What are the responsibilities and job description for the Information Security Officer position at Tropical Financial Credit Union?
Description
Summary : Individuals in the job are responsible for assisting Tropical Financial Credit Union in the achievement of its purpose of guiding members successfully through the financial marketplace. The Information Security Officer (ISO) is responsible for the planning, coordination, and oversight of the Credit Union's Information Security Program and for ensuring that the Credit Union's information is secure from unauthorized access, protected from inappropriate alteration and that the data is physically secure. The ISO will work closely with the Credit Union's Vice President of Administration / Chief Security Officer and supervise a team of Information Security Analysts to keep current the Credit Union's Information Security Policies and Procedures including Risk Management, monitoring, technical standards, employee awareness, and the Credit Union's Disaster Recovery and Business Continuity Plans. The ISO will also oversee the investigation of security breaches and violations and will provide ongoing reporting to senior management. Additionally, this position is responsible for ensuring that the Credit Union adheres to the established Member Information Security Policy and related regulations.
Essential Duties and Responsibilities include the following. Other duties may be assigned.
- Provide service that meets the Service Standards defined by Tropical Financial Credit Union and achieve annual goals that are established through the Performance Management Process.
- Responsible for developing, implementing, and maintaining the Credit Union's overall member / employee information security program's policies and procedures.
- Responsible for hiring, mentoring, coaching and feedback, evaluation, scheduling and developing of direct report employees. The ISO will foster a culture of continuous improvement, focusing on providing guidance for ongoing training, development, and performance support to ensure team success and growth.
- Oversee and report on strategic technological Security related activity to the Board of Directors and appropriate committees. Additionally leads the Corporate Information Security Committee; including the coordination of meetings and reporting.
- Provide oversight of the implementation of security-related practices to ensure company-wide adherence to security policies and standards as well as applicable federal and state regulations.
- Responsible for developing, implementing, and maintaining the Credit Union's Enterprise Risk Management program. Reviews all internal / external audit reports related to IT security.
- Assists the CSO in development, implementation and testing of the Disaster Recovery and Business Continuity Plans. Responsible for monitoring the Credit Union's network (LAN / WAN / Internet / Intranet)
- Review and manage daily / weekly / monthly reports of the Firewall and Intrusion Detection and Prevention Systems.
- Responsible for overseeing and investigating security incidents, including data breaches and violations to minimize damage and recover quickly.
- Conduct monthly vulnerability assessments and coordinate remediation efforts as necessary with the IT Department.
- Evaluate and provide network system security architecture and functionality recommendations to ensure confidentiality, integrity, and availability of corporate-owned data.
- Evaluate and provide application security and control recommendations to ensure confidentiality, integrity, and availability of corporate-owned data.
- Assists in development, implementation, and maintenance of the information security awareness training program for the Credit Union's Responsible for developing and implementing the Credit Union's employee and member security awareness programs.
- Responsible for developing monthly metrics and reports to provide an overview of information security activities.
- Responsible for overseeing third party providers ensure appropriate measures are in place to protect the Credit Union's information security assets as per designated guidelines. Oversight responsibilities include :
Ensuring minimum information security contract requirements are met.
BSA Compliance : every employee is required to uphold the credit union's compliance with the Bank Secrecy Act and anti-money laundering policies and procedures. Specific functions within TFCU will take into consideration the awareness of unusual or suspicious activity that is relevant to the department.
Requirements
Qualifications : To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill and / or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Education and / or Experience :
Primary Education : Bachelor's degree in Information Technology, MIS, Computer Science, Computer Engineering or a related field is preferred; may substitute years of experience and certifications in lieu of a undergraduate degree.
Experience : Eight or more years' experience in the following areas of expertise; operational audit, security administration, access control, encryption, internet security, application security, risk assessments, security design and implementation.
Prior experience working on IT projects as a contributor or manager. General knowledge of Cobit and / or ISO auditing standards. Experience leading a team of professionals through coordination, delegation and accountability with multiple activities, team members and work / projects in a high pace environment.
Certifications : Security Manager (CISM) , Certified in Risk and Information Systems Control (CRISC) , Microsoft Certified Systems Administrator : Security (MCSA : Security) are required .
Certified Information Security Systems Professional (CISSP), Certified Information Systems Auditor (CISA), Certified Information, SysAdmin, Audit, Networking, Security (SANS) certification desired. General knowledge of generally accepted account principles (GAAP) and / or auditing standards (GAAS) are preferred.
Physical Demands : The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. While performing the duties of this job, the employee is regularly required to talk or hear. The employee frequently is required to stand, walk, sit and use hands to handle or touch. The employee is occasionally required to reach with hands and arms. The employee must occasionally lift and / or move up to 10 pounds. Specific vision abilities required by this job include close vision, and ability to focus. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.