a strong information security risk posture aligned with the CRO's vision and the company's current and future needs.

Information Risk Management

  • Perform information risk inventories and assessments to prioritize cyber and information security audits.
  • Identify and assess security risks through testing and controls evaluation.
  • Develop strategies to mitigate risks, monitor progress, and make remediation recommendations to management and executive leadership.
  • Policies and Procedures Development

  • Establish and enforce information security policies, standards, guidelines, and procedures.
  • Collaborate with stakeholders to monitor compliance and provide training, mentorship, and recommendations for improvements.
  • Security Monitoring and Reporting

  • Actively monitor security exception reporting and practices within the information security architecture.
  • Oversee open items in the MS Azure environment, including cloud-based controls, secure coding practices, application development adherence to SDLC, and Vanta platform administration.
  • Incident and Business Resumption Response

  • Evolve security incident, business continuity, and disaster recovery processes in collaboration with the CRO and CTO.
  • Participate in annual compliance testing and develop federally compliant customer notification processes.
  • Compliance and Regulatory Alignment

  • Manage the company's information security posture within applicable regulations (e.g., NCUA, FDIC).
  • Prepare for PCI DSS 4.0 and SOC II reviews.
  • Create a CIS18 v8 framework within Vanta and ensure compliance with laws and regulations such as CCPA, TCPA, GLBA, and industry standards like FFIEC and ACET.
  • Vendor Management

  • Evaluate and manage third-party vendors and service providers from an information security perspective to ensure compliance with security requirements.
  • Leadership

  • Collaborate with the CRO and key stakeholders to assess and address information security risks while aligning solutions with strategic initiatives.
  • Stay ahead of emerging threats and technologies to continuously improve the security posture.
  • Co-chair the Information Risk Committee with the CRO to implement effective governance practices.
  • Skills and Experience

    Required :

  • 10 years of experience in senior management, with at least 5 years in a senior information security leadership role.
  • Deep technical knowledge of IT operations, controls, and cloud-based environments, particularly MS Azure.
  • Experience in a regulated industry such as financial services.
  • Background in information technology audit and testing.
  • Proven ability to lead, motivate, and manage complex relationships, teams, and projects.
  • Strong analytical and problem-solving skills for addressing security challenges.
  • Preferred :

  • Working knowledge of regulations such as NCUA, FDIC, FFIEC, ACET, and NIST.
  • Certifications such as CISA, CISSP, or CISM.
  • Membership in ISACA or IIA.
  • Bachelor's degree in information technology, business, or a related field.
  • Ability to be on-site in Paoli, PA 2-3 days / week.
  • Candidate must be local to the Malvern, PA area.
  • If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
    Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

    What is the career path for a Director, InfoSec and Compliance?

    Sign up to receive alerts about other jobs on the Director, InfoSec and Compliance career path by checking the boxes next to the positions that interest you.
    Income Estimation: 
    $220,784 - $286,649
    Income Estimation: 
    $270,069 - $359,305
    Income Estimation: 
    $220,784 - $286,649
    Income Estimation: 
    $270,069 - $359,305
    Income Estimation: 
    $194,072 - $240,547
    Income Estimation: 
    $220,784 - $286,649
    Income Estimation: 
    $87,093 - $107,335
    Income Estimation: 
    $111,725 - $147,313
    Income Estimation: 
    $112,673 - $137,290
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $152,549 - $188,894
    Income Estimation: 
    $194,072 - $240,547
    Income Estimation: 
    $135,994 - $168,063
    Income Estimation: 
    $161,209 - $233,553
    View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

    Job openings at Soni Resources

    Soni Resources
    Hired Organization Address Philadelphia, PA Full Time
    We are seeking an experienced Database Engineer to design, implement, and optimize SQL Server and cloud-based database s...
    Soni Resources
    Hired Organization Address Philadelphia, PA Full Time
    Soni's Client is seeking a Payroll Accountant to join their team and play a crucial role in analyzing payroll data, ensu...
    Soni Resources
    Hired Organization Address Conshohocken, PA Full Time
    We are seeking a Senior UI / UX Designer / Developer to join our clients innovative product and engineering team. In thi...
    Soni Resources
    Hired Organization Address New York, NY Full Time
    A New York based client of ours is breaking out a dedicated IT Systems team and looking someone to truly own MS Exchange...

    Not the job you're looking for? Here are some other Director, InfoSec and Compliance jobs in the Malvern, PA area that may be a better fit.

    Director of Compliance

    Contemporary Staffing Solutions, Sewell, NJ

    Director of Compliance

    Parke Bank, Sewell, NJ

    AI Assistant is available now!

    Feel free to start your new journey!