Information Security Officer
City First Bank of DC
Information Security Officer
City First Bank N.A. is a mission-driven Community Development Financial Institution (CDFI) principally focused on a transformative impact in underserved, urban markets with the highest needs to drive equitable economic development. Our credit activities are purely commercial and focused on the following segments: Multifamily Affordable Housing, Not-for-Profit Finance, and Small Business Finance. As a depository and commercial lending provider with over $1.3 billion in bank assets as of December 31, 2024, our unified organization has over 100 employees in Washington DC and Los Angeles/Inglewood, CA.
Role Summary
The Information Security Officer is responsible for monitoring, analyzing, and maintaining the bank's technical security controls in support of City First Bank's Information Security Program. This role will be focused on maintaining the security of the bank's applications and network which includes creation and timely execution of security projects, tool installations and integrating risk-based threat intelligence into the operational environment. The role also supports the ability to maintain assurance in our technical security controls, especially on the Cloud, so that risks to the confidentiality, integrity, and availability of the bank's information systems and infrastructure are sufficiently mitigated which in turn, supports the bank's operational and compliance goals. The role will also perform triage and analysis of security events escalated from the Tier1 and Tier-2 support teams.
Essential Functions and Responsibilities
- Advanced monitoring of the day-to-day operation of Security Information and Event Management (SIEM) and Network Anomaly Detection and other security control tools.
- Act as the first point of response for security event alerts and notifications. Maintain an efficient and secure IT computing infrastructure on the bank's environment, cloud, and SaaS products.
- Provide regular security reporting and risk metrics to IT Leadership, Senior Leadership, and committees as appropriate.
- Monitor knowledge sharing services and advise leadership on cybersecurity trends, emerging threats, and regulatory guidance.
- Leads Information Security compliance tasks and coordinate and gather artifacts for internal and external audits.
- Serve as the bank's designee for regulatory and audit purposes. Align controls with guidance and recommendations.
- Work with Compliance to identify, assess, and track remediation of security risk and findings.
- Ensure compliance with GLBA, FFIEC, and other regulatory, industry, and cybersecurity standards for access control and system permissions.
- Manage identity and access, roles and permissions, assignments and changes, and all other activities to ensure adherence to policies and procedures.
- Oversee periodic User Access Reviews for key bank systems.
- Enable and oversee the process of employee user account provisioning and de-provisioning, including Active Directory and SaaS applications.
- Lead the creation, implementation and integration of identity tools and practices that enhance the organization's security and regulatory compliance.
- Conduct and maintain IT risk assessments including Information Security, GLBA, and Vendor / Third Party reviews.
- Manage vendor due diligence reviews from an information security and technology perspective.
- Develop and evaluate security procedures for IT Department.
- Develop and administer the bank's security awareness program including annual training and phishing simulations.
- Partner with IT infrastructure, application, and operations teams to ensure secure system design and configuration.
- Generate and analyze reports, monitor alerts, and review reports to monitor security activities and document findings and recommend corrective actions.
- Work with managed service providers, network administrators and security operations to resolve problems, evaluate new solutions, recommend changes, and investigate incidents.
- Collaborate with lines of business, system, and network administrators to develop and manage role-based access control groups for ensuring appropriate access to information systems, applications, and data.
- Responsible for analyzing user access roles, permissions, and profiles to establish user provisioning within all bank applications.
- Implement and upgrade network security tools running in the physical and virtual environments.
- Ensure confidential data is secure and implement controls to ensure visibility and auditability across organization for changes in roles, functions, access-levels, and data footprint.
- Other duties as assigned.
Requirements
Education & Experience
Required Education/Experience:
- Bachelor's degree in Computer Science or Information Systems, Information Technology, or related focused technical training (CISSP, CISM, CRISC, or CISA) or in lieu 4 additional years of engineering and information security experience.
- 7+ years' experience in a combination of information security, or IT operations/engineering, or IT risk management
- 4+ years' experience with designing and implementing information security technologies.
- Extensive experience in banking regulations and compliance requirements, specifically related to regulatory examinations and security requirements.
- Experience in supporting and managing audit, examination, and regulatory interactions.
Preferred Education/Experience:
- 8 years of Engineering or Security Administration in banking preferred.
- 2 years security engineering/administration in the banking/financial sector
Knowledge, Skills, and Abilities
Required Knowledge & Skills:
- Knowledge of Microsoft Azure and Microsoft O365 virtualized environment and tools is a must. Ability to configure and work on Azure Security Center and O365 Security Center.
