Deputy Chief Information Security Officer
$269.7k - $353.95kMercury
The role:
You will be the operating second to the CISO and own the bank-entity scope of Mercury's 2LOD Information Security program. You'll be the person who keeps the program examiner-ready by default: coherent policy architecture, evidenced controls, a credible gap-remediation track record, and a tested incident response program with documented exercise history.
This is not a research or strategy role. It is a build-and-defend role. You will sit across the table from OCC examiners, FFIEC IT audit teams, our Chief Risk Officer, and the board's risk committee, and you will be expected to answer for every line in our policies and every status in our control inventory.
_*Mercury is a fintech company, not an FDIC-insured bank. Banking services provided through Choice Financial Group and Column N.A., Members FDIC_
What you'll own:
- Bank-entity 2LOD InfoSec program. Governance, policy, risk, and oversight scoped to the chartered bank.
- Examiner posture. OCC, FFIEC, FDIC and FRB examiner inquiries; ownership of the examiner-ready narrative; coordination of the evidence.
- FFIEC control remediation. Lead remediation of identified FFIEC IT control deficiencies to charter readiness ahead of the OCC pre-opening examination
- Policy architecture. Carry the bank-scoped policy stack (Policy / Standard / Procedure), including ratification cycles, MRCC memos, and board approvals.
- BC/DR. Partner with the Chief Risk Officer on bank continuity, resilience, and recovery, including tabletop exercises and full-scale drills.
- Audit and assurance. Manage relationships with internal audit (3LOD) and external assessors (SOC 2, FFIEC CAT, regulator-led IT examinations).
- Third-party risk. Ensure TPRM evidence holds up to bank-grade scrutiny for critical service providers and material outsourcing arrangements.
- Team development. Coach and grow the GRC sub-team; run a recurring training cadence; build the bench depth a national bank requires.
What we need:
- 8+ years in Information Security , with 3+ years inside a regulated bank, trust bank, or de novo bank charter effort. Mercury is a startup chartering a national bank — this experience is non-negotiable.
- Deep FFIEC and OCC fluency. You have deep working knowledge of the FFIEC CAT, the FFIEC IT Examination Handbook, BSA/AML IT supervisory expectations, and the OCC Heightened Standards.
- Direct examiner-facing experience. You have defended a control to an OCC, FDIC, or Federal Reserve examiner. You know what good evidence looks like before it gets challenged.
- Policy and standards craft. You can draft a board-ratifiable policy and the supporting standards stack that operationalizes intent, not just satisfies a checklist.
- Operating discipline. You run cadences, write status that survives executive review, and maintain currency of controls, evidence, and risk registers.
- 2LOD instinct. You understand the three-lines-of-defense model and have served in the oversight role.
What we'd love:
- Prior Deputy CISO or equivalent senior 2LOD role at a national bank, trust bank, or large credit union.
- Charter or de novo bank experience — if you've stood one up before, that is a meaningful advantage here.
- Strong technical baseline, you don't need to be an engineer, but you should be able to challenge an architecture review and read an incident timeline credibly.
- CISSP, CISM, or CRISC
What success looks like:
- At 30 days - You have developed working knowledge of Mercury’s FFIEC IT control inventory and roadmap, every in-flight policy draft, and met one-on-one with the GRC team. You can speak to the top ten risks in the bank-entity program by name.
- At 90 days - You are running the weekly bank charter status cadence, leading examiner-readiness reviews, and personally accountable for at least three priority program tracks. The CISO is briefing the board and the MRCC with material you authored.
- At one year - The charter timeline is on track. The bank-entity Information Security program sustains supervisory-grade standards as a standing posture. You are the executive other functions consult to determine whether a security risk is material.
Why this role:
We are building a security program designed to protect Mercury and enable the business. Chartering a national bank does not change that philosophy. It does mean we need a Deputy who can hold the bar to OCC standards without losing the operating tempo that has defined Mercury since inception.
If you've been waiting for a chance to build the bank-side security program you wish you'd inherited, this is it.
Mercury values diversity & belonging and is proud to be an Equal Employment Opportunity employer. All individuals seeking employment at Mercury are considered without regard to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, sexual orientation, or any other legally protected characteristic. We are committed to providing reasonable accommodations throughout the recruitment process for applicants with disabilities or special needs. If you need assistance, or an accommodation, please let your recruiter know once you are contacted about a role.
