Jobs and Careers
AM
VP, Information Security
American Credit AcceptanceSpartanburg, United Statesfull_timeVerifiedPosted 24 Nov 2023
About the role
Overview
The Vice President, Information Security Officer (ISO) will report directly to the General Counsel, and be responsible for:
- Establishing cybersecurity strategy
- Implementing and monitoring the security of information assets with current tools and technologies
- Directing day to day security operations, incident response, and mentor a team of security professionals
- Working closely with business leaders, technology leaders, and privacy professionals to assure the organization meets current standards, complies with regulatory requirements, and addresses the future direction of the business.
Detailed Responsibilities
- Finally, the ISO must be able to anticipate emerging threats as they relate to the changing business environment and work with the organization to address and mitigate any risks associated with these threats. Teamwork with legal, vendor management, IT operations, and the business are critical.
- The ISO will manage the Information Security Office functions and will be responsible for design, implementation, and maintenance of controls and procedures to ensure the integrity and security for all computer-based systems and networks across all technical platforms. In addition, the ISO will oversee the identity management lifecycle and work with the vendor management organization to assure third party vendors and contractors meet company standards. The ISO will work closely with other business groups and stakeholders, including Legal, Compliance, Audit and Risk, ensuring the protection of information and assets including data, systems, databases, networks, and other resources.
- The ISO will recommend information security investments which mitigate cyber and insider risks, strengthen defenses, and reduce vulnerabilities for development, internal, and client facing systems and products. In this role, the ISO must be able to not only define a strategic vision, but must also be able to implement and execute against it. The ability to communicate to peers, subordinates, and executive management are critical to the success of the ISO.
Essential Functions
Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
- Develop, implement, and monitor a strategic, comprehensive enterprise information security and risk management program.
- Leverage information security experts and technology to support a secure infrastructure, secure applications, and overall data security; lead strategic security planning with IT Operations, development teams, and users across the organization.
- Develop, communicate, and ensure compliance with organizational security policies and standards; proactively work with business units to implement practices that meet defined policies and standards for information security.
- Create and manage information security and risk management awareness training programs for employees, contractors, and approved system users.
- Work directly with business units to facilitate IT risk analysis and risk management processes; identify acceptable levels of risk, and establish roles and responsibilities with regard to information classification and protection.
- Provide subject matter expertise to executive management on a broad range of information security standards, best practices, and compliance requirements.
- Work with developers and architects to ensure security is appropriately built in the development cycle. Coordinate the performance of internal and external network and systems vulnerability assessments and penetration tests.
- Facilitate the review and verification of all new third party vendors with respect to their information security policies and procedures.
- Coordinate organizational efforts in response to security events.
- Develop business-relevant metrics to measure the efficiency and effectiveness of the program, facilitate appropriate resource allocation, and increase the maturity of the security program.
- Provide oversight and accountability of the day-to-day security operations.
- Review and oversee all application projects impacting information security.
- Provide oversight and accountability of the day-to-day security operations and/or other administrative areas
- Assess information security risk as well as conduct functionality and gap analyses to determine the extent to which key business areas and infrastructure comply with statutory and regulatory requirements.
Qualifications
- 10+ years of experience in the information security field and 5+ years of leadership in an information security role.
- Experience with financial industry compliance regulations.
- Exp
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s