Jobs · Information Technology · Oklahoma

Chief Information Security Officer

BOK Financial · Tulsa, OK · Yesterday
On-siteInformation Technology$54/hrFull-time

Protect what matters most at a $54 billion financial institution. This is a senior executive role with enterprise-wide visibility, positioned to define how BOK Financial protects its systems, data and the customers who trust us with their financial lives. As Chief Information Security Officer, you will lead the enterprise information security strategy and build a security program sized to our complexity — a bank, SEC-registered investment advisers, FINRA-supervised broker-dealers, and trust and fiduciary businesses, with more than $120 billion in assets under management or administration. You will also serve as the organization’s Privacy Officer, owning the enterprise privacy program end to end.

About the role

The Chief Information Security Officer (CISO) is responsible for leading the enterprise information security strategy and protecting the organization’s systems, data, customer information, and information assets from compromise, unauthorized access, disclosure, or disruption. This role designs, implements, and matures an enterprise-wide information security program aligned to the organization’s size, complexity, risk profile, regulatory obligations, and business strategy. BOKF’s information security program must also support the risk and regulatory complexity associated with more than $120B in assets under management or administration, two SEC-registered investment advisers, and two FINRA-supervised broker-dealer affiliates/subsidiaries.

The CISO is expected to support SEC and FINRA regulatory readiness by coordinating with affiliate compliance, legal, supervision, and business leaders on cybersecurity examinations, incident escalation and response, customer and client data protection, books-and-records considerations, third-party risk oversight, remediation tracking, and evidence-based demonstration of effective security governance across regulated advisory and broker-dealer affiliates.

The CISO also serves as the organization’s Privacy Officer and is responsible for overseeing the enterprise privacy program, including privacy governance, privacy risk management, regulatory readiness, customer/client information protection, privacy incident response, breach notification coordination, and alignment of privacy controls with cybersecurity, data governance, business, and regulated affiliate requirements.

The CISO partners closely with executive leadership, the Board, Risk, Information Technology, Compliance, Legal, Audit, business leaders, and external partners to identify, assess, monitor, and communicate the organization’s cyber-risk profile. This includes oversight of inherent risk, control effectiveness, residual risk, risk trajectory, security incidents, regulatory expectations, third-party risk, and emerging threats. The role is accountable for ensuring the organization maintains a strong security culture, operates within established risk thresholds, and has the leadership, governance, resources, controls, and response capabilities needed to protect the organization and its customers.

Responsibilities

  • Lead the enterprise information security program — policies, standards, controls, governance and reporting.
  • Define the organization’s cyber-risk profile, including inherent risk, control effectiveness, residual risk and risk trajectory against Board-approved thresholds.
  • Report security strategy, program effectiveness, incidents, and audit and examination outcomes to executive leadership and the Board.
  • Direct enterprise security operations — threat monitoring, vulnerability management, incident response, remediation and regulatory notification.
  • Serve as the organization’s Privacy Officer, owning privacy governance, risk assessments, training, incident response and breach notification.
  • Govern cloud security across SaaS, PaaS and IaaS, from architecture and identity to encryption, monitoring, resilience and cloud incident response.
  • Establish cybersecurity governance for AI and generative AI, including acceptable use, sensitive data protection and third-party AI risk.
  • Oversee third-party cyber risk from due diligence and contracting through ongoing monitoring, control validation and incident coordination.
  • Partner with affiliate compliance, legal and business leaders to drive SEC and FINRA regulatory readiness.
  • Secure a defensible, risk-based security budget by quantifying cyber risk in financial terms.
  • Build a high-performing security leadership team with strong talent pipelines, succession planning and a culture of accountability.

Team Culture

  • Enterprise mindset — aligning teams and priorities to protect clients and the business as one organization
  • Innovation with discipline — advancing cloud, AI and modern security capabilities while maintaining strong governance
  • Leadership at every level — empowering teams while influencing across a matrixed, highly regulated organization
  • Continuous evolution — staying ahead of threats, technologies and regulatory expectations

This is a team where leaders are accessible, decisions get made, and the impact of your work is visible all the way to the Board.

Requirements

  • Bachelor’s degree in Computer Science, Information Security, Information Assurance, Technology, Risk Management, Business, or a related field, with 15+ years of progressively responsible experience in information security, cybersecurity, technology risk, or related disciplines, including 8–10+ years in senior cybersecurity leadership roles; or an equivalent combination of education and experience.
  • Strongly preferred experience includes leadership of enterprise cybersecurity, privacy, cloud security, AI governance, technology risk, incident response, third-party risk management, and regulatory compliance programs within a large regulated financial services organization, including SEC-registered, FINRA-regulated, wealth management, fiduciary, and banking environments.
  • Experience presenting to executive leadership and Boards, supporting regulatory examinations, and leading security program transformation initiatives is preferred.
  • Professional certifications such as CISSP, CISM, CISA, CRISC, GIAC, or related security, risk, audit, or privacy certifications are preferred.

Skills

  • Deep expertise in cybersecurity, information security governance, risk management, security operations, cloud security, data protection, identity and access management, incident response, and third-party risk management.
  • Strong knowledge of financial services regulations and industry frameworks, including banking, privacy, cybersecurity, SEC, FINRA, and other applicable regulatory and compliance requirements.
  • Understanding of AI, generative AI, and emerging technology governance, including data protection, third-party risk, regulatory considerations, and cybersecurity controls.
  • Expertise in cloud security governance and architecture, including SaaS, PaaS, IaaS, access management, encryption, monitoring, resilience, and cloud service provider oversight.
  • Strong knowledge of privacy governance and Privacy Officer responsibilities, including data protection, privacy risk management, breach response, regulatory compliance, and customer information protection.
  • Ability to develop and execute cybersecurity strategy, communicate complex risks to executive leadership, Boards, regulators, and business stakeholders, and align security initiatives with organizational objectives and risk appetite.
  • Proven leadership, collaboration, and decision-making skills, with the ability to build high-performing teams, lead through cyber incidents and regulatory events, influence across functions, and adapt security programs to evolving threats, technologies, and regulatory requirements.

Similar jobs

Security Officer

HillwoodDallas, TX· 2 wk ago
Customer Serviceapply on recruiting2.ultipro.com

Security Officer

Citadel Security USACheyenne, WY· 2 wk ago
$22/hrapply on citadelsecurityusa.applicantstack.com

Security Officer

Children's Hospital of The King's DaughtersNorfolk, VA· 2 wk ago
Information Technologyapply on preview-site-65f2e3.hctsportals.com

Security Officer

Securitas Security Services USA, Inc.Lewisburg, TN· 1 mo ago
Information Technologyapply on ekaw.fa.us2.oraclecloud.com

Security Officer

GSSC (General Security Services Corporation)St Cloud, MN· 1 mo ago
Information Technologyapply on workforcenow.adp.com

Security Officer

Unitus Security, LLCAtlanta, GA· 1 mo ago
Information Technologyapply on recruitingbypaycor.com