INFORMATION SECURITY PROGRAM MANAGER
FinWise BankAbout the role
Job Details
Job Location HQ - Murray, UTSalary Range $80000.00 - $100000.00 SalaryDescription
Purpose:
FinWise Bank is a commercial institution located in Murray, Utah that offers exceptional products in a manner that continually surpasses expectations. Information Security is a vital part of the Bank’s structure, and the Risk Division supports the Bank in these efforts. The Information Security Program Manager is primarily responsible for the evaluation and monitoring of the security posture of existing and potential Strategic Partners inclusive of their products and associated processes that the Bank is engaged in. This role will also advise the Information Security Officer (ISO) of emerging risks from assigned Strategic Partners and suggest ways to mitigate them. This role will also establish and maintain strong relationships across lines of business to ensure that all applicable aspects of the Information Security Program are observed. The Information Security Program Manager is a key member of a large team of skilled and engaged colleagues with a broad span of responsibilities who actively interact with their respective counterparts from Strategic Partners.
Tasks:
- Serve as the primary point of contact between the Bank and assigned Strategic Partners for all matters related to Information Security.
- Develop strong and collaborative professional relationships with security counterparts at assigned Strategic Partners.
- Provide visibility to the ISO about the security posture of assigned Strategic Partners.
- Monitor that assigned Strategic Partners are providing expected oversight documentation.
- Escalate all assigned Strategic Partner issues to the ISO.
- Participate in annual virtual or onsite visits of assigned Strategic Partners.
- Review security assessments, monitoring alerts, architectural diagrams, testing results, and audits from assigned Strategic Partners to ensure compliance with applicable banking regulations.
- Review security policies, plan, procedures, and processes of assigned Strategic Partners using a risk-based approach.
- Document procedures, write reports, and create guidance documents to support the oversight of Strategic Partners as indicated in the Information Security Program.
- Communicate relevant process issues to the ISO, Program Management, and/or the Risk Division to improve efficiency.
- Ensure that security incidents associated with Strategic Partners are documented, investigated, and resolved in a timely manner. Provide final incident reports for review by the ISO.
Knowledge, Skills, and Abilities:
- Manage concurrent activities with tight deliverables and a strong attention to detail.
- Ability to remain aware of current security threats, trends, and topics to support the security programs of Strategic Partners.
- Outstanding technical security background as well as thorough understanding of relevant risk mitigation and technical controls following industry best practices from NIST, CIS, etc.
- Direct experience with controls related to Information Security as defined by the FFIEC, FDIC, GLBA, SEC, SOX, PCI-DSS.
- Demonstrate and apply a thorough understanding of Third-Party Risk Management, with specific focus on cyber security, data protection, business resiliency, and other security risks associated with the use or technology (e.g.: cloud, API, IT infrastructure, external audits, BCP/DR, and operational security functions).
- Ability to assess and review third-party audit evidence from Strategic Partners such as: SOC reports, Penetration Testing reports, ITGC audit reports, PCI DSS SAQ/AOC/ROC, cyber insurance policies,
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s