Chief Information Security Officer
Origin Bank · Mobile, AL · Yesterday
Information TechnologyFull-time
Your Career. Your Story. Let's Write the Next Chapter Together. At Origin Bank, a job isn't just a paycheck - it's a meaningful journey. We're committed to helping you grow both professionally and personally in an environment where people come first. We offer a competitive total rewards package, including generous benefits and compensation tailored to your skills, experience, and education. What truly sets us apart is our people-first culture. Here, you'll be supported by unique initiatives like our Dream Manager program, one-on-one guidance from a nationally certified health and wellness coach, and free access to certified financial professionals who are here to help you plan for your future. If you're looking for a career that empowers you to make meaningful connections, positively impact others, and pursue your personal and professional dreams-we'd love to meet you. Apply today and start the most rewarding chapter of your career with us. Job Description The Chief Information Security Officer (CISO) is a senior leadership role responsible for the development, implementation, and ongoing oversight of the Bank’s enterprise information security, cybersecurity, and data protection program. This role will support the Bank’s ability to protect the confidentiality, integrity, and availability of information assets while aligning cybersecurity practices with business objectives, regulatory expectations, and the Bank’s risk appetite framework. The CISO operates with appropriate independence within the Risk organization and provides objective oversight, escalation of cybersecurity risks, and subject matter expertise to executive leadership, Board committees, and business stakeholders. The role is accountable for maintaining a sound control environment, effective risk management processes, and regulatory readiness. The preferred work location for this role will be based within one of our Louisiana, Texas, Alabama, Florida, or Mississippi markets. Word Information Security Governance & Program Leadership Develops, implements, and manages the Bank’s enterprise information security program in alignment with strategic priorities and risk appetiteEstablishes and maintains information security policies, standards, and procedures consistent with regulatory guidance and industry frameworksProvides regular reporting to the Chief Risk Officer and senior leadership on:Cybersecurity risks and emerging threat landscapeKey risk indicators (KRIs) and program performanceControl effectiveness and remediation statusSupports Board and Risk Committee reporting by preparing materials and analysis as neededPromotes enterprise-wide security awareness and accountability Control Assurance & Monitoring Oversees the design and operation of key cybersecurity controls and monitoring processesSupports control assurance activities, including:Control validation and testing coordinationVulnerability management and remediation trackingEnsures control issues are identified, escalated, and remediated in a timely mannerPartners with Internal Audit and Risk teams to support independent testing and validation efforts Threat Protection & Security Operations Oversees day-to-day security operations, including monitoring, detection, and response processesDirects threat intelligence, vulnerability management, and penetration testing activitiesEnsures effective implementation of core security controls, including:Identity and access managementData protection and encryptionEndpoint and network securitySupports continuous improvement of detection and response capabilities Incident Response & Resilience Coordination Maintains the Bank’s cyber incident response framework and supporting proceduresCoordinates response to cybersecurity incidents in partnership with Technology, Risk, Legal, and leadership teamsConducts post-incident reviews and supports remediation trackingFacilitates cyber incident tabletop exercises and scenario testing with key stakeholdersAligns cybersecurity incident response with broader business continuity and disaster recovery plans Third-Party Risk Oversight Supports the Bank’s third-party cybersecurity risk management program across the vendor lifecycle:Due diligence and onboardingOngoing monitoringIssue Identification and remediationWorks with Vendor Management, Risk, and Legal to ensure third-party security expectations are metProvides risk assessments and recommendations for third-party engagements Data Protection & Privacy Alignment Supports the Bank’s data protection strategy, including:Data classification and handling standardsProtection of sensitive and confidential informationCoordinates with Legal, Compliance, and Risk to ensure alignment with privacy requirementsMonitors controls designed to prevent unauthorized data access or loss Technology & Emerging Risk Advisory Partners with Technology teams to ensure security considerations are incorporated into system design and implementationProvides input into risk assessments for:Cloud environmentsDigital transformation initiativesEmerging technologies (e.g., AI, APIs, fintech integrations)Promotes consistent application of secure development and architecture practices Regulatory & Audit Support Supports regulatory examinations and audits related to cybersecurity and information securityAssists in the preparation and coordination of responses to regulatory and audit inquiriesTracks and supports remediation of findings, including documentation and evidence collectionMaintains documentation to demonstrate compliance with applicable regulatory expectations Leadership & Collaboration Serves as a key advisor to Risk leadership and business units on cybersecurity mattersBuild relationships with internal stakeholders, auditors, and external partnersLeads and develops the Information Security team, including talent development and performance managementPromotes a collaborative, risk-aware culture across the organization Word Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, status as a protected veteran, or any other protected category under applicable federal, state, and local laws. Know Your Rights