Information Security Program Manager
VeleraAbout the role
Join the People Helping People
Velera is the nation’s premier payments credit union service organization (CUSO) and an integrated fintech solutions provider. The company serves more than 4,000 financial institutions throughout North America, operating with velocity to help our clients keep pace with the rapid momentum of change and fuel growth in the new era of financial services. Our purpose: We accelerate partners’ success through innovative financial technology solutions and inspired service.
The Opportunity
The Information Security Program Manager will be responsible for ensuring the organization meets information security standards and objectives to protect sensitive data and systems from threats. This includes assisting with setting security requirements and baselines, developing and implementing security policies, conducting risk assessments, and ensuring compliance with relevant regulations. They also work with various teams (internal and external) to mitigate risk, integrate security measures into business operations, and foster a security-conscious culture.
Day in the Life
Supports the development, implementation, monitoring and communication of the information security program and related activities
Works in collaboration with key stakeholders and technical teams across the organization to ensure that the information security program and requirements aligns with business objectives, mission, and values by developing comprehensive processes, strategies and tactics
Maintains a current understanding of emerging cyber threats, and new solutions which may impact cloud and on premises environments
Maintains penetration testing program, conducts red team and blue team exercises, performs internal and external penetration testing, and application vulnerability assessments to identify potential threats
Performs focused information security risk assessments of existing or new business processes, services and technologies, along with business counterparts
Communicates security risk assessment findings to information stakeholders, security leadership, risk management, information governance, and internal audit as necessary
Maintains strong working relationships with individuals and groups involved in managing information security risks across the organization
Facilitate the organization by implementing the risk management process and assisting individuals in identifying, analyzing, and evaluating risks in accordance with policy
Identifies opportunities to improve risk posture, developing solutions for remediating or mitigating risks and assessing the residual risk
Performs review and validation of all deliverables for SOC, Incident Response (IR), Threat Intelligence, Threat Hunting, to improve overall security posture
Provides consultative advice to cybersecurity governance or security teams that enables them to suggest informed risk mitigation decisions
Provides knowledge and expertise in government regulatory processes and documentation, including but not limited to Risk Management Approach (RMA), National Institute of Standards and Technology (NIST) standards, and policies and procedures
Translates technical information security requirements into clear, actionable policies that employees can understand and follow
Monitors and audits compliance of cybersecurity policies to identify gaps
Perform all other duties as assigned
Qualifications
BS or MA in Computer Science, Information Security, or equivalent combination of education and experience within Information Technology
8+ years of experience in cybersecurity, with focus in the areas of information risk analysis, security engineering or security architecture role
5+ years of experience with regulatory compliance and information security management frameworks (e.g., ISO 27000, COBIT, NIST CSF, PCI DSS)
Must possess at least one of the following certifications CISSP, CCSP, CISM, CEH or equivalent security certification required
Experience in application development security and relevant tools such as SAST, DAST, SCA, RASP, and IAST
Experience managing and maintaining a penetration testing program
Experience in performing penetration testing, secure code review, static, dynamic and manual source code review
Experience in program and project management
Experience in cybersecurity strategy planning
Experience identifying and assessing risks to the organization's business
Experience crafting and executing Information Security initiatives, including capturing and redef
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s
Similar roles
INFORMATION SECURITY MANAGER - 65000552
State of Florida
$83,000/yr
Sales Leadership Development Program Information Session - 3 Day Blinds (Virtual Event) 3/2
3dayblindsmanagementandsupport
Senior Analyst Information Technology EHR
NewYork-Presbyterian Hospital
$130,000/yr