Information Security Officer
Location: Lincoln, Nebraska (Hybrid: 3 Days/Week In Office)
Company: Haberfeld
Employment Type: Full-Time | Employee-Owned (ESOP)
Help Protect the Future of a Growing Employee-Owned Company
At Haberfeld, we help financial institutions grow through a powerful combination of consulting, marketing, analytics, data, and technology. As we continue expanding our use of cloud technologies, artificial intelligence, and data-driven solutions, security remains a top business priority.
We're seeking an experienced and collaborative Information Security Officer to lead our information security program and help safeguard our people, systems, clients, and data. This role combines regulatory compliance, cybersecurity leadership, risk management, incident response, vendor oversight, and employee education into a highly visible position that works across every department of the organization.
This is an exceptional opportunity for someone who enjoys building relationships, influencing positive security behaviors, and helping an organization achieve security excellence while supporting innovation and growth.
What You'll Do
In this role, you will own and continually mature Haberfeld's information security program, ensuring security practices align with business objectives, regulatory requirements, and industry frameworks.
Security Governance & Program Leadership
- Lead and maintain the enterprise Information Security Program.
- Develop, review, and update security policies, standards, procedures, and guidelines.
- Drive alignment with applicable security frameworks, including NIST Cybersecurity Framework, HIPAA, and SOC requirements.
- Present security risks, initiatives, and program updates to executive leadership and internal committees.
- Facilitate meetings and communications for the Information Security Team.
Risk Management
- Lead enterprise risk assessments and maintain the organization's risk register.
- Conduct and coordinate annual security assessments.
- Oversee vulnerability management activities and remediation efforts.
- Coordinate penetration testing, social engineering assessments, and tabletop exercises.
- Assess security implications of new technologies, cloud services, AI initiatives, and business projects.
Compliance & Audit Management
- Serve as the primary coordinator for annual SOC/SSAE18 audits and HIPAA assessments.
- Monitor compliance with internal policies and regulatory requirements.
- Coordinate collection and maintenance of audit evidence and documentation.
- Assist business stakeholders in meeting security and compliance obligations.
Security Operations & Incident Response
- Coordinate detection, investigation, and response to security incidents.
- Maintain incident response plans and procedures.
- Document, track, and report security incidents and corrective actions.
- Lead post-incident reviews and recommend improvements.
- Assist with business continuity and disaster recovery planning activities.
Vendor & Third-Party Risk Management
- Perform security reviews of vendors and service providers.
- Maintain third-party risk documentation and assessments.
- Review contracts and security requirements with prospective vendors.
- Track remediation efforts related to vendor security findings.
Security Awareness & Culture
- Develop and deliver ongoing security awareness training.
- Manage phishing simulations and social engineering programs.
- Promote a culture of security across all departments.
- Partner with Human Resources concerning security policy violations and corrective actions.
Data Protection & Privacy
- Serve as HIPAA Security Officer and Privacy Officer.
- Support data classification, retention, and protection initiatives.
- Help ensure appropriate controls exist around confidential and sensitive information.
- Collaborate with business and technical teams to improve data governance practices.
Cloud, Microsoft 365, and Emerging Technology Security
- Partner with IT leadership to strengthen Microsoft 365, Azure, endpoint, identity, and collaboration platform security.
- Review and assess security controls associated with AI, automation, and cloud services.
- Monitor evolving cybersecurity threats and recommend improvements to organizational defenses.
- Support implementation of security best practices for modern workplace technologies.
What Success Looks Like
In your first year, you will:
- Maintain successful SOC and HIPAA assessments.
- Improve security awareness and employee engagement.
- Advance Haberfeld's security maturity against NIST and industry best practices.
- Strengthen incident response and risk management processes.
- Enhance security governance around cloud and AI initiatives.
- Help protect the organization while enabling innovation and growth.
Qualifications
We’re less focused on checking every box and more focused on finding someone who is curious, capable, and eager to grow.
Required
- Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Systems, Business, or related field.
- 3+ years of experience in information security, cybersecurity, IT audit, compliance, risk management, or related disciplines.
- Experience developing or maintaining information security policies and procedures.
- Strong understanding of security frameworks such as NIST, HIPAA, and SOC.
- Experience conducting risk assessments and vendor evaluations.
- Strong communication, training, and presentation skills.
- Strong project management and organizational capabilities.
- Ability to communicate technical concepts to both technical and non-technical audiences.
Preferred
- Security certifications such as CISSP, CISM, CRISC, Security+, HCISPP, CISA, or similar.
- Experience with Microsoft 365 Security, Microsoft Defender, Entra ID, Microsoft Purview, Sentinel, or Azure security services.
- Experience supporting compliance or audit programs.
- Experience with regulated industries such as healthcare, financial services, or data-driven organizations.
- Knowledge of privacy regulations and data governance principles.
- Experience evaluating AI security and governance risks.
Why Haberfeld
We believe great people deserve great benefits and meaningful work. What We Offer:
- Competitive salary and incentive opportunities
- Employee Stock Ownership Plan (ESOP)
- 401(k)
- Medical, dental, and vision insurance
- Life and disability insurance
- Responsible Time Off (RTO)
- Paid pregnancy-related leave
- Paid parental bonding leave
- Nebraska Paid Sick leave
- Military leave
- Birthday holiday
- Company holidays
- Flexible hybrid work environment
- Onsite fitness facility
- Wellness programs
- Education benefit
- Free parking
- Summer early-out Fridays
- Employee Assistance Program (EAP)
- Financial planning resources
About Haberfeld
Haberfeld helps organizations achieve sustainable growth through a unique blend of consulting, analytics, training, technology, and marketing solutions. As an employee-owned company, we believe shared ownership leads to stronger commitment, better collaboration, and exceptional outcomes for our clients.
Our core values guide everything we do:
Integrity • Excellence • Collaboration • Curiosity • Joy in the Journey
Join Us
If you’re excited to apply your expertise in a collaborative, employee‑owned environment, we’d love to hear from you.
Apply today and help us build what’s next together.
Skills Required
- Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Systems, Business, or a related field
- 3+ years of experience in information security, cybersecurity, IT audit, compliance, risk management, or related disciplines
- Experience developing or maintaining information security policies and procedures
- Strong understanding of NIST, HIPAA, and SOC security frameworks and requirements
- Experience conducting risk assessments and vendor evaluations
- Strong communication, training, and presentation skills
- Strong project management and organizational capabilities
- Ability to communicate technical concepts to technical and non-technical audiences
- Security certification such as CISSP, CISM, CRISC, Security+, HCISPP, CISA, or similar
- Experience with Microsoft 365 Security, Microsoft Defender, Entra ID, Microsoft Purview, Sentinel, or Azure security services
- Experience supporting compliance or audit programs
- Experience in healthcare, financial services, or other regulated industries
- Knowledge of privacy regulations and data governance principles
- Experience evaluating AI security and governance risks
What We Do
Haberfeld is a data-driven consulting and marketing firm that partners with community financial institutions and patient service providers. They focus on aligning marketing, products, and people to drive sustained organizational growth. Their services include product consulting, targeted omnichannel marketing, and employee training, all supported by extensive data analytics accumulated over three decades of service to help clients acquire new customers and increase profitability.








