Chief Information Security Officer- Ford Credit Bank

Ford Ford · Auto · Salt Lake City, UT +1 · Ford Credit Services

Chief Information Security & Data Officer (CISDO) for a new de novo bank, responsible for developing and executing enterprise-wide strategies for information security, data governance, and data privacy. This executive role involves leading cybersecurity, data governance, and privacy teams to mitigate risk, protect the bank from cyber security events, and ensure data integrity, availability, and privacy while enabling business leverage of data. The role requires strong knowledge of cybersecurity frameworks, financial services regulations, and experience in regulated environments.

What you'd actually do

  1. Develop and execute an enterprise-wide strategy for information security and data management that aligns with business goals
  2. Serve as a key advisor to the CEO and Board of Directors on cybersecurity risks, data privacy regulations, and emerging technology trends
  3. Establish and maintain the enterprise security vision, strategy, and program to ensure information assets and technologies are adequately protected.
  4. Direct the development and implementation of security policies, standards, and procedures (e.g., NIST, ISO 27001, SOC2)
  5. Partner with Risk, Compliance, and Internal Audit teams to meet regulatory requirements (e.g., FFIEC, PCI DSS, SOX, GDPR where applicable)

Skills

Required

  • Information security strategy
  • Data governance framework
  • Data privacy regulations
  • Cybersecurity frameworks (NIST, ISO 27001, SOC2)
  • Financial services regulations (FFIEC, PCI DSS, SOX, GDPR, CCPA, HIPAA)
  • Incident response planning
  • Threat hunting
  • Data architecture
  • Data quality standards
  • Master data management (MDM)
  • Cloud platforms (AWS, Azure, GCP)
  • Third-party risk management
  • Business continuity
  • Disaster recovery
  • Operational resilience
  • Executive-level communication
  • Strategic thinking

Nice to have

  • Master’s degree
  • Core banking platforms
  • Payment networks
  • Digital banking ecosystems

What the JD emphasized

  • banking or financial services industry
  • regulated environments
  • regulatory requirements
  • data privacy regulations
  • cybersecurity risks