Information Security Manager - IAM
At FHLB Des Moines, we work each day to develop an inclusive culture that supports and leverages the complexity of a diverse workforce. This enables us to effectively serve the needs of our members and help them succeed.
About the Role
Plans, organizes, and manages an information security team. Partners with IT and builds and maintains information security systems to ensure that data systems, databases, and networks are protected from unauthorized users. Provides strategic direction and operational oversight for identity lifecycle management, authentication services, single sign-on, enterprise MFA, and credential and privileged access management. Organizes security investigations and implements corrective actions. Provides the Bank with appropriate education and training to support Information Security best practices.
Responsibilities
- Manage and deliver technical projects and enhancements.
- Propose and partner with the Bank to deliver security improvements, close gaps, or address control issues.
- Partner with Internal Audit, SOX, and Enterprise Risk to ensure alignment in improving information security and addressing issues.
- Ensure the Bank has a security response plan and partner with the business to ensure readiness for a cyber event.
- Ensure appropriate controls are maintained for joiner, mover, and leaver processes.
- Identify opportunities for automation within team processes.
- Understand gaps in the information security program (NIST Gap assessment) and propose actions to close gaps.
- Ensure ongoing education of teams, as required by many regulations and best practices.
- Provide updates to regulators on any information requests.
- Ensure highly qualified staff to address the responsibilities of the team.
- Work with employees to keep up with emerging threats and practices to improve security posture.
- Manage and develop high-performing team members through communication, feedback, coaching, and completion of mid-year and year-end performance evaluations.
- Identify strengths and weaknesses in team members and provide training to improve skills and knowledge.
- Manage departmental regulatory issues and internal controls.
- Serve as an escalation point of contact for cybersecurity, IT, and business unit guidance.
- Develop and implement comprehensive cybersecurity strategies, policies, and procedures to protect the organization's information assets from cyber threats.
- Collaborate with senior management to assess security risks, prioritize initiatives, and allocate resources effectively.
- Stay abreast of emerging threats, industry best practices, and regulatory requirements to ensure the organization's security posture remains current and effective.
- Oversee the design, implementation, and maintenance of the organization's network infrastructure, including routers, switches, firewalls, and VPNs.
- Monitor network performance, troubleshoot issues, and implement solutions to optimize reliability, scalability, and security.
- Collaborate with cross-functional teams to plan and execute network upgrades, expansions, and migrations while minimizing disruptions to business operations.
- Develop and maintain incident response plans and procedures to effectively detect, contain, and mitigate cybersecurity incidents.
- Lead investigations into security breaches, coordinate with relevant stakeholders, and implement corrective actions to prevent future incidents.
Requirements
- Bachelor’s degree in information security, computer science, or equivalent work experience.
- Extensive knowledge of data security, access management, and information systems.
- Specific knowledge of data security standards, procedures, and products.
- Knowledge of risk management and effective control procedures, project management.
- Understanding of SSO, MFA, identity lifecycle management, and privilege access management.
- Experience with protocols such as SAML and OAuth, and managing entitlements/provisioning on a platform such as SailPoint IIQ.
- Strong understanding of Active Directory and cloud identity platforms.
- Excellent written and verbal communication skills.
- 5-10 years’ experience managing projects, developing, and reviewing policies, methodologies, and procedures for security.
Pay
Annual Salary: $128,211.00 - $152,251.00. This salary range represents the Bank’s good faith and reasonable estimate of possible compensation at the time of hire. The offer will be determined by the selected applicant’s education, experience, knowledge, skills, and abilities, as well as internal equity and alignment with market data. This role is also eligible to participate in the Bank’s annual incentive plan.
Benefits
- 11 paid holidays.
- 5 weeks of PTO and a work culture that values work/life balance.
- Hybrid work schedule for most roles.
- 401(k) matching: 100% of the first 6% you contribute, plus an additional 4% non-discretionary contribution at the end of the year.