hirly

THE DIME BANK

Information Security Officer

Honesdale, PA

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at THE DIME BANK first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.4M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Seniority
Mid level
Country
US
Work mode
On-site / unstated
First seen by hirly
26 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

Description

The Information Security Officer (ISO) shall be responsible for developing, implementing, and managing the Bank's Information Security Program and policies to ensure the confidentiality, integrity, and availability of bank information assets. ISO serves as the primary leader for cybersecurity governance, risk management, regulatory compliance, incident response, and security awareness initiatives. This position ensures compliance with applicable banking regulations, including FFIEC guidance, GLBA, Pennsylvania Department of Banking, Interagency Guidelines Establishing Information Security Standards, state regulations, and cybersecurity best practices.

As a key member of the Bank's risk management framework, the ISO provides independent oversight and possesses independent authority for information security risk reporting to executive management and the Board of Directors.

Essential Duties

  • Develop and maintain the bank’s information security strategy, risk tolerance, policies and information security exception management for alignment with business objectives.
  • Conduct risk assessments and report findings to senior management and the board.
  • Ensure alignment of security controls with business objectives and regulatory requirements.
  • Monitor third-party vendor security practices.
  • Provide employee and board training and awareness programs.
  • Establish and maintain the Bank’s cybersecurity strategic roadmap.
  • Provide cyber risk appetite and operational resilience reporting
  • Ensure the Bank’s Information Security Program aligns with Information security frameworks (NIST Cybersecurity Framework (CSF 2.0), CIS Critical Security Controls (CIS Controls), and ISO/IEC 27001)

Ancillary Duties

  • Present cybersecurity risk assessments, program updates, significant cybersecurity incident reporting, third party cyber risks, emerging threats, remediation efforts and strategic information security initiatives to executive management and the Board.
  • Maintain Information Security compliance standards (GLBA Safeguards Rule compliance, customer information protection, security awareness program effectiveness, policy exception management, annual Information Security Program review.
  • Develop mitigation plans for identified vulnerabilities and threats.
  • Develop and oversee security control testing and validation efforts, for existing Information Security Technology, upgrades and enhancements.
  • Responsible for leading the bank’s information security risk assessments (ISRA, GLBA, Privacy)
  • Lead the Bank’s Incident Response Program. Coordinate response activities during security incidents. Ensure proper breach notification and regulatory reporting procedures are followed.
  • Conduct post-incident reviews and lessons-learned sessions. Maintain cyber resilience and recovery procedures.
  • Participate in vendor due diligence reviews. Assess SOC reports, penetration test results, and security questionnaires. Monitor vendor cybersecurity performance and remediation efforts. Support contract language related to cybersecurity requirements.
  • Working with the Information Technology Management Team, oversee security monitoring and threat detection activities.
  • Review and manage cybersecurity alerts and incident investigations.
  • Responsible for reviewing key performance indicators for the information security program. These include but are not limited to the following:
  • Completion of annual risk assessments
  • Reduction of critical vulnerabilities
  • Regulatory examination results
  • Audit finding remediation timelines
  • Employee phishing test performance
  • Third-party risk assessment completion rates
  • Incident detection and response metrics
  • Security awareness training completion rates
  • Compliance with Board-approved security objectives
  • Develop and maintain cybersecurity metrics, key risk indicators (KRIs), and executive dashboards for Board reporting.
  • Responsible for ensuring the Bank’s Identity and Access Management (IAM) processes use industry best practices and risk management controls.
  • Ensure appropriate vulnerability management processes are maintained.
  • Review application deployment and change management processes to ensure security standards are adhered to.
  • Maintain threat intelligence and cyber threat monitoring processes, including participation in FS-ISAC and other financial sector information-sharing organizations.
  • Direct penetration testing and independent security assessments.
  • Maintain and oversee cybersecurity supply-chain risk management practices for critical vendors, fintech partners, cloud providers, and service providers.
  • Ensure standards are documented and adhered to for data encryption at rest and in motion.
  • Responsible for creating and maintaining the Bank’s data classification standards, data retention requirements, secure disposal procedures for hardware and software, and maintaining the bank’s sensitive data inventory, and ensure hardware, software and information asset inventories are in place and updated.
  • Ensure Password policy standards are documented and adhered to for all systems, including multi-factor authentication for all software with customer or sensitive bank information.
  • Ensure compliance with federal incident notification requirements, including 36-hour notification requirements for qualifying computer-security incidents.
  • Collaborate as a member of the Business Continuity Planning (BCP) Committee with business continuity team members to ensure cyber resilience is developed in all departmental BCP plans.
  • Coordinate and conduct annual cyber recovery testing, ransomware recovery exercises and all relevant tabletop exercises.
  • Chair or participate in the Information Security Committee.
  • Lead security-related projects and initiatives. Including Conducting periodic NIST CSF information security maturity assessments, gap analyses, and program effectiveness reviews.
  • Responsible for coordinating all regulatory examinations, independent audits, and security assessments related to information security and cybersecurity and for ensuring management responses and corrective action plans are completed in a timely manner.
  • Perform tasks which are supportive in nature of the essential functions of the job, but which may be altered or re-designed depending upon individual circumstances.

Requirements

Education/Training: A bachelor’s degree in information security, Cybersecurity, Information Technology, Risk Management, Computer Science, or related field required. Master's degree preferred.

Skill(s): Proficient reading, writing, and grammar skills; proficient interpersonal relations and communicative skills; proficient information technology skills, including information security and applicable regulations; visual and auditory skills; valid driver's license.

Experience: A minimum of five (5) years of information security, information technology risk management, cybersecurity, audit, or related experience, including at least three (3) years in a leadership role. Relevant security certifications are preferred (CISSP, CISM, CCSP) but not required. Banking or regulated financial institution experience strongly preferred

Original posting on THE DIME BANK's site ↗

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job