
Open role
Director of Cybersecurity & Resilience
South Shore Bank

South Shore Bank
Posted 2026-09-14
About the role
Job Type Full-time Description SUMMARY Reporting to the Chief Information Officer, the Director of Cybersecurity & Resilience is responsible for leading the organization's cybersecurity and information technology risk management functions, including thirty-party risk and business continuity management. The Director establishes, operates, and continuously improves a risk-based cybersecurity program that protects information assets, supports regulatory compliance, strengthens cyber resilience, and provides management and governance committees with clear visibility into cybersecurity and IT risk. ESSENTIAL DUTIES AND RESPONSIBILITIES Accountable for developing, maintaining, and executing the organization's cybersecurity strategy, program, policies, standards, and roadmap in alignment with organizational objectives, risk appetite, applicable laws and regulations, and recognized frameworks such as the NIST Cybersecurity Framework, NIST 800-53, ISO 27001/2, and other financial industry guidance, where applicable. Accountable for the effective delivery of Cybersecurity Operations (CyberOps), including security monitoring, detection, investigation, escalation, containment, recovery, and the secure configuration, hardening, testing, deployment, and maintenance of cybersecurity technology platforms. Lead the IT and cybersecurity risk management process, including risk identification, assessment, treatment, acceptance, monitoring, and reporting. Maintain current risk assessments and risk registers, establish action plans, and escalate exposures that exceed approved risk thresholds. Maintain a risk-based vulnerability and threat management program covering internal and external scanning, penetration testing, configuration weaknesses, threat intelligence, remediation validation, exception management, and timely escalation of overdue or high-risk findings. Serve as a leader of the organization's incident response team for cybersecurity events and suspected breaches of confidential information. Maintain and test cybersecurity incident response plans, playbooks, communication protocols, evidence-handling practices, and escalation procedures; coordinate lessons learned and corrective actions. Oversee cybersecurity requirements for identity and access management, including privileged access, multifactor authentication, periodic access reviews, segregation of duties, joiner-mover-leaver controls, service accounts, and timely remediation of inappropriate access. Establish cybersecurity architecture, secure configuration, and system hardening requirements. Identify and measure cybersecurity and IT risk before material technology changes, new products, system implementations, cloud adoption, integrations, or significant investments are approved or deployed. Accountable for managing and maintaining the third-party risk management lifecycle, including due diligence, risk assessment, control evaluation, contractual security requirements, ongoing monitoring, issue management, incident coordination, and termination or transition risk. Accountable for managing and maintaining the business continuity management function including technology resilience, business continuity, disaster recovery, backup security, and recovery testing. Ensure cyber scenarios, including destructive attacks and prolonged technology outages, are incorporated into exercises and remediation plans. Oversee technical and administrative safeguards for sensitive and non-public information, including encryption, data loss prevention, secure transmission, logging, monitoring, and other information protection controls. Coordinate security requirements with privacy, legal, compliance, and business stakeholders. Analyze and monitor cybersecurity and IT risk metrics, key risk indicators, key performance indicators, control effectiveness measures, incidents, vulnerabilities, exceptions, and remediation status. Identify trends and provide clear, decision-useful reporting to Senior Management and appropriate governance committees. Coordinate cybersecurity and IT risk support for internal audits, external audits, regulatory examinations, independent assessments, penetration tests, and control reviews. Recommend and initiate corrective actions, track findings to validated closure, and maintain supporting evidence. Assist in the coordination of the cybersecurity awareness and education program, including role-based training, phishing education and testing, targeted communications, and reporting. Promote prompt reporting of suspicious activity and reinforce employee responsibilities for safeguarding information. Maintain accurate and current cybersecurity and IT risk policies, standards, procedures, control documentation, diagrams, inventories, risk records, exceptions, testing evidence, and management reports. Develop and manage the cybersecurity budget, resource plan, and investment priorities based on risk, regulatory expectations, control effectiveness, technology lifecycle considerations, and the cybersecurity strategy. Participate on the organization's Technology Committee and other governance committees as required. Present material cybersecurity and IT risks, incidents, control gaps, investment needs, and remediation progress in clear business terms. Provide supervision and support to assigned cybersecurity personnel and oversee cybersecurity service providers. Establish responsibilities, performance expectations, escalation requirements, cross-training, succession coverage, and accountability for deliverables. Maintain awareness of changes in cyber threats, attack techniques, regulatory expectations, and security practices. Recommend proportionate improvements to cybersecurity controls, processes, staffing, and technologies based on risk and lessons learned. Complete all internal Company training as assigned and required. Adhere to the Company’s privacy and data security policies including but not limited to safeguarding of sensitive information and complying with relevant regulations to protect non-public information. Exhibit the ability and desire to embrace and enhance the Company culture. Consider this description to be the foundation of your job, not its boundaries. Expect to participate in internal and external training sessions and activities not described here which enhance the quality of service to the client. SUPERVISORY RESPONSIBILITIES Directly manages assigned employees in the Cybersecurity and Business Resilience functions and oversees cybersecurity and business resilience service providers. Carries out supervisory