Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Information Security Officer

$135k - $140k

CityFirst Bank

WHO WE ARE

City First Bank N.A. is a mission-driven Community Development Financial Institution (CDFI) principally focused on a transformative impact in underserved, urban markets with the highest needs to drive equitable economic development. Our credit activities are purely commercial and focused on the following segments: Multifamily Affordable Housing, Not-for-Profit Finance, and Small Business Finance. As a depository and commercial lending provider with over $1.3 billion in bank assets as of December 31, 2024, our unified organization has over 100 employees in Washington DC and Los Angeles/Inglewood, CA.


ROLE SUMMARY


The Information Security Officer is responsible for monitoring, analyzing, and maintaining the bank's technical security controls in support of City First Bank's Information Security Program. This role will be focused on maintaining the security of the bank's applications and network which includes creation and timely execution of security projects, tool installations and integrating risk-based threat intelligence into the operational environment. The role also supports the ability to maintain assurance in our technical security controls, especially on the Cloud, so that risks to the confidentiality, integrity, and availability of the bank's information systems and infrastructure are sufficiently mitigated which in turn, supports the bank's operational and compliance goals. The role will also perform triage and analysis of security events escalated from the Tier1 and Tier-2 support teams.

ESSENTIAL FUNCTIONS AND RESPONSIBILITIES

  • Advanced monitoring of the day-to-day operation of Security Information and Event Management (SIEM) and Network Anomaly Detection and other security control tools.
  • Act as the first point of response for security event alerts and notifications. Maintain an efficient and secure IT computing infrastructure on the bank's environment, cloud, and SaaS products.
  • Provide regular security reporting and risk metrics to IT Leadership, Senior Leadership, and committees as appropriate.
  • Monitor knowledge sharing services and advise leadership on cybersecurity trends, emerging threats, and regulatory guidance.
  • Leads Information Security compliance tasks and coordinate and gather artifacts for internal and external audits.
  • Serve as the bank's designee for regulatory and audit purposes. Align controls with guidance and recommendations.
  • Work with Compliance to identify, assess, and track remediation of security risk and findings.
  • Ensure compliance with GLBA, FFIEC, and other regulatory, industry, and cybersecurity standards for access control and system permissions.
  • Manage identity and access, roles and permissions, assignments and changes, and all other activities to ensure adherence to policies and procedures.
  • Oversee periodic User Access Reviews for key bank systems.
  • Enable and oversee the process of employee user account provisioning and de-provisioning, including Active Directory and SaaS applications.
  • Lead the creation, implementation and integration of identity tools and practices that enhance the organization's security and regulatory compliance.
  • Conduct and maintain IT risk assessments including Information Security, GLBA, and Vendor / Third Party reviews.
  • Manage vendor due diligence reviews from an information security and technology perspective.
  • Develop and evaluate security procedures for IT Department.
  • Develop and administer the bank's security awareness program including annual training and phishing simulations.
  • Partner with IT infrastructure, application, and operations teams to ensure secure system design and configuration.
  • Generate and analyze reports, monitor alerts, and review reports to monitor security activities and document findings and recommend corrective actions.
  • Work with managed service providers, network administrators and security operations to resolve problems, evaluate new solutions, recommend changes, and investigate incidents.
  • Collaborate with lines of business, system, and network administrators to develop and manage role-based access control groups for ensuring appropriate access to information systems, applications, and data.
  • Responsible for analyzing user access roles, permissions, and profiles to establish user provisioning within all bank applications.
  • Implement and upgrade network security tools running in the physical and virtual environments.
  • Ensure confidential data is secure and implement controls to ensure visibility and auditability across organization for changes in roles, functions, access-levels, and data footprint.
  • Other duties as assigned.
Requirements

