Deputy Chief Information Security Officer - Bank

Mercury Mercury · Fintech · Remote · Information Security

Deputy Chief Information Security Officer (CISO) for a fintech company's bank entity, responsible for the 2LOD Information Security program. This role focuses on building and defending the program to meet regulatory standards (OCC, FFIEC, FDIC, FRB), ensuring examiner readiness, managing policy architecture, BC/DR, audit and assurance, and third-party risk. It requires deep experience in regulated banking environments and direct examiner-facing experience. The role involves team development and leading remediation efforts.

What you'd actually do

  1. Bank-entity 2LOD InfoSec program. Governance, policy, risk, and oversight scoped to the chartered bank.
  2. Examiner posture. OCC, FFIEC, FDIC and FRB examiner inquiries; ownership of the examiner-ready narrative; coordination of the evidence.
  3. FFIEC control remediation. Lead remediation of identified FFIEC IT control deficiencies to charter readiness ahead of the OCC pre-opening examination
  4. Policy architecture. Carry the bank-scoped policy stack (Policy / Standard / Procedure), including ratification cycles, MRCC memos, and board approvals.
  5. BC/DR. Partner with the Chief Risk Officer on bank continuity, resilience, and recovery, including tabletop exercises and full-scale drills.

Skills

Required

  • 8+ years in Information Security
  • 3+ years inside a regulated bank, trust bank, or de novo bank charter effort
  • Deep working knowledge of the FFIEC CAT, the FFIEC IT Examination Handbook, BSA/AML IT supervisory expectations, and the OCC Heightened Standards
  • Direct examiner-facing experience
  • Policy and standards craft
  • Operating discipline
  • 2LOD instinct

Nice to have

  • Prior Deputy CISO or equivalent senior 2LOD role at a national bank, trust bank, or large credit union
  • Charter or de novo bank experience
  • Strong technical baseline
  • CISSP, CISM, or CRISC

What the JD emphasized

  • non-negotiable
  • Deep FFIEC and OCC fluency
  • Direct examiner-facing experience
  • must have