Executive Director, Information Security
San Antonio Home Office I, United States
USAA
USAA offers competitive auto rates, no-monthly service fee banking and retirement options to all branches of the military and their family. Join now and let us serve you.Why USAA?
At USAA, our mission is to empower our members to achieve financial security through highly competitive products, exceptional service and trusted advice. We seek to be the #1 choice for the military community and their families.
Embrace a fulfilling career at USAA, where our core values – honesty, integrity, loyalty and service – define how we treat each other and our members. Be part of what truly makes us special and impactful.
The Opportunity
We are seeking an Executive Director, Information Security that is passionate about building world-class Information Security programs. This position reports directly to the USAA CISO and will be responsible for the execution of all Information Security programs and projects. This will include the planning, organizing, and implementation of large, complex, strategic programs and projects. These are typically highly visible initiatives with significant impact on Cyber Security and range across multiple disciplines, businesses, and/or organizations. You will be responsible for advancing the organizational strategic and business objectives through the alignment and integration of all programs and projects under their purview, and the coordinated management of all Program and Project Managers. This role will establish a project management and delivery framework and develop the functions and team in alignment with the IT Transformation Office. You will work closely with the CISO(s), Information Security Managers, Infrastructure, IT and Business teams to manage a portfolio of projects through the full lifecycle including requirements, design, development, testing, and implementation. The ideal candidate will have broad knowledge of Information Security functions and technologies (including digital/cloud) as well as prior experience building and running an Information Security Delivery or Project Management function in the US for a large bank with merger/acquisition transformational change.
We offer a flexible work environment that requires an individual to be in the office 4 days per week. This position can be based in one of the following locations: San Antonio, TX, Plano, TX, Phoenix, AZ, Charlotte, NC.
What you'll do:
Manages assigned information security functional area’s day to day operations, programs, architecture / infrastructure support, analysis, and oversight of compliance related tasks and activities
Sets the strategy and future roadmaps for tools and processes – including the use of emerging technologies and practices, establishing lifecycle governance within functional area
Provides direction and leads strategic control issue(s), developments and journeys including funding/budgets, staff alignment, third party consulting, deadlines, issues and troubleshooting, risks, and outcomes
Responds to, engages, and guides internal/external auditors and examiners to ensure accuracy, appropriate communication quality and business outcomes
Leads vision and creates conditions for related operational solutions to increase enterprise workforce efficiency, increase business agility and workforce scalability, reduce information security risk, meet compliance requirements, and provide ongoing and future information security policy/practice frameworks
Consults and engages with aligned business executives on their requirements and related business management risks, directions, changes and issues
Accountable for the teams that identify, measure, track and manage information security programs and strategies in a manner that meets compliance and regulatory requirements
Ensures effective written risk and compliance policies, procedures and controls are in place supporting all business activities, processes, systems, strategies, and implementations
Promotes, facilitates, and sponsors information security opportunities in support of major improvements to processes and systems
Builds and oversees a team of employees for assigned functional area through ongoing execution of recruiting, development, retention, coaching and support, performance management, and managerial activities
Ensures risks associated with business activities are effectively identified, measured, monitored, and controlled in accordance with risk and compliance policies and procedures
What you have:
Bachelor’s Degree in Information Security, Information Technology, Computer Science, Business Administration, Information Systems/Management or related field; 4 additional years of related experience (in addition to the minimum years of experience required) may be substituted in lieu of degree
10 years of experience in a progressive technical discipline (e.g. cyber security, identity and access management, information assurance and governance, risk management etc.) with a proven track record of leading comparable operations and programs (e.g. information governance / security, electronic information, privacy, eDiscovery, records management, operational risk management) and delivering results in a complex matrix environment
6 years of relevant experience in a supervisory role in IT, cybersecurity, or operational risk management
4 years of people leadership experience in building, managing, and/or developing high-performing teams
Well-versed in regulations and standards related to risk management and information security (FFIEC, HIPAA, Gramm-Leach-Bliley, FFIEC Cybersecurity Assessment Tool, NIST Cybersecurity Framework and the Payment Card Industry Data Security Standard)
Experience collaborating with key resources and stakeholders, influencing decisions, and managing work to achieve strategic goals
Executive-level business acumen in the areas of business operations, industry practices and emerging trends
Demonstrated ability to communicate technical information to a non-technical audience
Technical knowledge and understanding of the field of information systems security, including such areas as identity and access management, cybersecurity engineering, security program policies, processes, and procedures
Demonstrated experience in vendor contract management and management of distributed development teams and resources
Demonstrated financial acumen involving budgets, forecasting, and executing on the budgets for applicable information security, cybersecurity, or technology support function
Technical knowledge and understanding of policy formulation, information security management, and business risk management
Understanding of the programs necessary to achieve compliance with relevant information security and cybersecurity regulations at an enterprise level
What sets you apart:
25 + years professional experience driving large scale multiple million-dollar programs in top 5 USA Banks
20+ years project management experience leading complex projects and budgets greater than $100M
7+ years’ experience in US Regulatory programs in top 10 USA Banks, delivering regulatory remediations programs and presenting to US regulators (FRBB or OCC)
5+ years’ experience in banking with Information Security, preferably within a merger/acquisition environment with significant transformational change with people, process and technology
3+ years’ experience with digital banking deployed on public cloud platforms and leveraging Artificial Intelligence technologies
Experience leading Global vendors to support Regulatory remediations across Cloud Infrastructure, Info Security, Financial Applications, Platform Operations, and Governance, Risk & Compliance
Broad knowledge of Information Security frameworks (e.g. NIST, FFIEC), regulations (SOX, GLBA, NYDFS), and functions (Anticipate, Protect, Detect, Respond) and cyber controls
Expertise with information security project management, portfolio management, working across IT and Business functions and with Second and Third lines of Defense, and Regulators
Salary Range: $195,230 - $351,410
Compensation: USAA has an effective process for assessing market data and establishing ranges to ensure we remain competitive. You are paid within the salary range based on your experience and market data of the position.
Employees may be eligible for pay incentives based on overall corporate and individual performance and at the discretion of the USAA Board of Directors.
The above description reflects the details considered necessary to describe the principal functions of the job and should not be construed as a detailed description of all the work requirements that may be performed in the job.
Long Term Incentive Plan: Cash payment for Executive level roles only, representing a cash payment which is both time and performance based.
Benefits: At USAA our employees enjoy best-in-class benefits to support their physical, financial, and emotional wellness. These benefits include comprehensive medical, dental and vision plans, 401(k), pension, life insurance, parental benefits, adoption assistance, paid time off program with paid holidays plus 16 paid volunteer hours, and various wellness programs. Additionally, our career path planning and continuing education assists employees with their professional goals.
For more details on our outstanding benefits, visit our benefits page on USAAjobs.com.
Applications for this position are accepted on an ongoing basis, this posting will remain open until the position is filled. Thus, interested candidates are encouraged to apply the same day they view this posting.
USAA is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Tags: Artificial Intelligence Banking CISO Cloud Compliance Computer Science FFIEC GLBA Governance HIPAA IAM NIST Privacy Risk management SOX Strategy
Perks/benefits: Career development Competitive pay Flex hours Flex vacation Health care Insurance Team events Wellness
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.