EDUCATION & EXPERIENCE

Required Education/Experience:
  • Bachelor's degree in Computer Science or Information Systems, Information Technology, or related focused technical training (CISSP, CISM, CRISC, or CISA) or in lieu 4 additional years of engineering and information security experience.
  • 7+ years' experience in a combination of information security, or IT operations/engineering, or IT risk management
  • 4+ years' experience with designing and implementing information security technologies.
  • Extensive experience in banking regulations and compliance requirements, specifically related to regulatory examinations and security requirements.
  • Experience in supporting and managing audit, examination, and regulatory interactions.
Preferred Education/Experience:
  • 8 years of Engineering or Security Administration in banking preferred.
  • 2 years security engineering/administration in the banking/financial sector
KNOWLEDGE, SKILLS, AND ABILITIES

Required Knowledge & Skills:
  • Knowledge of Microsoft Azure and Microsoft O365 virtualized environment and tools is a must. Ability to configure and work on Azure Security Center and O365 Security Center.
  • Knowledge of Active Directory, Azure AD, identity management, DLP policies, Azure Sentinel and other security tools essential.
  • Familiarity with at least one security best practice standards such as the Center for Internet Security (CIS) Security Controls or NIST Cybersecurity Framework, or equivalent.
  • Excellent knowledge of Azure Security Center and Azure portal. Knowledge of SEIM and AD tools.
  • Excellent knowledge of Microsoft Operating system and Azure tools. Strong Active Directory and Windows Group Policy knowledge.
  • Networking technology and protocols, including routers, switches, VPNs, Citrix, email gateways, etc.
  • Requires skill in providing expert input into technology projects.
  • Assist the Tier-1 and Tier-2 escalations with troubleshooting and analysis of security events.

Salary Description


$135,000 - $140,000, annually
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Information Security Officer in Washington DC vacancy
  • $113k - $188k

     ...Guidehouse's cyber practice, you will lead and execute core security compliance and RMF activities for classified federal...  ...across the engagement. What You Will Do : The Information Systems Security Officer ( ISSO ) serves as the primary liaison between the system... 
    Suggested
    Temporary work
    Flexible hours

    Guidehouse

    Washington DC
    12 hours ago
  •  ...Chief Information Security Officer (CISO) About the Company Mission-driven online provider of musculoskeletal therapy Industry Health, Wellness and Fitness Type Privately Held, VC-backed Founded 2015 Employees 501-1000 Funding $200+ million... 
    Suggested

    Confidential

    Washington DC
    4 days ago
  •  ...leading national software provider serving the consumer lending and financial services industry. We are seeking a Chief Information Security Officer (CISO) to lead the protection of corporate and client information assets and drive a secure, scalable technology environment... 
    Suggested
    Full time
    For contractors
    Remote work
    Monday to Friday

    Shaw Systems Associates

    Arlington, VA
    1 day ago
  •  ...Chief Information Security Officer (CISO) The CISO is responsible for overseeing and managing the organization's information security program, ensuring the protection of sensitive data and compliance with regulatory requirements. This role involves strategic planning... 
    Suggested

    Beyond SOF

    Washington DC
    4 days ago
  •  ...Chief Information Security Officer (CISO), Growth About the Company Accomplished provider of top-tier security services Industry Security and Investigations Type Privately Held About the Role The Company is seeking a Chief Information... 
    Suggested

    Confidential

    Washington DC
    12 hours ago
  • $172.97k - $321.24k

     ...universe, and connect the world. Our team is excited to meet you! Job Overview & Responsibilities At ULA, the Chief Information Security Officer (CISO) is responsible for the overall Security of the ULA Enterprise IT Infrastructure and Application portfolio... 
    Hourly pay
    Permanent employment
    Contract work
    Work experience placement
    Work at office
    Immediate start
    Relocation
    Flexible hours

    United Launch Alliance

    Arlington, VA
    12 hours ago
  • $90k - $120k

     ...Work Location: Tysons, VA (SCIF - Onsite) Clearance Required: TS/SCI Alpha Omega is looking for a Senior Information System Security Officer (ISSO) to join our team to support one of our government customers. The primary responsibilities for the position are... 
    Contract work
    Work experience placement
    Remote work
    Flexible hours

    Alpha Omega Integration, LLC

    Washington DC
    4 days ago
  •  ...Military Friendly & Preferred - Hoh SponsorThe Information Systems Security Officer (ISSO) is responsible for supporting the full lifecycle of security assessment and authorization (A&A) activities for information systems. The ISSO ensures that assigned systems comply... 
    Work at office
    Remote work

    Hiring Our Heroes

    Arlington, VA
    4 days ago
  • A reputable IT services provider in Washington is seeking a Mid-Level Information System Security Officer (ISSO). The role involves ensuring the confidentiality, integrity, and availability of information systems. Responsibilities include implementing security controls,... 

