Information Security Manager (INFOSEC)
This position is located in Division of Risk Management Supervision (RMS) and serves as the primary subject matter and technical expert in information security, responsible for managing the development and implementation of RMS's information security and privacy programs. Additional selections may be made from this announcement to fill identical vacancies that arise later.
Develops and implements RMS's security and privacy policies and procedures related to RMS systems and processes. Manages the day-to-day operations of RMS's IT projects with respect to security and privacy requirements and documentation. Oversees RMS's compliance with corporate directives related to information security and privacy protection, and internal security memoranda and practices related to bank supervision. Collaborates with all RMS staff, other FDIC divisions, and external agencies on system access, security, and privacy matters, including sensitive issues with Division-wide implications. Implements business-specific security and privacy practices as directed by OCISO management and maintains communication with OCISO to ensure a continuous feedback loop. Serves as the point of contact for divisional data-loss incidents and data breaches; tracks and reports suspected information security violations to the Security Response Team and coordinates corrective actions with OCISO and RMS staff. Assesses FDIC technology posture, broader IT industry trends, and legislative and oversight actions to recommend program changes or new initiatives within the Division. Develops and delivers presentations and guidance to improve user understanding of security and privacy requirements and promote adherence to corporate and Division policies.