#LI-DNI
Total Rewards
The total rewards package at Mercury includes base salary, equity (stock options/RSUs), and benefits.
Our salary and equity ranges are highly competitive within the SaaS and fintech industry and are updated regularly using the most reliable compensation survey data for our industry. New hire offers are made based on a candidate’s experience, expertise, geographic location, and internal pay equity relative to peers.
Our target new hire base salary ranges for this role are the following :
US employees in New York City, Los Angeles, Seattle, or the San Francisco Bay Area:
$269,700—$353,950 USD
US employees outside of New York City, Los Angeles, Seattle, or the San Francisco Bay Area:
$242,700—$318,550 USD
- ...team that holds a high bar for itself — keep reading.About the RoleSocure is seeking an experienced, executive-level Deputy Chief Information Security Officer (Deputy CISO) to report directly to the CISO. In this role, you will lead company-wide security, data governance,...Suggested
- ...Deputy Chief Information Security Officer (CISO) About the Company Industry-leading cybersecurity platform Industry Computer & Network Security Type Privately Held, VC-backed Founded 2019 Employees 201-500 Funding $200+ million Categories...Suggested
- ...Deputy Chief Information Security Officer (CISO), Security Technology About the Company Popular provider of revenue cycle management solutions Industry Hospital & Health Care Type Privately Held, Private Equity-backed Founded 2003 Employees 1...Suggested
- ...Deputy Chief Information Security Officer Sardine is hiring a Deputy Chief Information Security Officer to partner closely with our CISO and help scale our security program as we grow. This is a senior, high-impact role for a security leader who can operate across...SuggestedRemote workHome officeFlexible hours
- ...startup with the trust and stability of an FDIC-insured national bank. We are seeking a highly collaborative, hands-on Chief Information Security Officer (CISO) who wants to build, protect, and scale a digital banking infrastructure that serves millions of customers....SuggestedWork at officeShift work
$260.5k - $325.6k
...an unprecedented dataset of empirical information via a revolutionary cloud-based... ...processing, and software engineering, our office is a truly inspiring mix of experts from... ...the Role: As the Vice President and Chief Information Security Officer (CISO), you will serve as a...Full timeContract workTemporary workWork experience placementWork at officeLocal areaRemote workHome officeShift work3 days per week- ...Scanner, a Security Data Lake platform, seeks a Head of Sales to build and lead the sales organization through its next growth phase. You will stay close to CISOs and security leaders while collaborating with the CEO and cross-functional leaders to shape Scanner's GTM...
- ...decades‑old legacy systems with AI‑native technology that automates 90% of the manual work humans once had to do. What you'll do: Build security tooling & processes that engineers actually use. Create internal mechanisms for appsec, identity and access management, and threat...
- ...AIOS is hiring a Head of Information Security & Systems to build a secure foundation enabling global scale. You will own cybersecurity across AIOS’ healthcare, technology, and pharmacy platforms, shaping strategy, governance, controls, and tooling. In this fully remote...Remote work
$350k
...building a smarter, faster, and more secure financial future by revolutionizing... ...About the team The Security & Information Technology organization is the backbone... ...Reporting directly to the Global CTO, the Chief Information Security Officer (CISO) & Head of Information...Full timeContract workTemporary workWork at officeWorldwideHome officeFlexible hours- ...build the future of inclusive finance through cutting‑edge technology and customer‑centric solutions. Overview As Chief Information Security Officer (CISO), you will be the primary leader responsible for developing and implementing our information security strategy....Immediate startFlexible hours
$299k - $344k
...apply human judgment to AI outputs, and keep building AI fluency in ways that support their role and our mission. The Chief Information Security Officer will be responsible for defining, leading, and advancing Spring Health’s enterprise-wide information security,...Full timeWork at officeWorldwideRelocationSleeping nights2 days per week3 days per week- ...Chief Information Security Officer (CISO) About the Company Innovative provider of data safety & recovery solutions Industry Information Technology and Services Type Privately Held Founded 2024 Employees 51-200 Specialties cloud backup...
- ...Chief Information Security Officer (CISO) About the Company Innovative provider of online banking payment solutions Industry Financial Services Type Privately Held, VC-backed Founded 2008 Employees 1001-5000 Specialties fintech e-commerce...