- Knowledge of Active Directory, Azure AD, identity management, DLP policies, Azure Sentinel and other security tools essential.
- Familiarity with at least one security best practice standards such as the Center for Internet Security (CIS) Security Controls or NIST Cybersecurity Framework, or equivalent.
- Excellent knowledge of Azure Security Center and Azure portal. Knowledge of SEIM and AD tools.
- Excellent knowledge of Microsoft Operating system and Azure tools. Strong Active Directory and Windows Group Policy knowledge.
- Networking technology and protocols, including routers, switches, VPNs, Citrix, email gateways, etc.
- Requires skill in providing expert input into technology projects.
- Assist the Tier-1 and Tier-2 escalations with troubleshooting and analysis of security events.
$113k - $188k
...Guidehouse's cyber practice, you will lead and execute core security compliance and RMF activities for classified federal... ...across the engagement. What You Will Do : The Information Systems Security Officer ( ISSO ) serves as the primary liaison between the system...SuggestedTemporary workFlexible hours- ...Job Description Job Description Position Description We are seeking a hands-on Chief Information Security Officer (CISO) to lead and execute the company’s cybersecurity program in support of federal government contracts. This is a senior-level individual contributor...SuggestedFull time
$135k - $140k
...organization has over 100 employees in Washington DC and Los Angeles/Inglewood, CA. ROLE SUMMARY The Information Security Officer is responsible for monitoring, analyzing, and maintaining the bank's technical security controls in support of City...SuggestedWork at office- ...Chief Information Security Officer (CISO) The CISO is responsible for overseeing and managing the organization's information security program, ensuring the protection of sensitive data and compliance with regulatory requirements. This role involves strategic planning...Suggested
- ...A reputable IT services provider in Washington is seeking a Mid-Level Information System Security Officer (ISSO). The role involves ensuring the confidentiality, integrity, and availability of information systems. Responsibilities include implementing security controls...Suggested
- ...leading national software provider serving the consumer lending and financial services industry. We are seeking a Chief Information Security Officer (CISO) to lead the protection of corporate and client information assets and drive a secure, scalable technology environment...Full timeFor contractorsRemote workMonday to Friday
- ...Information Systems Security Officer Washington, D.C. Metro Why do you need to choose between doing important work and having a fulfilling life? At Ardent, we have both. Ardent employees are committed to solving our customers' most difficult problems—and we are...Local area3 days per week
$99k - $225k
...Job Number: R0230187 Information System Security Officer The Opportunity: We're looking for an Information System Security Officer (ISSO) who can create solutions for the Government that will withstand even the most advanced cyber threats. As an ISSO at Booz Allen, you...Full timeContract workPart timeFor subcontractorLocal areaRemote work$100k - $130k
...Information Systems Security Officer Total Systems Technologies Corporation (TSTC) is an award-winning provider of full lifecycle program, investment, and security management consulting services that enable United States civilian, defense, intelligence, and law enforcement...Full timeContract workTemporary workLocal areaRemote workFlexible hours$92.21k - $125.15k
...ISSO Employment Type: Full-Time, Experienced Department: Information Technology CGS is seeking an Information Systems Security Officer (ISSO) with DIACAP and/or RMF experience who has deep expertise in security assessment documentation to support Dept. of Commerce systems...Full timeLocal areaFlexible hours- ...Information System Security Officer / ISSO NXTKey provides commercial and government entities with the horsepower to drive their business machine faster and more efficiently to successful outcomes. To support our customers needs; we excel at providing Cyber Security...
