• Bachelor’s degree in Information Security, Cybersecurity, Information Systems, Computer Science, or Business Administration required; advanced degree (MBA, MS in Cybersecurity or Risk Management) preferred.
• 15+ years of progressive experience in information security, IT risk, regulatory compliance, or audit, including at least 5 years in a BISO or senior, business-Facing a security leadership role.
• Financial services or mortgage industry experience required; non-depository Mortgage lenders experience a significant differentiator.
• Proven track record leading security programs through regulatory examinations, investor audits, and incident response, including board-level reporting.
• Deep knowledge of GLBA Safeguards Rule, FFIEC guidance, state privacy and cybersecurity laws, and investor security requirements (FNMA, FHLMC, Ginnie Mae).
• Working fluency in NIST CSF/800-53, ISO 27001/27002, SOC 2, and FAIR quantitative risk analysis frameworks.
• Demonstrated ability to quantify cyber risk in financial terms and communicate it clearly to executives, Board members, and Legal leadership.
• Strong written and oral communication skills, with experience producing board- quality materials and executive risk briefings.
• CISSP, CISM, or CRISC certification required (at least two); CISA, CGRC, or ISO 27001 Lead Auditor preferred.
• Working knowledge of GRC platforms, SIEM tools, identity and access management, and third-party risk management systems.
• Discretion and sound judgment in handling sensitive consumer financial data and confidential regulatory matters.