- ...Chief Information Security Officer (CISO), Information Security & Compliance About the Company Innovative artificial intelligence (AI) & marketing analytics platform Industry Information Technology and Services Type Public Company Founded 2014...
- ...Chief Information Security Officer (CISO) About the Company Popular provider of workplace mental health solutions Industry Mental Health Care Type Privately Held, VC-backed Founded 2016 Employees 1001-5000 Funding $200+ million Categories...
- ...Field Chief Information Security Officer (CISO) About the Company Industry leading provider of security & compliance solutions Industry Outsourcing/Offshoring Type Privately Held Founded 2020 Employees 501-1000 Funding $200+ million Categories...Remote work
- ...Deputy Chief Technology Officer (CTO) About the Company Prominent political organization Industry... ...the Chief Technology Officer, Chief Security Officer, and Heads of Data &... ...Technology Officer Functions Engineering Information Technology ConfidentialRemote work
- ...Deputy Chief Technology Officer (CTO) About the Company Top-tier investment bank Industry Investment Banking Type Public Company... ...scenarios. Hiring Manager Title CIO/CTO Functions Engineering Information Technology Confidential
- ...how the HealthTech ecosystem connects. We're looking for a Security Lead to own our security governance, compliance, IT... ...governance, compliance, and IT programs end-to-end.Serve as named Information Security Officer and Privacy Officer for SOC 2 and HIPAA — own the policy...Live in
$250k - $350k
...embedded software, aircraft, and field infrastructure. Security must protect those systems, customers, partners, and the... ...enabling engineering teams to deliver safely and quickly.As Chief Information Security Officer, you will own company-wide security and privacy strategy...Local area- ...General Internal MedicinePosition InformationPosition Title: Deputy Chief of Integrative Health, San Francisco VA Health Care System (SFVAHCS... ...must list current and/or pending qualifications upon submission.*Please click here to see the VA’s website for salary informationFull time
$78k - $82k
...Disabilities Foundation (PWDF) is seeking a Deputy Executive Director (DED). PWDF is a small... ...of Public Awareness/Education and Office Manager. Support the Advocacy Program and... ...formats. Highly Preferred Experience in Social Security, employment, health care and other...Full timeWork at officeLocal area- Telecommunications ManagerThe major duties of the Telecommunications Manager include, but are not limited to, the following:Managing, coordinating, and administrating operations of a communications centerDirect supervision of public safety dispatch supervisors and public...
- The City and County of San Francisco seeks a Criminalist I in Digital Forensics to perform scientific examination, analysis, and interpretation of digital evidence in support of investigations. The role emphasizes proper evidence handling, adherence to forensic standards...
- ...Of Communications Center This position acts as manager of the communications center which is located in the San Francisco Field Office Dispatch Operations Center of the United States Park Police. The Dispatch Operations Center operates 24-hours a day/ 7 days a week...Work at office
$201.11k - $269.08k
...required to make them successful. They can engage credibly with Chief Data Officers, CIOs, Enterprise Architects, Data Governance leaders, and... .... Please see our Candidate Privacy Statement for more information about how we use your personal data and your rights, including...Full timeWork at office- Job description: Location: San Francisco, CA (on-site)Employment: Full-TimeAbout the RoleWe are looking for a Founding CTO, someone who wants to be the company's technical co-pilot. You will start hands-on, ship fast, and own the core architecture. As the company scales...Relocation
- ...headquartered in San Francisco, CA. and has an office in Cambridge, MA. About the role:... ...We are looking for an experienced IT & Security Administrator to support Lumafield's day... ..., gender identity, disability, genetic information or veteran status. Reach out if...Work at officeFlexible hours
- ...infrastructure This is a ground-floor opportunity to build a security organisation from scratch, setting policies, controls, and... ...Responsibilities: Define and execute the company-wide information security and compliance strategy across infrastructure, cloud,...Permanent employmentRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Deputy Chief Information Security Officer. Be the first to apply!
- information security officer San Francisco, CA
- information security officer iso San Francisco, CA
- ciso San Francisco, CA
- chief information security officer ciso San Francisco, CA
- business information security officer San Francisco, CA
- chief information security officer San Francisco, CA
- information security compliance analyst San Francisco, CA
- information security San Francisco, CA
- information security analyst San Francisco, CA
- senior director information security San Francisco, CA


