Information Security Officer
APGFCU | |
United States, Maryland, Edgewood | |
1321 Pulaski Highway (Show on map) | |
Jan 04, 2025 | |
Description
APGFCU - Your Community Credit Union! For over 80 years, APGFCU has shared our financial experience and provided valuable products and services to build stability and financial independence, one member at a time. We are looking for those who want to join this movement and become a part of a growing organization. We offer competitive pay and great benefits. Summary: Reporting to the Senior Vice President, Fraud and Security, the Information Security Officer oversees the enterprise-wide APGFCU Information Security Management Program encompassing information security, regulatory compliance, data privacy, and protection of APGFCU intellectual property. Functioning independently of the Information Technology department, this position analyzes, oversees, reports and provides recommendations and counsel regarding credit union information security and vulnerability across the credit union's assets including outsourced assets. On an ongoing basis provides significant interaction with all levels of credit union leadership including Executive and Management Teams, Board Members, as well as support staff in leadership positions. Manages and provides support to the Information Security Analyst. Essential duties and Responsibilities: Information Security and Compliance: Oversee and recommend acceptable levels of risk for the credit union and ensure the integrity, confidentiality and availability of information owned, controlled or processed by the organization including on premise solutions, other modules and systems as implemented. Proactively protect the integrity, confidentiality, and availability of information in the custody of or processed by APGFCU by:
Threat Management Monitoring and Evaluation: Daily reviews of security monitoring systems, network and user activity, and emerging threats by:
Intellectual Property Protection: Determine which types of confidential information are required to be protected as well as establish and maintain policy and verify implementation of suitable encryption controls to protect such information. Risk Assessments: Conduct Risk Assessments of security controls, systems, and procedures to assess their effectiveness, and working with management, identify, develop, and execute plans to maintain adequate monitoring and address information security risks.
Policy and Procedure: Determine, develop, maintain, and publish corporate-level information security policies, standards, procedures, and guidelines, including incident response, privacy policies, disaster recovery, business continuity plans and compliance reporting procedures for general IT controls in conjunction with management and legal counsel. Compliance and Enforcement
Project and Risk Governance: Through project team and committee participation promote a risk based management approach and oversight of the security and control framework through ongoing committee participation.
External Audits: Participate in the preparation prior to regulatory examinations and serving as an active respondent to questions, which arise during an examination.
Other Job Responsibilities Include:
QUALIFICATIONS: Education: Bachelor Degree or Systems Management or related field is required. Experience can be credited in lieu of education. Specialized training pertaining to the systems in place and continuing education a plus. Professional industry certifications, such as a Certified Information Security Professional CISSP, networking, operating systems, and security or other information security credentials required. Experience: A minimum of 7-10 years of experience with a broad range of exposure to business and technical requirements, security and control frameworks, hardware and software systems analysis and internal control procedures. Experience in data administration, security methods, access controls, user roles and profiles, and database design techniques. Education may be substituted in lieu of experience. Knowledge, Skills and Abilities:
Physical Demands: The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. While performing the duties of this job, the employee is regularly required to stand; walk; use hands to handle or feel objects, tools, or controls; and talk or hear. The employee frequently is required to reach with hands and arms. The employee is frequently required to type, sit, stoop, kneel, or crouch. The employee must frequently lift and/or move up to 25 pounds, and be capable of transporting related supplies and equipment. Specific vision abilities by this job include vision, distance vision, color vision, peripheral vision, depth perception and the ability to focus. APGFCU is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability to Protected Veteran status. Please use the attached link to view the EEO law poster http://www1.eeoc.gov/employers/poster.cfm APGFCU is committed to working with and providing reasonable accommodations to persons of all abilities, including persons with disabilities. If you need a reasonable accommodation for any part of the employment process, please send to the Human Resources Department and let us know the nature of your request and your contact information. Reasonable accommodations are considered on a case-by-case basis. Please note that only inquiries concerning a request for reasonable accommodations will be responded to from this e-mail address. Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor's legal duty to furnish information. 41 CFR 60-1.35(c)
|