Unclassified - Edgewood, MD

posted 3 months ago

Full-time - Senior
Edgewood, MD

About the position

The Information Security Officer at Aberdeen Proving Ground Federal Credit Union (APGFCU) is a pivotal role that oversees the enterprise-wide Information Security Management Program. This position is responsible for ensuring the integrity, confidentiality, and availability of information owned, controlled, or processed by the organization. Reporting directly to the Senior Vice President of Fraud and Security, the Information Security Officer functions independently from the IT department, providing critical analysis, oversight, and recommendations regarding the credit union's information security and vulnerability management across all assets, including those that are outsourced. In this role, the Information Security Officer will engage with various levels of leadership within the credit union, including Executive and Management Teams, Board Members, and support staff. The officer will manage the Information Security Analyst and will be responsible for overseeing compliance with regulatory requirements, data privacy, and the protection of APGFCU's intellectual property. Key responsibilities include monitoring program data, access control tables, and user profiles, as well as ensuring that disaster recovery and business continuity processes are effectively tested and updated. The Information Security Officer will also play a crucial role in threat management by reviewing security monitoring systems and user activity, maintaining situational awareness of all systems, and conducting vulnerability assessments on a quarterly basis. This position requires a proactive approach to protecting the credit union's information assets and ensuring compliance with industry standards and regulations. The officer will also be involved in policy development, vendor management, and external audits, ensuring that the credit union's information security policies are up-to-date and effectively enforced.

Responsibilities

  • Oversee and recommend acceptable levels of risk for the credit union.
  • Ensure the integrity, confidentiality, and availability of information owned, controlled, or processed by the organization.
  • Serve as the process owner of information assurance activities related to member and business information.
  • Interact with various leaders to ensure consistent application of policies and standards regarding cyber and information security.
  • Report regularly to the Executive Team and Board of Directors regarding the status of the Information Security Program and Audit.
  • Monitor program data and access control tables; design computer system access reports to identify security violations or intrusions.
  • Ensure disaster recovery and business continuity processes are tested and updated as needed.
  • Collaborate with the IT department for risk review and mitigation.
  • Provide security awareness training to employees during onboarding.
  • Conduct vulnerability assessments on a quarterly basis.
  • Review security documentation for new and ongoing vendors to ensure effective security controls are in place.

Requirements

  • Bachelor's degree in Systems Management or related field required; experience can be credited in lieu of education.
  • Minimum of 7-10 years of experience with exposure to business and technical requirements, security and control frameworks, and internal control procedures.
  • Professional industry certifications such as CISSP, networking, operating systems, and security credentials required.
  • Strong technical analytical skills and ability to relate business requirements and risks to technology implementation.
  • Knowledge of risk assessment procedures, policy formation, and role-based authorization methodologies.
  • Strong oral and written communication skills to convey technical information to non-technical audiences.
  • High proficiency with office systems, including Windows and Microsoft Office software.

Nice-to-haves

  • Specialized training pertaining to the systems in place and continuing education a plus.
  • Expert knowledge of laws, cyber security standards, and compliance frameworks such as FFIEC, GLBA, ISO, NIST, COBIT, SOX, HIPAA, and PCI DSS.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service