Title:Ā Ā Ā VP, Information SecurityĀ
Standard Hours:Ā Ā Ā 40
Primary Location:Ā Ā Ā Home Office
Reports to:Ā Ā Ā CIO
Position Summary
The Vice President of Information Security leads a modern, business-aligned security program across the organizationās Microsoft-based environment.
This role blends security leadership with cloud architecture and reliability principles, ensuring systems are not only protected, but also resilient, observable, and continuously improving.
The VP will work closely with internal teams, vendors and a managed service provider (MSP), maintaining accountability for outcomes while enabling efficient, scalable operations.
________________________________________
Core Responsibilities
Security Program Leadership
ā¢Ā Ā Ā Manage and maintain a risk-based, right-sized security program aligned to business prioritiesĀ
ā¢Ā Ā Ā Manage security controls that balance protection, usability, and system performanceĀ
ā¢Ā Ā Ā Translate risk into clear, actionable decisions for leadershipĀ
________________________________________
Cloud Security, Architecture & Reliability
ā¢Ā Ā Ā Working with our vendors, ensure systems are architected with:Ā
oĀ Ā Ā Strong identity and access controlsĀ
oĀ Ā Ā Secure configurationsĀ
oĀ Ā Ā High availability and resilienceĀ
ā¢Ā Ā Ā Partner with MSP and IT to build secure, scalable, and fault-tolerant systemsĀ
ā¢Ā Ā Ā Promote infrastructure consistency and automationĀ
________________________________________
Observability, Monitoring & Metrics
ā¢Ā Ā Ā Manage and enhance monitoring, logging, and alerting across all platformsĀ
ā¢Ā Ā Ā Define and track key security and reliability metrics, such as:Ā
oĀ Ā Ā Incident detection and response timesĀ
oĀ Ā Ā Vulnerability remediation timelinesĀ
oĀ Ā Ā System availability and performanceĀ
ā¢Ā Ā Ā Improve visibility into system behavior to support faster, more effective decision-makingĀ
________________________________________
Incident Response & Continuous Improvement
ā¢Ā Ā Ā Lead all aspects of incident response, including coordination with MSP, COO, and CIO
ā¢Ā Ā Ā Conduct root cause analysis and implement corrective actionsĀ
ā¢Ā Ā Ā Drive a culture of continuous improvement, reducing repeat incidents over timeĀ
ā¢Ā Ā Ā Ensure systems and processes evolve based on lessons learnedĀ
________________________________________
MSP Management & Operations
ā¢Ā Ā Ā Manage the MSP relationship, ensuring accountability and performanceĀ
ā¢Ā Ā Ā Oversee:Ā
oĀ Ā Ā Security monitoringĀ
oĀ Ā Ā Alert triage and responseĀ
oĀ Ā Ā Vulnerability managementĀ
oĀ Ā Ā Desk top maintenance and issue resolutionĀ
ā¢Ā Ā Ā Define SLAs and ensure operational effectivenessĀ
________________________________________
Risk, Compliance & Audit
ā¢Ā Ā Ā Working with internal and external resources, lead SSAE 18 / SOC audits, including preparation and remediation coordination. Ā
ā¢Ā Ā Ā Maintain existing policies, standards, and documentation aligned to actual riskĀ
ā¢Ā Ā Ā Create new policies as identified
________________________________________
Business Continuity & Resilience
ā¢Ā Ā Ā Co-Own business continuity and disaster recovery programs across the organizationĀ
ā¢Ā Ā Ā Participate in testing and improvement recommendations
________________________________________
Vendor & Partner Security
ā¢Ā Ā Ā Assess and monitor third-party security postureĀ
ā¢Ā Ā Ā Integrate vendor risk into broader risk management practicesĀ
ā¢Ā Ā Ā Work with and manage other vendor partners to ensure best security practices and successful audits. Ā ________________________________________
Security Culture & Awareness
ā¢Ā Ā Ā Promote a practical, accountable security cultureĀ
ā¢Ā Ā Ā Deliver targeted training and awareness programs to staff
ā¢Ā Ā Ā Stay current on threats and evolving best practicesĀ
________________________________________
Qualifications
ā¢Ā Ā Ā ~7ā12 years in information security, cloud security, or related rolesĀ
ā¢Ā Ā Ā Experience with Azure and/or Microsoft 365 security and architecture
ā¢Ā Ā Ā Experience with monitoring, incident response, and cloud operationsĀ
ā¢Ā Ā Ā Familiarity with automation and modern infrastructure practicesĀ
ā¢Ā Ā Ā Experience working with MSPs or external service providersĀ
ā¢Ā Ā Ā Exposure to SOC/SSAE 18 and regulated environmentsĀ
________________________________________
Leadership Profile
ā¢Ā Ā Ā Hands-on and accountable, with both strategic and technical capabilityĀ
ā¢Ā Ā Ā Focused on measurable outcomes and continuous improvementĀ
ā¢Ā Ā Ā Pragmaticābalances security, reliability, and business needsĀ
ā¢Ā Ā Ā Strong collaborator across technology, operations, and leadershipĀ
ā¢Ā Ā Ā Growth-oriented and eager to expand leadership scopeĀ
________________________________________
Work Conditions
ā¢Ā Ā Ā Sitting for extended periods of time
ā¢Ā Ā Ā Dexterity of hands and fingers to operate a computer keyboard, mouse, and other devices
ā¢Ā Ā Ā Physically able to participate in training sessions, presentations and meetings
ā¢Ā Ā Ā Some travel is required for the purpose of meeting with management, employees, and occasional credit union client meetings
AA EEO
Learn more about this Employer on their Career Site
