The Information Security Officer (ISO) owns and is accountable for the credit union’s written Information Security Program (ISP), ensuring compliance with NCUA regulations (12 CFR Part 748), the GLBA Safeguards Rule, and applicable federal and state cybersecurity requirements. The ISO works in partnership with the credit union’s outsourced CISO partner (OneStep), the Information Security Governance Committee, and IT Security to direct the program’s execution, while retaining ultimate accountability to the Board, the VP of Enterprise Risk Management, and NCUA examiners. The ISO also partners with the VP of ERM to lead the credit union’s transition toward an internal information security department. The ISO provides independent oversight and challenge of information security and establishes information security governance and risk requirements.
Key Responsibilities
- Own and maintain the written Information Security Program (ISP), incorporating guidance from OneStep and the Information Security Governance Committee, with accountability for the program’s adequacy to the Board, VP of ERM, and NCUA examiners.
- Conduct annual risk assessments of information systems, third-party vendors, and data flows.
- Oversee the incident response plan (IRP), including compliance with the NCUA 72-hour cyber incident notification rule.
- Direct vulnerability management, penetration testing, and patch management programs, coordinating execution across external IS consultants and IT Security.
- Lead vendor/third-party risk management for cloud, core processor, and fintech relationships, including ongoing due diligence and performance monitoring of OneStep as a critical vendor.
- Align business continuity/disaster recovery planning with information security controls.
- Deliver information security awareness training and phishing simulation programs to staff and the Board.
- Serve as primary point of contact for NCUA/state examiners on IT and cybersecurity exams, including the ACET (Automated Cybersecurity Examination Tool) process.
- Serve as the credit union’s primary internal liaison to the outsourced CISO (external consultant), translating security guidance and recommendations into internal policy, procedures, and Board reporting.
- Serve as an active member of the Information Security Governance Committee, coordinating between external consultant’s CISO recommendations and internal execution via IT Security.
- Partner with the VP of Enterprise Risk Management to lead the transition from outsourced information security support (external consultant) to an internal information security department, including org design, staffing plan, and phased capability build-out.
- Collaborate with the VP of ERM on decisions regarding which functions remain outsourced to external consultant versus insourced as the department matures.
- Integrate information security risk into the enterprise risk register and ERM reporting cycle, in coordination with the VP of Enterprise Risk Management.
- Ensure escalation to the Board/Risk Committee is preserved: ISP updates and material risk findings are escalated through the VP of ERM for inclusion in Board/Risk Committee reporting at least annually, with direct Board access maintained for significant incidents or unresolved risk disagreements.
- Establish Information Security requirements for cloud, SaaS hosted, and externally managed environments, including identity, encryption, logging, configuration management, data protection, and third-party connectivity.
- Monitor cybersecurity threats, vulnerabilities, regulatory alerts, financial-sector threat intelligence, and emerging technology risks, and assess their relevance and potential impact to the credit union.
Job Skills
- ISO Standards
- Presentations
- Access Management Governance
- Incident Response and Cyber Resilience
- Regulatory Examination and Audit Management
- Executive and Board Reporting
- Control Objectives for Information and Related Technologies (COBIT)
- Security Technologies and Architecture
- Risk Management Frameworks
- Attention to Detail
- Continuous Learning
- Facilitation
- Vendor Management
- Identity Management Governance
- Cloud and SaaS Security
Qualifications & Experience
- 7+ years of progressively responsible experience in information security, cybersecurity, technology risk, information security governance, or a related discipline, with financial-services experience strongly preferred and credit-union experience highly desirable.
- Working knowledge of NCUA Part 748, GLBA, FFIEC guidance, and the ACET, NIST or equivalent framework.
- Three plus years in a leadership or supervisory capacity within information security, IT risk, or a related discipline required (e.g., team lead, security manager, or comparable supervisory role) recommended.
- Experience building or scaling an internal information security function, including staffing and organizational design, strongly preferred.
- Experience working within an enterprise risk management framework preferred.
- CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager) or equivalent senior information security certification required, CISSP and CISM combination preferred.
- CRISC (Certified in Risk and Information Systems Control) preferred.
- CISA (Certified Information Systems Auditor) preferred.
- GIAC (Global Information Assurance) / GSEC (GIAC Security Essentials) certifications preferred.
- CCSK (Certificate of Cloud Security Knowledge) /CCSP (Certified Cloud Security Professional) preferred.
- CGRC (Certified in Governance, Risk and Compliance) preferred.
- Computer Science (Bachelor's degree) or Information Security (Bachelor's degree) or Information Technology (Bachelor's degree) or equivalent experience.
Minimum Physical Requirements and Working Conditions
- Sitting for prolonged periods at a desk working on a computer.
- Frequent prolonged meetings in person or online.
- Traveling to various branches on occasion.
- Reaching, bending, twisting, turning on occasion.
- Lifting, pulling, pushing, and carrying up to 30 pounds on occasion.
- We'll make reasonable accommodations for qualified applicants and employees with disabilities.
Benefits and Pay
The expected pay for the Information Security Officer (ISO) is $110,667.18 to $150,000.24 per year.
This pay reflects the compensation we reasonably expect to offer for this role based on typical qualifications and market data. Offered pay may vary depending on the candidate’s experience, skills, and other relevant factors.
We cover 100% of employees single medical, drug, vision, and dental monthly health insurance premiums. Employees also love receiving paid volunteer time and our pay it forward program. Tuition assistance for higher education is another special way we invest in our workforce. Benefits include, Paid Time Off, 401(k) and 3% Employer Contribution, Health insurance, Paid time off, Vision insurance, Dental insurance, Prescription drug insurance, Tuition reimbursement, Life insurance, Flexible spending account, Disability insurance, Health savings account, Opportunities for advancement, Employee assistance program, Referral program, Retirement plan, Employee discount, Paid training, Professional development assistance, AD&D insurance, Volunteer time off, Credit union membership, Paid orientation, and more.
Make a difference one life at a time!
- Locations
- Honolulu, Hawaii, United States
- Education
- bachelor degree
- Experience
- 7+ years