Chief Information Security Officer

Origin BankRuston, LA
Hybrid

About The Position

The Chief Information Security Officer (CISO) is a senior leadership role responsible for the development, implementation, and ongoing oversight of the Bank’s enterprise information security, cybersecurity, and data protection program. This role will support the Bank’s ability to protect the confidentiality, integrity, and availability of information assets while aligning cybersecurity practices with business objectives, regulatory expectations, and the Bank’s risk appetite framework. The CISO operates with appropriate independence within the Risk organization and provides objective oversight, escalation of cybersecurity risks, and subject matter expertise to executive leadership, Board committees, and business stakeholders. The role is accountable for maintaining a sound control environment, effective risk management processes, and regulatory readiness.

Requirements

  • Senior leadership role
  • Responsible for development, implementation, and ongoing oversight of enterprise information security, cybersecurity, and data protection program.
  • Supports protection of confidentiality, integrity, and availability of information assets.
  • Aligns cybersecurity practices with business objectives, regulatory expectations, and risk appetite framework.
  • Operates with appropriate independence within the Risk organization.
  • Provides objective oversight, escalation of cybersecurity risks, and subject matter expertise to executive leadership, Board committees, and business stakeholders.
  • Accountable for maintaining a sound control environment, effective risk management processes, and regulatory readiness.
  • Experience in developing, implementing, and managing enterprise information security programs.
  • Experience establishing and maintaining information security policies, standards, and procedures.
  • Experience reporting on cybersecurity risks, KRIs, program performance, and control effectiveness.
  • Experience supporting Board and Risk Committee reporting.
  • Experience promoting enterprise-wide security awareness.
  • Experience overseeing cybersecurity controls and monitoring processes.
  • Experience supporting control assurance activities, including validation, testing, vulnerability management, and remediation.
  • Experience ensuring timely identification, escalation, and remediation of control issues.
  • Experience partnering with Internal Audit and Risk teams.
  • Experience overseeing security operations, including monitoring, detection, and response.
  • Experience directing threat intelligence, vulnerability management, and penetration testing.
  • Experience implementing core security controls (identity and access management, data protection, endpoint/network security).
  • Experience improving detection and response capabilities.
  • Experience maintaining cyber incident response frameworks and procedures.
  • Experience coordinating incident response with Technology, Risk, Legal, and leadership.
  • Experience conducting post-incident reviews and supporting remediation.
  • Experience facilitating incident tabletop exercises.
  • Experience aligning incident response with business continuity and disaster recovery.
  • Experience supporting third-party cybersecurity risk management programs.
  • Experience with vendor due diligence, onboarding, monitoring, and remediation.
  • Experience providing risk assessments for third-party engagements.
  • Experience supporting data protection strategies, including classification, handling standards, and protection of sensitive information.
  • Experience coordinating with Legal, Compliance, and Risk on privacy requirements.
  • Experience monitoring controls for unauthorized data access or loss.
  • Experience partnering with Technology teams on security considerations in system design.
  • Experience providing input on risk assessments for cloud, digital transformation, and emerging technologies.
  • Experience promoting secure development and architecture practices.
  • Experience supporting regulatory examinations and audits.
  • Experience assisting with responses to regulatory and audit inquiries.
  • Experience tracking and supporting remediation of findings.
  • Experience maintaining compliance documentation.
  • Experience advising Risk leadership and business units on cybersecurity.
  • Experience building relationships with internal stakeholders, auditors, and external partners.
  • Experience leading and developing Information Security teams.
  • Experience promoting a collaborative, risk-aware culture.

Nice To Haves

  • Preferred work location within one of our Louisiana, Texas, Alabama, Florida, or Mississippi markets.

Responsibilities

  • Develops, implements, and manages the Bank’s enterprise information security program in alignment with strategic priorities and risk appetite.
  • Establishes and maintains information security policies, standards, and procedures consistent with regulatory guidance and industry frameworks.
  • Provides regular reporting to the Chief Risk Officer and senior leadership on cybersecurity risks, emerging threat landscape, key risk indicators (KRIs), program performance, and control effectiveness and remediation status.
  • Supports Board and Risk Committee reporting by preparing materials and analysis as needed.
  • Promotes enterprise-wide security awareness and accountability.
  • Oversees the design and operation of key cybersecurity controls and monitoring processes.
  • Supports control assurance activities, including control validation and testing coordination, and vulnerability management and remediation tracking.
  • Ensures control issues are identified, escalated, and remediated in a timely manner.
  • Partners with Internal Audit and Risk teams to support independent testing and validation efforts.
  • Oversees day-to-day security operations, including monitoring, detection, and response processes.
  • Directs threat intelligence, vulnerability management, and penetration testing activities.
  • Ensures effective implementation of core security controls, including identity and access management, data protection and encryption, and endpoint and network security.
  • Supports continuous improvement of detection and response capabilities.
  • Maintains the Bank’s cyber incident response framework and supporting procedures.
  • Coordinates response to cybersecurity incidents in partnership with Technology, Risk, Legal, and leadership teams.
  • Conducts post-incident reviews and supports remediation tracking.
  • Facilitates cyber incident tabletop exercises and scenario testing with key stakeholders.
  • Aligns cybersecurity incident response with broader business continuity and disaster recovery plans.
  • Supports the Bank’s third-party cybersecurity risk management program across the vendor lifecycle, including due diligence, onboarding, ongoing monitoring, and issue identification and remediation.
  • Works with Vendor Management, Risk, and Legal to ensure third-party security expectations are met.
  • Provides risk assessments and recommendations for third-party engagements.
  • Supports the Bank’s data protection strategy, including data classification, handling standards, and protection of sensitive and confidential information.
  • Coordinates with Legal, Compliance, and Risk to ensure alignment with privacy requirements.
  • Monitors controls designed to prevent unauthorized data access or loss.
  • Partners with Technology teams to ensure security considerations are incorporated into system design and implementation.
  • Provides input into risk assessments for cloud environments, digital transformation initiatives, and emerging technologies (e.g., AI, APIs, fintech integrations).
  • Promotes consistent application of secure development and architecture practices.
  • Supports regulatory examinations and audits related to cybersecurity and information security.
  • Assists in the preparation and coordination of responses to regulatory and audit inquiries.
  • Tracks and supports remediation of findings, including documentation and evidence collection.
  • Maintains documentation to demonstrate compliance with applicable regulatory expectations.
  • Serves as a key advisor to Risk leadership and business units on cybersecurity matters.
  • Builds relationships with internal stakeholders, auditors, and external partners.
  • Leads and develops the Information Security team, including talent development and performance management.
  • Promotes a collaborative, risk-aware culture across the organization.

Benefits

  • Competitive total rewards package
  • Generous benefits
  • Compensation tailored to skills, experience, and education
  • Dream Manager program
  • One-on-one guidance from a nationally certified health and wellness coach
  • Free access to certified financial professionals
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service