    Xpect Solutions

    Washington DC
    2 days ago
  • $248.1k - $400k

     ...preparation of independent, accurate, and informative audit reports.Our investor protection...  ...assigned to the Washington, DC (Headquarters) office.* **Generous paid time off**- Up to 6...  ...-time position for a Chief Information Security Officer (CISO) in the Office of... 
    Full time
    Work at office
    Immediate start

    Pcaob As

    Washington DC
    1 day ago
  • $100k - $130k

     ...Information Systems Security Officer Total Systems Technologies Corporation (TSTC) is an award-winning provider of full lifecycle program, investment, and security management consulting services that enable United States civilian, defense, intelligence, and law enforcement... 
    Full time
    Contract work
    Temporary work
    Local area
    Remote work
    Flexible hours

    Total System Technologies

    Washington DC
    3 days ago
  • $35 - $88 per hour

     ...Insight Global is seeking multiple Information System Security Officers (ISSO) onsite in Washington, DC. In this role, you will support solution accreditation for U.S. Government agencies, working closely with Prime's engineers to ensure compliance and security standards... 
    Hourly pay
    Contract work

    Insight Global

    Washington DC
    2 days ago
  •  ...Information Systems Security Officer Washington, D.C. Metro Why do you need to choose between doing important work and having a fulfilling life? At Ardent, we have both. Ardent employees are committed to solving our customers' most difficult problems—and we are... 
    Local area
    3 days per week

    Ardent Services

    Washington DC
    1 day ago
  •  ...Job Description Responsibilities: As an ISSO, you will play a critical role in ensuring the organization's information systems remain secure and compliant. Your responsibilities include: Authorization to Test (ATT) & Authorization to Operate (ATO) :... 
    Immediate start
    Flexible hours

    Novul Solutions

    Arlington, VA
    4 days ago
  • $92.21k - $125.15k

     ...ISSO Employment Type: Full-Time, Experienced Department: Information Technology CGS is seeking an Information Systems Security Officer (ISSO) with DIACAP and/or RMF experience who has deep expertise in security assessment documentation to support... 
    Full time
    Local area
    Flexible hours

    Contact Government Services, LLC

    Washington DC
    12 hours ago
  •  ...Information System Security Officer (ISSO) DDC Innovation & Growth is seeking a part-time Information System Security Officer (ISSO) to support the United States Court of Appeals for the Armed Forces (USCAAF) in Washington, DC. This position requires on-site support... 
    Contract work
    Part time
    For contractors
    For subcontractor
    Interim role
    Immediate start

    Diné Development

    Washington DC
    12 days ago
  • $113k - $149k

     ...Information Systems Security Officer, AD&S Washington, District of Columbia, United States Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology... 
    Full time
    Work experience placement
    Immediate start

    anduril

    Washington DC
    1 day ago
  • $97.24k - $131.56k

     ...Job Family: Cyber and IT Risk Management Skills: Information Security,Information Security Management,Information System Security...  ...Department of Defense (DoD) agencies, such as HQ Air Force, Office of the Secretary of Defense (OSD) and Military Compartments... 
    Temporary work
    Work at office
    Immediate start
    Worldwide
    Flexible hours

