Description
The Information Security Officer (ISO) shall be responsible for developing, implementing, and managing the Bank's Information Security Program and policies to ensure the confidentiality, integrity, and availability of bank information assets. ISO serves as the primary leader for cybersecurity governance, risk management, regulatory compliance, incident response, and security awareness initiatives. This position ensures compliance with applicable banking regulations, including FFIEC guidance, GLBA, Pennsylvania Department of Banking, Interagency Guidelines Establishing Information Security Standards, state regulations, and cybersecurity best practices.
As a key member of the Bank's risk management framework, the ISO provides independent oversight and possesses independent authority for information security risk reporting to executive management and the Board of Directors.
Essential Duties
- Develop and maintain the bank’s information security strategy, risk tolerance, policies and information security exception management for alignment with business objectives.
- Conduct risk assessments and report findings to senior management and the board.
- Ensure alignment of security controls with business objectives and regulatory requirements.
- Monitor third-party vendor security practices.
- Provide employee and board training and awareness programs.
- Establish and maintain the Bank’s cybersecurity strategic roadmap.
- Provide cyber risk appetite and operational resilience reporting
- Ensure the Bank’s Information Security Program aligns with Information security frameworks (NIST Cybersecurity Framework (CSF 2.0), CIS Critical Security Controls (CIS Controls), and ISO/IEC 27001)
Ancillary Duties
- Present cybersecurity risk assessments, program updates, significant cybersecurity incident reporting, third party cyber risks, emerging threats, remediation efforts and strategic information security initiatives to executive management and the Board.
- Maintain Information Security compliance standards (GLBA Safeguards Rule compliance, customer information protection, security awareness program effectiveness, policy exception management, annual Information Security Program review.
- Develop mitigation plans for identified vulnerabilities and threats.
- Develop and oversee security control testing and validation efforts, for existing Information Security Technology, upgrades and enhancements.
- Responsible for leading the bank’s information security risk assessments (ISRA, GLBA, Privacy)
- Lead the Bank’s Incident Response Program. Coordinate response activities during security incidents. Ensure proper breach notification and regulatory reporting procedures are followed.
- Conduct post-incident reviews and lessons-learned sessions. Maintain cyber resilience and recovery procedures.
- Participate in vendor due diligence reviews. Assess SOC reports, penetration test results, and security questionnaires. Monitor vendor cybersecurity performance and remediation efforts. Support contract language related to cybersecurity requirements.
- Working with the Information Technology Management Team, oversee security monitoring and threat detection activities.
- Review and manage cybersecurity alerts and incident investigations.
- Responsible for reviewing key performance indicators for the information security program. These include but are not limited to the following:
- Completion of annual risk assessments
- Reduction of critical vulnerabilities
- Regulatory examination results
- Audit finding remediation timelines
- Employee phishing test performance
- Third-party risk assessment completion rates
- Incident detection and response metrics
- Security awareness training completion rates
- Compliance with Board-approved security objectives
- Develop and maintain cybersecurity metrics, key risk indicators (KRIs), and executive dashboards for Board reporting.
- Responsible for ensuring the Bank’s Identity and Access Management (IAM) processes use industry best practices and risk management controls.
- Ensure appropriate vulnerability management processes are maintained.
- Review application deployment and change management processes to ensure security standards are adhered to.
- Maintain threat intelligence and cyber threat monitoring processes, including participation in FS-ISAC and other financial sector information-sharing organizations.
- Direct penetration testing and independent security assessments.
- Maintain and oversee cybersecurity supply-chain risk management practices for critical vendors, fintech partners, cloud providers, and service providers.
- Ensure standards are documented and adhered to for data encryption at rest and in motion.
- Responsible for creating and maintaining the Bank’s data classification standards, data retention requirements, secure disposal procedures for hardware and software, and maintaining the bank’s sensitive data inventory, and ensure hardware, software and information asset inventories are in place and updated.
- Ensure Password policy standards are documented and adhered to for all systems, including multi-factor authentication for all software with customer or sensitive bank information.
- Ensure compliance with federal incident notification requirements, including 36-hour notification requirements for qualifying computer-security incidents.
- Collaborate as a member of the Business Continuity Planning (BCP) Committee with business continuity team members to ensure cyber resilience is developed in all departmental BCP plans.
- Coordinate and conduct annual cyber recovery testing, ransomware recovery exercises and all relevant tabletop exercises.
- Chair or participate in the Information Security Committee.
- Lead security-related projects and initiatives. Including Conducting periodic NIST CSF information security maturity assessments, gap analyses, and program effectiveness reviews.
- Responsible for coordinating all regulatory examinations, independent audits, and security assessments related to information security and cybersecurity and for ensuring management responses and corrective action plans are completed in a timely manner.
- Perform tasks which are supportive in nature of the essential functions of the job, but which may be altered or re-designed depending upon individual circumstances.
Requirements
Education/Training: A bachelor’s degree in information security, Cybersecurity, Information Technology, Risk Management, Computer Science, or related field required. Master's degree preferred.
Skill(s): Proficient reading, writing, and grammar skills; proficient interpersonal relations and communicative skills; proficient information technology skills, including information security and applicable regulations; visual and auditory skills; valid driver's license.
Experience: A minimum of five (7) years of information security, information technology risk management, cybersecurity, audit, or related experience, including at least three (3) years in a leadership role. Relevant security certifications are preferred (CISSP, CISM, CCSP) but not required. Banking or regulated financial institution experience strongly preferred
Skills Required
- Bachelor’s degree in information security, cybersecurity, information technology, risk management, computer science, or a related field
- At least five years of information security, information technology risk management, cybersecurity, audit, or related experience
- At least three years of experience in a leadership role
- Proficient information technology skills, including information security and applicable regulations
- Proficient reading, writing, grammar, interpersonal, and communication skills
- Valid driver’s license
- Master’s degree
- Relevant security certifications, such as CISSP, CISM, or CCSP
- Banking or regulated financial institution experience
What We Do
Dime Bank is a full-service financial institution that offers a comprehensive range of consumer and commercial banking solutions, including home mortgages, wealth management, and trust services. Since 1869, the company has focused on providing customers with valuable banking products such as checking accounts, savings accounts, and business loans, serving communities across Connecticut and Rhode Island with a personal touch.









