SVP, Security Risk and Assurance
Listed on 2026-01-14
-
IT/Tech
Cybersecurity, IT Consultant, Information Security
Banc of California and Your Career
Banc of California, Inc. (NYSE: BANC) is a bank holding company headquartered in Los Angeles with one wholly‑owned banking subsidiary, Banc of California (the “bank”). Banc of California is one of the nation’s premier relationship‑based business banks focused on providing banking and treasury management services to small, middle‑market, and venture‑backed businesses. The bank offers a broad range of loan and deposit products and services, with full‑service branches throughout California and Denver, Colorado, as well as full‑stack payment processing solutions through Banc Edge.
The bank is committed to its local communities by supporting organizations that provide financial literacy and job training, small business support, affordable housing, and more.
Responsible for overseeing all aspects of information security programs/projects, information security & technology risk assessments, vendor security reviews, and information security reporting. Performs all duties in accordance with the Company’s policies and procedures, all U.S. state and federal laws and regulations, wherein the Company operates.
How You’ll Make a Difference- Acquire and manage the necessary resources, including leadership support, financial resources, and key security personnel, to support information security goals and objectives to reduce overall organizational risk. Forecast ongoing service demands and ensure that security assumptions are reviewed as necessary. Advise senior management on cost/benefit analysis of information security programs, policies, processes, systems, and elements.
- Provide continuous monitoring of security landscape so that possible security threats are identified and actioned appropriately. Supervise or manage the governance, risk and compliance function for protective, preventative or corrective measures when a cybersecurity incident or vulnerability is discovered.
- Collect and maintain data needed to meet system cybersecurity reporting. Advise senior management on risk levels and security posture. Advise appropriate senior leadership on changes affecting the organization's cybersecurity posture.
- Establish enterprise information security architecture (EISA) with the organization’s overall security strategy. Ensure that protection and detection capabilities are acquired or developed using the IS security engineering approach and are consistent with organization‑level cybersecurity architecture. Evaluate and approve development efforts to ensure that baseline security safeguards are appropriately installed.
- Monitor and evaluate the effectiveness of the enterprise's cybersecurity safeguards to ensure that they provide the intended level of protection. Manage threat or target analysis of cyber defence information and production of threat information within the enterprise.
- Define and/or implement policies and procedures to ensure protection of critical infrastructure as appropriate. Continuously validate the organization against policies/guidelines/procedures/regulations/laws to ensure compliance.
- Work closely with client executives and management teams to understand their businesses and assist in identifying and managing financial and operational risks within their business systems to ensure technology risks are managed. Collaborate with stakeholders to establish the enterprise continuity of operations program, strategy, and mission assurance. Ensure that cybersecurity requirements are integrated into the continuity planning for that system and/or organization(s).
Participate in the development or modification of the computer environment cybersecurity program plans and requirements. - Review business processes and controls against industry frameworks, identifying gaps in design and execution, and communicating issues and recommendations to business clients. Oversee the development of business continuity programs and the execution of internal control assessments in the areas of:
- IT strategy and governance
- IT operations, business continuity and disaster recovery
- Cybersecurity
- Third party risk
- ITGC and application controls
- SOC reporting
- Regulatory and compliance…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).