Third Party Security Lead

Old National BankEvansville, IN

About The Position

Old National Bank has been serving clients and communities since 1834. With over $70 billion in total assets, we are a regional powerhouse deeply rooted in the communities we serve. As a trusted partner, we thrive on helping our clients achieve their goals and dreams, and we are committed to social responsibility and investing in our communities through volunteering and charitable giving. We continually seek highly motivated and talented individuals as our people are critical to our success. In return, we offer competitive compensation with our salary and incentive program, in addition to medical, dental, and vision insurance. 401K, continuing education opportunities and an employee assistance program are also included in our benefit suite. Old National also offers a variety of Impact Network Groups led by team members who are passionate about driving engagement, creating awareness of diverse backgrounds and experiences, and building inclusion across the organization. We offer a unique opportunity to join a growing, community and client-focused company that is firmly rooted in its core values.

Requirements

  • Bachelor’s degree in Computer Science, Technology, related field, or equivalent work experience required
  • 5+ years experience in cybersecurity, information security risk, or third-party/vendor risk management within financial services.
  • Minimum of 3+ years of experience leading or supporting a third-party security risk management and application assessment program.
  • Detailed understanding of information security frameworks such as ISO27XXX, NIST, CRI, and industry best practices
  • Involvement in adhering to security laws and regulations affecting financial institutions including, but not limited to, GLBA, SOX, HIPAA, FFIEC, etc.
  • Extensive knowledge of and experience with information security and technology risk management, control development, and control validation.
  • Knowledge of application, infrastructure, cloud, and network security concepts with the ability to evaluate technical architectures and identify security weaknesses in vendor and application integrations.
  • Experience in policy, standards, and procedure creation based on selected framework and implementation issues related to regulatory and other requirements.
  • Thorough understanding of how to analyze business applications, perform application security assessments, and recommend appropriate security controls.
  • Knowledge and experience with an enterprise GRC and IT Service Management system.
  • Knowledge of OCC Heightened Standards for risk assessment, incident response, and third-party risk management.

Nice To Haves

  • Achieved or in pursuit of a globally recognized information security certification such as CISSP (Certified Information Systems Security Professional), CISA (Certified Information Systems Auditor), or equivalent preferred.

Responsibilities

  • Execution of Security Risk Assessments and Control Testing: Provide subject matter expertise within ONB’s ISTRM Program by assessing the impact of new vendors, technologies, processes, or partnerships including vendor-hosted solutions, SaaS platforms, and third-party integrations (e.g., APIs, cloud services, and network connectivity), and risk-based decision making.
  • Lead and oversee end-to-end risk assessments, control testing, and risk management review processes to analyze third-party, application, and organization risk and control effectiveness assisting vendors and team members in risk and control identification.
  • Evaluate the design and operating effectiveness of controls across key information security and technology risk domains, including Identity and Access Management (IAM), Security Operations, Network Security, Cryptography and key management, Security Assessment and Testing, and Logging, Monitoring, and Incident Response.
  • Translate technical findings into business risk statements for stakeholders and governance forums.
  • Escalate issues and recommendations to management, using a risk-based approach, for immediate attention as needed.
  • Validate remediation actions and ensure identified control gaps are effectively addressed.
  • Establish and enforce effective information security and technology risk management practices across the vendor and application lifecycle, including onboarding, periodic reviews, and trigger-based reassessments, ensuring consistency, quality, and defensibility of risk evaluations.
  • Identify applicable laws and regulations and validate adherence to required standards for vendors, business applications, infrastructure, processes, etc.
  • Due Diligence & Documentation Review: Review and analyze due diligence artifacts including security questionnaires, SOC reports, penetration test results, policies, standards, and control documentation.
  • Validate completeness and accuracy of vendor and team member responses and supporting evidence.
  • Perform gap analysis against internal standards, regulatory expectations, and industry frameworks (e.g., NIST, CRI, ISO 27001, FFIEC, GLBA).
  • Support pre-assessment readiness activities and guide vendors and team members through required documentation expectations.
  • Support the creation, maintenance, and continuous improvement of ONB’s ISTRM policies, program, procedures, standards, security documentation, regulatory documentation, etc.
  • Provide leadership and effort in the buildout, maintenance, and detailed mapping of global regulatory and industry frameworks to organizational control standards.
  • Organize and prepare metrics and dashboards for committee, council, and regulatory reporting, ensure smooth execution of meetings, present information as requested, and communicate and track outcomes of meetings.
  • Participate in departmental activities and assignments including meetings, updates, planning, reporting, and other responsibilities as needed.
  • Collaborate with internal and external stakeholders: Partner with business owners, procurement, legal, and technology teams to support secure vendor and application onboarding and ongoing monitoring ensuring requirements are incorporated into their program, business processes, and projects.
  • Interface directly with third parties to clarify controls, request evidence, and discuss findings.
  • Support contract security requirements and risk acceptance decisions.
  • Collaborate with security engineering, SOC, and incident response teams to ensure alignment of monitoring and threat detection for vendor risks.
  • Partner with the first line of defense and risk offices on risk control assessments and provide guidance on development and enhancement of key controls and risk management.
  • Assess and respond to information security events and incidents.
  • Assist in coordination with internal and external parties and assist in evaluation, communication and documentation of issues and incidents
  • Support and coordinate internal audits, collaborating with auditors to ensure adherence to standards
  • Develop, publicize, and support education and training initiatives for all team members to raise awareness of information security and risk management requirements.
  • Act as an information security and technology risk advocate to management, team members, and business/process owners.
  • Influence behaviors to reduce risk and foster a strong ISTRM culture throughout the enterprise.

Benefits

  • medical, dental, and vision insurance
  • 401K
  • continuing education opportunities
  • employee assistance program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service