Chief Information Security Officer (CISO) / IT ManagerLocation: Near Schoharie, NY Salary Range: $95,000 – $100,000 annually Employment Type: Full-TimeLead Information Security, Technology Operations & Regulatory ComplianceOur respected financial client in the Capital Region is seeking an experienced Chief Information Security Officer (CISO) / IT Manager to lead its information security program, technology operations, cybersecurity initiatives, regulatory compliance efforts, and business continuity planning.This is a highly visible leadership position responsible for safeguarding critical information systems, ensuring compliance with regulatory requirements, and supporting the organization's long-term technology strategy. The successful candidate will serve as a trusted advisor to executive leadership and the Board while overseeing the organization's cybersecurity posture and IT governance framework.Position OverviewThe CISO / IT Manager will oversee the development, implementation, and ongoing management of the organization's information security and technology programs. This role is responsible for coordinating security efforts across departments, managing cybersecurity risks, supporting regulatory examinations, overseeing disaster recovery planning, and ensuring that technology infrastructure remains secure, reliable, and compliant.This position combines strategic leadership, risk management, regulatory compliance, and hands-on technology oversight.Key ResponsibilitiesInformation Security LeadershipLead and manage the organization's Information Security ProgramDevelop, implement, and maintain information security policies, procedures, and standardsServe as the organization's primary information security advisorEvaluate emerging cybersecurity threats and recommend appropriate safeguardsCoordinate information security initiatives across all business unitsProvide regular updates and reporting to executive leadership and the Board of DirectorsCybersecurity & Risk ManagementConduct annual information security risk assessmentsEvaluate cybersecurity risks and implement mitigation strategiesMonitor access controls and user permissions across systemsOversee vulnerability management, security monitoring, and remediation effortsReview firewall reports, antivirus reporting, network scans, and software update complianceEnsure appropriate security controls are maintained throughout the organizationRegulatory Compliance & AuditsManage compliance with: NYS Department of Financial Services (NYDFS) Cybersecurity Regulations, FFIEC Cybersecurity Assessment requirements, GLBA Information Security requirements, NIST and COBIT cybersecurity frameworks, PCI compliance standardsCoordinate internal and external cybersecurity auditsPrepare for and support regulatory examinations and assessmentsMonitor evolving regulatory requirements and implement necessary changesSecurity Awareness & TrainingDevelop and oversee cybersecurity awareness programsProvide security training for employees and leadershipDeliver cybersecurity education and awareness initiativesEnsure users understand security policies and best practicesIncident Response & Security OperationsDevelop and maintain incident response plans and proceduresCoordinate investigation and response efforts related to security incidentsServe as a key member of incident response and emergency management teamsReview security events and oversee corrective actionsCoordinate response activities with internal stakeholders and external partnersBusiness Continuity & Disaster RecoveryLead organization-wide disaster recovery and business continuity planningCoordinate testing and validation of critical technology systemsEnsure recovery plans remain current and effectiveOversee testing of critical infrastructure, applications, and vendor recovery capabilitiesSupport pandemic planning and operational continuity initiativesVendor Risk ManagementConduct vendor due diligence and cybersecurity reviewsReview SOC reports, SSAE reports, and other third-party security assessmentsEvaluate cybersecurity insurance coverage and risk management practicesMonitor vendor performance and compliance requirementsIT Management & Strategic PlanningParticipate in technology planning and long-term strategic initiativesManage technology-related contracts and vendor relationshipsOversee hardware and software inventory managementMaintain software licensing and technology asset recordsSupport budgeting and technology investment decisionsTechnical Operations SupportProvide backup support for IT infrastructure and end-user support functions as neededAssist with troubleshooting involving: Active Directory, Firewalls, Network infrastructure, Windows environments, Core business systems, Workstations and end-user technologies