responsibilities in accordance with the organization's policies and applicable laws. Responsibilities include interviewing, hiring, and training employees; planning, assigning, and directing work; appraising performance; rewarding and disciplining employees; addressing complaints; and resolving problems. Requirements QUALIFICATIONS To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. EDUCATION and/or EXPERIENCE Bachelor's Degree from a four-year college or university in cybersecurity, information systems, computer science, risk management, or a related field, or an equivalent combination of education and directly relevant experience. Ten or more years of progressively responsible cybersecurity, information security, or IT risk experience, including experience leading cybersecurity functions in a complex, regulated environment. Five or more years of financial services experience and knowledge of banking products, cybersecurity risks, regulatory expectations, and terminology preferred, but not required. Demonstrated experience with cybersecurity governance, risk assessments, security operations, vulnerability management, incident response, identity and access management, third-party cybersecurity risk, data protection, and cyber resilience. Proven successful experience as a leader of employees and cybersecurity service providers, with the ability to establish accountability and produce results. Experience developing cybersecurity budgets, resource plans, metrics, and risk-based investment priorities. Ability to communicate cybersecurity and IT risk matters effectively to technical teams, business leaders, Senior Management, auditors, examiners, and governance committees. Strong analytical, organizational, planning, problem-solving, influencing, and change management skills. Relevant professional certification, such as CISSP, CISM, CRISC, or equivalent, preferred. Competent level of proficiency with Microsoft Office and cybersecurity, risk management, reporting, and productivity tools necessary to perform the role. SKILLS Basic knowledge of the banking and financial services industry including federal laws and regulations Willingness to gain new knowledge and technical skills. Intermediate typing skills to meet the production needs of the position. Intermediate math skills: the ability to calculate interest, commissions, proportions, and percentages; balance accounts; add, subtract, multiply, and divide into all units of measure, using whole numbers, common fractions, and decimals; locate routine mathematical errors; compute rate, ratio, and percent, including the drafting and interpretation of bar graphs. Exceptional verbal, written, and interpersonal communication skills with the ability to apply common sense to carry out instructions and instruct others, train personnel, read, analyze, and interpret documents and professional journals, understand procedures, write reports, correspondence, and procedures, speak clearly to customers and employees. ADDITIONAL JOB REQUIREMENTS / ADA CONSIDERATIONS The employee must be able to communicate effectively with internal and external stakeholders, including but not limited to, clients, prospects, employees, management, and external partners in person, by phone, virtually, and in writing; read, interpret, and prepare business, banking, regulatory, proposal, contract, and client documentation as applicable to the role; and apply business- and financial-related concepts, analysis, or calculations as appropriate to the role. Work is primarily performed in a professional office environment and may include client locations, meetings, presentations, conferences, association events, and other business development settings. The role requires regular use of a computer, phone, virtual meeting tools, and standard office technology; the ability to review screens and documents; occasional travel within the market area; and occasional lifting or moving of materials up to 10 pounds. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions, consistent with applicable law. KEY POINTS For those seeking to deliver the latest financial solutions rooted in trustworthy, high-quality service, Charlesbridge, a mutual bank holding company, provides operational support, resources, legacy, and innovative thinking to financial institutions so they can deliver a suite of flexible, personalized solutions designed to meet the evolving needs of our clients and our communities. Our local roots, dedication to the communities we serve, loyalty to our people, and commitment to excellence ensure that we remain a trusted partner in an ever-evolving financial journey, today and tomorrow. While our employees are committed to helping our clients, we are committed to our employees. To support our employees, we offer a competitive benefit package with Medical, Dental, Vision, Flexible Spending, Tuition Reimbursement, Childcare Subsidy, Retirement, Life Insurance, and many other benefits. Charlesbridge is committed to providing equal opportunity for all employees and applicants without regard to race, color, religion, gender, sexual orientation, age, marital status, national origin, physical or mental disability, veteran or disability status, gender identity, or expression, citizenship, genetic information, ancestral origin, military status, pregnancy, childbirth, and or conditions relating to pregnancy or any other related medical conditions or any other status protected by Federal, State or local laws. Here at Charlesbridge, we strive to foster a culture where every voice is valued and where employees have a sense of belonging and connection with each other. We are dedicated to creating a work environment that understands, supports, and welcomes diverse perspectives and backgrounds. Together, we will create an inclusive and culturally competent and supportive environment where employees model behavior that enriches both Banks and the communities we support. PAY RANGE DISCLOSURE The pay range for this position is $166,500 to $199,800 per year and is the lowest to highest salary Charlesbridge in good faith believe we would pay for this role at the time of this posting. The Company may ultimately pay more or less than the posted range, and the range may be modified in the future. An employee’s pay position within the salary range will be based on several factors including, but not limited to, relevant education, qualifications, certifications, experience, sales or revenue-based metrics, and business or organizational needs and affordability. EOE/F/M/Vet/Disabled Salary Description $166,500 to $199,800 per year
AI apply unlocks in the Sawell app
Prefer desktop? Sign in on web

