Bank of China logo
Bank of ChinaPosted 1 month ago

Chief Information Security Office-Strategy, Programs & GRC AVP

$65,000–$65,000 year

On-siteNew York City, New York, United States or New York, United States

Full TimeSenior LevelEnterprise

Job Summary

Coordinate Information Security strategy aligned with BOCNY branch goals, maintaining strategic initiatives tracking and KRIs while conducting quarterly reviews with the CISO team. Manage end-to-end project management for CISO-led initiatives and oversee all CISO programs, including Information Security, Data Privacy, and Training & Culture, covering security training, phishing campaigns, and tabletop exercises. Establish and maintain Information Security policies, procedures, and TISR frameworks, ensuring clear delineation of CISO roles and responsibilities across first and second lines. Conduct risk assessments for projects, third parties, and new activities, develop annual work plans for risk identification and control evaluation, and catalog remediation of issues arising from audits and regulatory exams. Prepare audit requests and response evidence for IT/IS regulatory exams, recommend policy changes to align with OCC and federal guidelines, and liaise with LCD/RAO/IAD to meet regulatory requirements. Develop and implement privacy strategies, monitor privacy risk assessments, and plan privacy training programs. Manage operational, executive, and board metrics and reporting dashboards, and establish access recertification policies to ensure consistency across all BOC applications.

Required Qualifications

  • Bachelor's Degree in Business, Risk, Data, Computer Science, Management Information Systems, Engineering, Mathematics, or related field
  • Minimum 5 years of work experience in Risk Management, Audit, IT/IS Operations, or other relevant functions
  • Minimum 3 years of experience in developing and executing IT/IS Risk programs, projects, and policies
  • Minimum 1 year of experience working with US Banking Regulations, financial industry standards, and industry standard IT/IS Risk Frameworks
  • Strong program, frameworks, project management development, implementation, and maintenance skills
  • Strong writing skills, especially in the context of governing documents, such as policies and standards
  • Strong verbal and interpersonal skills when working with a diverse group of stakeholders that can include senior management, business staff, and technical staff
  • Creative problem-solving skills
  • Strong organizational understanding and ability to navigate complex organizations
  • Results oriented and metrics driven
  • Understanding of financial services business and related processes and IT/IS risks and how to mitigate with well-designed, commercially sound controls
  • Operational and IT/IS risk assessment and management skills in first, second, and/or third line capacity
  • Sound and practical IT/IS risk management and program knowledge
  • Financial / banking industry, business line, and product knowledge
  • Familiarity with IT/IS Risk Management regulations, standards, and frameworks including NIST, ISO27002, FFIEC Guidelines, etc.
  • Risk identification and assessments of different types that are commensurate with the size and complexity of the financial institution
  • IT/IS risk management and audit principles and industry standard practices

Desired Qualifications

  • CISSP/CRISC/ or IT related certifications preferred

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce