INFORMATION SECURITY MANAGER
About this role
POSITION OVERVIEW
The Information Security Manager is responsible for developing and maintaining the Bank’s information security strategy, vision, and programs.
This role helps protect the Bank’s information assets and technology infrastructure from internal and external threats.
The position leads initiatives to support regulatory compliance, industry standards, and security best practices while promoting a strong culture of security awareness across the organization.
The incumbent also supports effective risk management and helps safeguard the Bank’s data and intellectual property.
POSITION RESPONSIBILITIES
- Develop, implement, and continuously enhance the Bank’s Information Security Strategy, Architecture, and Roadmap to align with business objectives, risk appetite, and regulatory requirements.
- Establish and maintain enterprise-wide information security policies, standards, procedures, and controls consistent with industry best practices and applicable regulations.
- Monitor emerging cybersecurity threats, vulnerabilities, and industry trends, adapting security strategies and controls to address evolving risks.
- Identify, assess, prioritize, and oversee the mitigation of information security risks across the organization through a comprehensive risk management framework.
- Lead the Bank’s information technology disaster recovery, and cyber resilience programs, including planning, testing, coordination, and ongoing improvement activities.
- Oversee the design, implementation, operation, and continuous improvement of security technologies, processes, and controls to safeguard the confidentiality, integrity, and availability of Bank information assets.
- Direct cybersecurity incident response, investigation, containment, recovery, and post-incident remediation activities to minimize business impact and strengthen security posture.
- Conduct and oversee security assessments, control reviews, audits, and testing activities to evaluate effectiveness and ensure ongoing compliance.
- Ensure compliance with applicable laws, regulations, industry standards, and regulatory guidance, including but not limited to GLBA, FFIEC, ISO 27001, and other relevant requirements.
- Establish and maintain effective information security governance, reporting, and oversight structures to support enterprise risk management and strategic decision-making.
- Serve as the primary liaison with internal and external auditors, regulators, and independent assessors, providing subject matter expertise, guidance, and oversight on security-related reviews, investigations, and assessments.
- Develop, implement, and promote enterprise-wide security awareness and training programs to foster a strong culture of cybersecurity and accountability.
- Provide leadership, guidance, and specialized security training to Information Technology personnel and other stakeholders on cybersecurity best practices and regulatory expectations.
- Perform other duties and responsibilities as assigned by the Chief Information Officer and Executive Management.
SKILLS / QUALIFICATIONS
- Strong knowledge of cybersecurity principles, frameworks, and technologies, including NIST, ISO 27001, CIS Controls, SIEM, IDS/IPS, DLP, encryption, cloud security, and other industry-standard security practices.
- Exceptional leadership, communication, and interpersonal skills, with a demonstrated ability to collaborate across business and technology functions and influence stakeholders at all organizational levels.
- Strong analytical, critical thinking, and problem-solving capabilities, with the ability to assess complex risks and make sound, risk-based decisions in a dynamic and fast-paced environment.
- Proven ability to lead, mentor, and develop high-performing cybersecurity teams while fostering a culture of accountability, continuous improvement, and operational excellence.
EDUCATION / PROFESSIONAL QUALIFICATION
- Bachelor’s degree from an accredited university in Computer Science, Information Technology, Cybersecurity, or a related field.
- Minimum of seven (5) years of progressive leadership experience in cybersecurity, with a demonstrated track record of successfully developing, implementing, and managing enterprise cybersecurity programs.
- Experience within regulated industries such as financial services with a strong understanding of applicable regulatory and compliance requirements.
- Professional cybersecurity certifications, including CISSP, CISM, CISA, or equivalent credentials, are highly preferred.
- Proven ability to align cybersecurity strategies with business objectives, regulatory expectations, and organizational risk management practices.
We offer a competitive total rewards package, including but not limited to Medical, Dental, Vision, and Life Insurance, 401k retirement savings plan, and paid federal holidays, for this full-time position within the annual salary range of $140,000 - $150,000. Annual pay ranges are determined based on qualifications, level, and location. Exact compensation may vary based on your skills and experience.
Must be authorized to work in the US.
We are an Equal Opportunity Employer. All applicants will receive consideration for employment without regard to race, color, ancestry, religion, sex, national origin, sexual orientation, age, marital status, disability, gender identity, gender expression, genetic information, or military or Veteran status, or any other characteristic protected by law.
Company at a glance
Commonwealth Business Bank, as known as CBB Bank, is a full-service business-focused bank established in 2005.
We offer products and services catering to business owners that will nurture and protect small- to medium-size enterprises and improve their economic viability. For more than 18 years, we have diligently helped grow Korean American business as a proud partner in line with our vibrant shared history of community development.
The organizational culture of CBB Bank fosters trust and harmony through equity and fairness in personnel management.
We are an innovative financial partner providing equal opportunities, the best service in support of small and medium-size business growth and placing the highest priority on fulfilling our customers' needs above all.
We are distinguished by these five core values: Professionalism, Principled, Personal, Passionate, and Pride in service.
The CBB Bank promise is to help our customer's business grow stronger, from the very start to their definition of what success looks like.
Our aim is true. We sync up businesses and employees with success.
Top Benefits
- Medical Insurance
- Dental Insurance
- Vision Insurance
- Life Insurance
- 401k Retirement Savings Plan
- Paid Federal Holidays
Tired of cold applications?
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
Know someone who'd be great for this?