Jobs and Careers
CO

Information Security Manager

Conference of State Bank Supervisors
Washington, United Statesfull_timeVerifiedPosted 16 May 2025

About the role

Job Summary
The Information Security Manager is responsible for developing, implementing, and maintaining the organization's information security program aligned to FISMA and the NIST Cyber Security Framework to ensure the confidentiality, integrity, and availability of our information and information system assets. This includes the development of policies, procedures and processes, creation of Security Authorization packages, and oversight of monthly Continuous Monitoring reports which include vulnerability scanning, interviews and system testing. The Information Security Manager supports security engineering architecture reviews of CSBS information systems ensuring they are designed and built around their respective protection needs with proven security architectures, and that required protection mechanisms are addressed and implemented early and maintained throughout the life cycle of information systems to minimize risk to CSBS. The Information Security Manager is expected to work with a variety of stakeholders, including system owners, implementation engineers, third-party auditors, and the CSBS Information Security Department to develop deliverables, recommend security solutions, and maintain the existing Authority to Operate (ATO) status for CSBS systems and implement new ATOs for other emerging systems and platforms.

Essential Functions
To perform this job successfully, an individual must be able to perform each essential duty and responsibility satisfactorily. Reasonable accommodations may be made to enable an individual with disabilities to perform the essential functions. Other duties may be assigned to meet business needs.
This position will perform hands-on tasks to monitor and manage the security posture of CSBS’s information technology services. In this role, the Information Security Manager will be responsible for participating in and leading the analysis and evaluation of information technology services design, engineering practices, and architecture.
Security Program Management
• Work with the CISO to develop a security program and security projects that address identified risks and business security requirements.
• Manage the process of gathering, analyzing and assessing the current and future threat landscape, as well as providing the CISO with a realistic overview of risks and threats in the enterprise environment.
• Partner with the CISO to develop budget projections based on short and long-term goals and objectives.
• Monitor and report on compliance with security policies, as well as the enforcement of policies within the IT department.
• Propose changes to existing policies and procedures to ensure operating efficiency and regulatory compliance.
• Work as a liaison with vendors and the legal and purchasing departments to establish mutually acceptable contracts and service-level agreements.
• Manage production issues and incidents and participate in problem and change management forums.
• Work with the CISO, IT and business stakeholders to define metrics and reporting strategies that effectively communicate successes and progress of the security program.
• Provide support and guidance for legal and regulatory compliance efforts, including audit support.
• Develop and implement controls and configurations aligned with security policies and legal, regulatory, and audit requirements.
• Work with the CISO to develop a security program and security projects that address identified risks and business security requirements.
• Advise senior leadership on risk mitigation strategies based on established risk tolerance and industry best practices.
• Align organizational requirements with security risk management goals, ensuring a cohesive approach to risk mitigation.
• Develop, review, and monitor compliance with organizational security policies.
Security Engineering Architecture Reviews
• Work with the enterprise architecture team to ensure that there is a convergence of business, technical, and security requirements; liaise with IT management to align existing technical installed base and skills with future architectural requirements.
• Consult with IT and security staff to ensure that security is factored into the evaluation, selection, installation and configuration of hardware, applications, and software.
• Recommend and coordinate the implementation of technical controls to support and enforce defined security policies.
• Research, evaluate, design, test, recommend or plan the implementation of new or updated information security hardware or software, and analyze its impact on the existing environment; provide technical and managerial expertise for the administration of security tools.
• Coordinate, measure, and report on the technical aspects of security management.
• Manage security projects and provide expert guidan

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Conference of State Bank Supervisors

View company profile →