    General Dynamics Information Technology

    Washington DC
    4 days ago
  •  ...that provides services and solutions in: National Security Programs Professional, Administrative, and Management...  ...(Open) Position Status: Full Time Position Title: Information Systems Security Officer (ISSO) I Location: Washington, DC Security... 
    Full time
    For contractors
    Work at office
    Local area
    Flexible hours

    gTANGIBLE

    Washington DC
    3 days ago
  •  ...iQuasar, LLC is seeking a motivated Information System Security Officer to join our team. The ideal candidate will have a Bachelor's degree in Computer Science or a related four-year technical field, along with 4+ years of IT experience in NIST Cybersecurity Risk Management... 
    Work at office

    iQuasar

    Washington DC
    2 days ago
  • $97.24k - $118.56k

     ...SUBJECT MATTER EXPERTS specializing in security and risk management. We're intimately familiar...  ...security posture is maintained for an information system and as such, works in close...  ...Defense (DoD) agencies, such as HQ Air Force, Office of the Secretary of Defense (OSD) and... 
    Hourly pay
    Contract work
    For contractors
    Work experience placement
    Work at office
    Local area

    Watermark Risk Management International, LLC

    Washington DC
    19 hours ago
  •  ...GCyber is seeking an Information Systems Security Officer, to support a high profile DISA customer. You will be responsible to ensure cyber security controls are created, implemented, followed, and successfully assessed within the RMF to include successful completion... 

    GCyber

    Arlington, VA
    12 hours ago
  • $127.5k - $172.5k

     ...Family: Cyber and IT Risk Management Skills: Computer Security,Information Systems,Information System Security Experience: 5 +...  ...Capital Region in Summer 2026 As an Information System Security Officer (ISSO) at GDIT, you'll be a key part of a focused team... 
    Temporary work
    Summer work
    Immediate start
    Worldwide
    Relocation
    Flexible hours

    General Dynamics Information Technology

    Washington DC
    12 hours ago
  • $99k - $225k

     ...Information Systems Security Officer The Opportunity: Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to government organizations. In all of this "cyber noise," how can these organizations... 
    Full time
    Contract work
    Part time
    Local area

    Navstar

    Washington DC
    1 day ago
  •  ...Executive Summary: Our client seeks a Cloud Information System Security Officer (ISSO) - Senior Level (TS Required, eligible for SCI) for a role in Washington, DC. Position Description: The program provides support in Cybersecurity and Management to improve a... 
    Contract work

    Macpower Digital Assets Edge

    Washington DC
    12 hours ago
  • $62k - $141k

     ...Information System Security Officer, Mid The Opportunity : Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to government agencies. In all of this "cyber noise," how can these organizations... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Washington DC
    2 days ago
  • $114.6k - $192.5k

     ...Enforcement Agency CIO's organization is looking to provide Information Security as a Service and needs ISSO to support cybersecurity stakeholders...  ...At least 5 years serving as an Information Systems Security Officer (ISSO) at a cleared facility. Minimum of 7 years of work... 
    Contract work
    Work experience placement
    H1b

    SMX Corporation

    Washington DC
    2 days ago
  • $75.2k - $158.1k

     ...Intermediate Information System Security Officer CACI is searching for an Intermediate Information System Security Officer to join our team of highly qualified and dedicated individuals supporting the FEMA Office of the Chief Information Security Officer (OCISO) in... 
    Contract work
    Work experience placement
    Work at office
    Monday to Friday
    Flexible hours

    CACI International

    Washington DC
    1 day ago
  •  ...Information Systems Security Officer I (ISSO I) Crystal City, VA (JUS) - Crystal City, VA 22202 Overview Position Type Full Time Job Shift Day Description At System High Corporation—a Top Washington-Area Workplace (The Washington Post, 2023–2025), a Top... 
    Full time
    Work at office
    Shift work

    System High Corp

    Arlington, VA
    4 days ago
  •  .... Paul OR Washington DC who can work in-office 3+ days per week. Your Impact As our...  ...AOs and SCA teams, and help build a security program that scales with a fast-moving defense...  ...eMASS package lifecycle for one or more information systems — from initial system... 
    Work at office
    Local area
    3 days per week

    Swoop Technologies, LLC

    Washington DC
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Information Security Officer. Be the first to apply!