Work with team members to enhance Standards by evaluating various industry frameworks and identifying opportunities for enhancements to foster continuous security improvements in the interest of protecting the confidentiality of member and employee information.
Communicate and socialize proposed updates with stakeholders from across NFCU to ensure that updates to the Standards are balanced with current or proposed operational practices and needs.
Research and provide recommendations for the selection of security controls and assist with the tailoring of those controls to accurately reflect NFCU’s needs.
Support the migration between the old and new technology platforms (e.g., SharePoint Online) and assist team with documentation management while maintaining confidentiality and accessibility.
Assist in short and long-term strategic planning and implementation for various team initiatives.
Proactively research areas of emerging technologies and risks applicable to NFCU and develop potential solutions and recommendations in the interest of addressing the associated risks.
Requirements
Total Professional and Educational Experience 4+ years of which Information Technology/Security is 1+ years.
Excellent communication skills
Self-starter / self-directed
Understanding of general Information Technology concepts
Experience with business process definition and optimization
Strong analytical skills with experience creating reports and analyses
High level proficiency with Microsoft Office
Advanced verbal, written, interpersonal, and presentation skills to communicate clearly and concisely technical and non-technical information to all levels of management
Advanced skill building effective relationships with all levels of staff, management, stakeholders, and vendors, through rapport, trust, diplomacy and tact
Advanced organizational, planning and time management skills
Advanced skill developing and implementing programs in a leadership role
Effective skill to influence, negotiate and persuade to reach agreeable exchange and positive outcomes
Advanced skills in taking initiatives and using good judgment to make sound decisions
Ability to work collaboratively within a team environment
Curiosity and eagerness to learn new technologies and security practices
Coursework, projects, and/or work experience related to security risk and controls management and/or cybersecurity frameworks (such as NIST, FedRAMP, PCI DSS, HIPAA, ISO, etc.)
Knowledge of Federal banking safety and soundness regulations and familiarity of examination approaches from regulatory bodies such as the: FFIEC, NCUA, OCC, FHFA and the CFPB.
Knowledge of industry leading risk and security program management frameworks (such as COSO, COBIT, NIST CSF, ITIL)
Knowledge of data protection and/or privacy frameworks (e.g., GDPR, CCPA, NIST Privacy Framework)
Experience in the development and/or implementation of security risks and controls management frameworks
Experience with information technology systems, project processes, and application development (e.g., SharePoint Online)