Information Security Officer
2 days ago
Glendale
Job Description Credit Union West has been named a ‘Top Company to Work for in Arizona’ for the 14th year in a row (2014-2026)! This prestigious award announced by BestCompaniesAZ is earned by achieving stellar marks in a comprehensive workplace survey, where employees are asked to rate and share feedback including culture, leadership and overall satisfaction. Credit Union West continuously looks for ways to improve employee satisfaction and experience. In addition to high paying wages, Credit Union West also offers the following: • Full-time employees receive 100% paid health, dental & vision insurance, • Earn incentives up to 20%, depending on position, • 401K plan with employer matching funds up to 5%, • Profit Sharing, • Tuition reimbursement, • Gym membership reimbursement, • Paid time off for holidays, vacation, and sick days, • Credit Union West membership and discounts Be part of our award-winning team! POSITION SUMMARY The Information Security Officer (ISO) is expected to embody the essence of servant leadership, prioritizing the needs of employees, members, and communities. The Information Security Officer will be committed to fostering a positive and inclusive workplace culture. They will promote an environment where all employees feel valued, respected, and empowered to contribute to the organization's success. The individual serves as a champion of the credit union’s strategic direction, leading by example to innovate, adapt, and drive initiatives that propel Credit Union West towards a shared vision of growth, financial stability and community prosperity. The ISO enhances the quality of life for members and team members by setting the vision and consistently championing the WEST service model, ensuring strategies, decisions, and outcomes meet or exceed service expectations across the organization. The Information Security Officer collaborates closely with the Chief Information Officer (CIO) to execute, operationalize, and continuously improve the credit union’s information security program. The ISO is responsible for providing day‑to‑day security operations leadership, overseeing the Security Operations Center (SOC), and ensuring the effective implementation of information security policies, standards, and controls in alignment with the organization’s overall security strategy and risk posture. The ISO provides leadership and direction to the Information Security Administrators, supports incident response and risk management activities, and ensures compliance with applicable regulatory, legal, and industry requirements. This role works closely with the CIO, IT leadership, and business teams to operationalize security priorities, support audits and examinations, and maintain a secure, resilient, and compliant operating environment. ESSENTIAL FUNCTIONS & RESPONSIBILITIES Security Program Governance & Oversight – Oversee the execution and ongoing operation of the credit union’s information security program in alignment with the organization’s security strategy and risk posture. Ensure that information security policies, standards, and procedures are implemented consistently and effectively across the organization. Provide operational oversight of the Security Operations Center (SOC), establish priorities for security operations, and ensure appropriate controls are in place to protect the confidentiality, integrity, and availability of organizational information assets. SOC Oversight & Incident Response Leadership - Provide leadership and direction for security monitoring, detection, and response activities performed by the Security Operations Center. Ensure that security incidents are appropriately investigated, documented, escalated, and resolved in accordance with established procedures. Direct response activities, coordinate with internal and external stakeholders, and advises the CIO on incident severity, risk implications, and response actions for significant, enterprise‑impacting, or regulatory incidents. Ensure that incident response plans are maintained, tested, and continuously improved. Risk Management, Compliance & Regulatory Engagement - Operationalize security risk management activities and ensure ongoing compliance with applicable regulatory, legal, and industry requirements. Oversee security risk assessments, vulnerability management activities, and audit preparation efforts, ensuring findings are addressed and remediated in coordination with IT and business teams. Serve as a primary operational point of contact for regulators, auditors, and examiners related to cybersecurity matters and collaborate closely with the CIO to support regulatory examinations, audits, and reporting obligations. Security Program Execution & Maturity - Work in partnership with the CIO to continuously improve the effectiveness and maturity of the information security program. Identify operational gaps, emerging threats, and opportunities for enhancement and translate them into actionable security initiatives. Ensure security considerations are integrated into technology initiatives, system changes, and operational processes and work with IT leadership to embed security into day‑to‑day operations without disrupting business objectives. Leadership, Enablement & Communication - Provide leadership and direction to the Information Security Administrators and supports their professional development and effectiveness. Promote security awareness across the organization, reinforce accountability for secure practices, and communicate security risks, priorities, and outcomes to leadership. Ensure that security operations remain aligned with organizational values, service expectations, and regulatory obligations. Leadership, Enablement & Communication - Evaluate, implement, and manage emerging technologies, including artificial intelligence, in alignment with the credit union’s technology strategy, security standards, data governance practices, and regulatory expectations. Perform other duties as assigned. QUALIFICATIONS & REQUIREMENTS EDUCATION: A bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field is required, or an equivalent combination of education and relevant experience. Advanced or professional certifications such as CISSP, CISM, CRISC, or GIAC are preferred. EXPERIENCE: 7–10 years of progressive experience in information security, cybersecurity operations, or risk management roles. Experience overseeing security operations, supporting SOC functions, leading or coordinating incident response efforts, and engaging in regulatory, audit, or compliance activities. Experience within financial services or similarly regulated environments is highly preferred. SKILLS & COMPETENCIES Live the mission, vision, and core values of the credit union. Able to communicate effectively and tactfully with employees and members both orally and in writing and requires the ability to communicate complex security issues clearly to technical and non-technical audiences. Excellent judgment and creative problem-solving skills including negotiation and conflict resolution skills. Exceptional leadership skills: ability to motivate, influence, and engage direct and indirect reports and peers with a significant level of diplomacy and trust. Energetic, forward-thinking, and creative in business solutions with high ethical standards and trustworthiness. Act as a change agent who can collaborate with diverse interests and adapt to internal, market or regulatory-driven changes. Proven, high-level experience of decision-making within the discipline and authority of the role. Use of advanced logic to make highly complex judgments with a material impact at the organizational level. Work as a team member and possess positive influencing skills to bring others to new thinking and mindset. Present a professional, courteous image when interacting with members, co-workers, the Board of Directors, management, business partners, and the community to build strong collaborative business relationships. Demonstrated ability to evaluate, implement, and manage emerging technologies, including artificial intelligence, in alignment with the credit union’s technology strategy, cybersecurity standards, data governance practices, and regulatory expectations. Maintain working knowledge of Microsoft Office, SharePoint, and collaborative tools (Teams and Zoom). Thorough knowledge and understanding of organization’s Employee Handbook and policies.