Deputy Chief Information Security Officer - Bank
Core
Operating second to the CISO to own the bank-entity scope of Mercury's 2LOD Information Security program, ensuring examiner-ready posture and coherent policy architecture.
Role type
Deputy Chief Information Security Officer (Bank Entity)
Builds
Bank-entity 2LOD InfoSec program, examiner-ready narrative, FFIEC control remediation, policy stack, BC/DR plans, audit evidence, third-party risk controls.
Domain
Banking / Financial Services / Regulatory Compliance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Information Security program management, FFIEC and OCC regulatory fluency, examiner-facing defense, policy and standards drafting, business continuity and disaster recovery, audit and assurance management, third-party risk management, GRC team leadership.
Preferred skills
Deputy CISO experience, de novo bank charter experience, technical architecture review capability, CISSP, CISM, or CRISC certification.
Technologies
FFIEC CAT, FFIEC IT Examination Handbook, BSA/AML frameworks, OCC Heightened Standards.
Responsibilities
Own governance, policy, risk, and oversight for the chartered bank; coordinate evidence for OCC, FFIEC, FDIC, and FRB examiner inquiries; lead remediation of FFIEC IT control deficiencies; draft and ratify board-level policies and standards; partner on bank continuity and resilience drills; manage relationships with internal and external auditors; coach and grow the GRC sub-team.
Seniority
Senior, hands-on IC with executive oversight