Third Party Security Lead
Old National Bank · Evansville, IN · 6 days ago
Information Technology$82k–$165k/yrFull-time
Responsibilities
- Salary Range: $81,700/yr - $165,100/yr plus bonus.
- The Third‑Party Security Lead is responsible for the design, execution, and continuous improvement of ONB’s third‑party cybersecurity and technology risk oversight.
- Lead and oversee inherent risk assessments, cybersecurity due diligence, and application security reviews.
- Evaluate the design and operating effectiveness of controls across key information security and technology risk domains.
- Translate technical findings into business risk statements for stakeholders and governance forums.
- Escalate issues and recommendations to management, using a risk-based approach, for immediate attention as needed.
- Validate remediation actions and ensure identified control gaps are effectively addressed.
- Establish and enforce effective information security and technology risk management practices across the vendor and application lifecycle.
- Identify applicable laws and regulations and validate adherence to required standards for vendors, business applications, infrastructure, processes, etc.
Due Diligence & Documentation Review
- Review and analyze due diligence artifacts including security questionnaires, SOC reports, penetration test results, policies, standards, and control documentation.
- Support pre-assessment readiness activities and guide vendors and team members through required documentation expectations.
- Create, maintain, and continuously improve ONB’s ISTRM policies, program, procedures, standards, security documentation, regulatory documentation, etc.
- Organize and prepare metrics and dashboards for committee, council, and regulatory reporting.
Collaboration With Internal And External Stakeholders
- Partner with business owners, procurement, legal, and technology teams to support secure vendor and application onboarding and ongoing monitoring.
- Interface directly with third parties to clarify controls, request evidence, and discuss findings.
- Support contract security requirements and risk acceptance decisions.
- Collaborate with security engineering, SOC, and incident response teams to ensure alignment of monitoring and threat detection for vendor risks.
- Partner with the first line of defense and risk offices on risk control assessments and provide guidance on development and enhancement of key controls and risk management.
- Assist in coordination with internal and external parties and assist in evaluation, communication and documentation of issues and incidents.
- Develop, publicize, and support education and training initiatives for all team members.
Key Competencies For Position
- Planning, Organization, and Execution: Self-starter, motivated, able to drive efforts and propose paths forward independently.
- Problem Solving/Decision Making: Ability to define problems, collect data, establish facts, and draw valid conclusions.
- Communication: Ability to present ideas, decisions, and recommendations effectively to all levels of management.
- Technical Knowledge: Possesses the required technical knowledge to perform the role effectively.
Qualifications And Education Requirements
- Bachelor’s degree in Computer Science, Technology, related field, or equivalent work experience required.
- Minimum of 5+ years experience in cybersecurity, information security risk, or third-party/vendor risk management within financial services.
- Minimum of 3+ years of experience leading or supporting a third-party security risk management and application assessment program.
- Detailed understanding of information security frameworks such as ISO27XXX, NIST, CRI, and industry best practices.
- Involvement in adhering to security laws and regulations affecting financial institutions including, but not limited to, GLBA, SOX, HIPAA, FFIEC, etc.
- Extensive knowledge of and experience with information security and technology risk management, control development, and control validation.
- Knowledge of application, infrastructure, cloud, and network security concepts with the ability to evaluate technical architectures and identify security weaknesses in vendor and application integrations.
- Experience in policy, standards, and procedure creation based on selected framework and implementation issues related to regulatory and other requirements.
- Thorough understanding of how to analyze business applications, perform application security assessments, and recommend appropriate security controls.
- Knowledge and experience with an enterprise GRC and IT Service Management system.
- Knowledge of OCC Heightened Standards for risk assessment, incident response, and third-party risk management.
- Achieved or in pursuit of a globally recognized information security certification such as CISSP (Certified Information Systems Security Professional), CISA (Certified Information Systems Auditor), or equivalent preferred.