- ...Job Description Responsibilities: As an ISSO, you will play a critical role in ensuring the organization's information systems remain secure and compliant. Your responsibilities include: Authorization to Test (ATT) & Authorization to Operate (ATO) :...Immediate startFlexible hours
- ...additional 4 years experience may be substituted in lieu of degree). Position Description: PingWind is seeking an Information System Security Officer (ISSO) responsible for overseeing system-level cybersecurity compliance, assessment coordination, and continuous...Temporary workFlexible hours
- ...Information Systems Security Officer (ISSO) II Location: Joint Base Anacostia-Bolling (JBAB) DC Clearance: TS/SCI required with the ability to obtain CI poly The ISSO is responsible for ensuring the appropriate operational security posture is maintained for an information...Work at office
- ...Information Systems Security Officer I (ISSO I) Crystal City, VA (JUS) - Crystal City, VA 22202 Overview Position Type Full Time Job Shift Day Description At System High Corporation—a Top Washington-Area Workplace (The Washington Post, 2023–2025), a Top...Full timeWork at officeShift work
- ...documentation, including Body of Evidence artifacts, SSPs, and related security documentation within eMASS to support authorization and continuous monitoring activities. Serve as the Information System Security Officer (ISSO) for assigned Joint Service Provider (JSP) systems...Permanent employmentLocal area
$95k - $110k
...Information Systems Security Officer (ISSO) Location: Washington, DC (Onsite) Clearance: Top Secret Status: Exempt Salary: $95k - $110k per year Responsibilities: Work as part of the IT Security Support Team which manages and operates an information systems...Local area- ...Tactibit Technologies provides innovative information technology, cybersecurity, and cloud support services to the Federal Government... ...in everything we do. About the Information System Security Officer position We are looking for a talented cybersecurity professional...Flexible hours
$80k - $120k
...Description SAIC is seeking an Information System Security Officer (ISSO) for our team to support a government customer. This position is remote, but the candidate must be local to the DC area (within 50 miles) and will be expected to come in at least once every 2 weeks...Local areaRemote work- ...personal appearance, matriculation, political affiliation, credit information, employment status, physical or mental disability, genetic... ...Knowledgebase, LLC., is seeking an Information Systems Security Officer for a project at a large NIH support organization. The successful...Full timeContract workPart timeWork experience placementLocal area
- ...Job Summary: DDC Innovation & Growth is seeking a part-time Information System Security Officer (ISSO) to support the United States Court of Appeals for the Armed Forces (USCAAF) in Washington, DC. This position requires on-site support and offers an opportunity...Contract workPart timeFor contractorsFor subcontractorInterim roleImmediate start
- ...Information System Security Officer (ISSO) Arlington, VA We deliver essential technology services to our customers in support of their missions to sustain the national security and economic interests of our nation. SecuriGence is seeking a talented Information System Security...Remote work1 day per week
$97.24k - $118.56k
...Small Business. SUBJECT MATTER EXPERTS specializing in security and risk management. We’re intimately familiar with DOD... ...savings plan. At Watermark, our people come first! Information Systems Security Officer II The ISSO is responsible for ensuring the...Hourly payContract workFor contractorsWork experience placementWork at officeLocal area- ...Information System Security Officer Information Technology Strategies, Inc. is a government IT solutions provider servicing commercial and government initiatives in various parts of the United States. We are currently seeking an Information System Security Officer to...Contract workTemporary workLocal area
- ...Information System Security Officer (ISSO) Apogee Research brings cutting-edge research into practice for the DoD community. We blend agility with rigor to develop new technologies and transition them into operational use. Founded in 2012, Apogee Research brings together...Full timeContract workWork at office
- ...Headquarters United States Space Force ( HQ USSF) Director of Staff Security Office (SF/DSZ) is responsible for carrying out and providing... ...to the Sensitive Compartmented Personnel Security Program, Information Security, Industrial Security, Physical Security, and...Temporary workFor contractorsWork at officeRemote workMonday to FridayFlexible hours
- ...As an Information Systems Security Officer, you will be entrusted with the critical responsibility of safeguarding the integrity of operating systems and applications. Your role will require you to adeptly identify, select, and implement the most appropriate security...Contract workWork at office
- 4275 Information Systems Security Officer 4275 | Top Secret Job Description: OVERVIEW: We are seeking a mid-level ISSO for our mission critical customer in Washington, DC. You will work as part of a highly talented team providing security compliance expertise...
- ...RMF). The contractor will apply knowledge and understanding of information assurance (IA) concepts and practices. and procedures using... ...and DIA policies and standards to minimize and/or mitigate RMF security risks. The contractor will review and comment on technical...For contractorsWork experience placementFor subcontractorWorldwide
- ...Information System Security Officer II (Req: 26-J-1801) The ISSO is responsible for ensuring the appropriate operational security posture is maintained for an information system and as such, works in close collaboration with the ISSM and ISO. The position shall have the...Work at officeImmediate startFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security Officer. Be the first to apply!
- chief information security officer ciso Washington DC
- ciso Washington DC
- chief information security officer Washington DC
- information security officer Washington DC
- remote ciso Washington DC
- business information security officer Washington DC
- information systems security officer Washington DC
- information security compliance analyst Washington DC
- entry level information security analyst Washington DC
- information security analyst Washington DC


