We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

VP, Information Security Officer

Workers Credit Union
188113.00 To 250817.00 (USD) Annually
paid time off, paid holidays, tuition reimbursement, 401(k), remote work
United States, Massachusetts, Littleton
Sep 14, 2026

Job Title: VP, Information Security Officer

Department or Branch: Risk Management

Working at Workers Credit Union

At Workers Credit Union, everything starts with a simple but powerful purpose: We enable financial prosperity through values-driven solutions because everyone deserves a future they can believe in.

For more than a century, we've been a trusted partner in helping people make confident financial decisions and build stronger futures. Today, as a $2.5B organization serving over 120,000 members, we continue to evolve, thoughtfully blending personal connection with modern capabilities to better support our members in the moments that matter most.

We call this the Workers Way. It shapes how we show up every day, with personalized guidance, practical solutions, and a deep commitment to doing what's right. Just as importantly, it defines how we work together. We choose purpose over ego. We communicate directly with respect. We dare to grow. We do the right thing, always. And we win together, because meaningful results are built through shared success.

As we look ahead, we're building on a strong foundation and continuing to evolve how we operate and deliver impact, simplifying experiences and strengthening capabilities. We have big plans for the future, and we hope you'll be part of what comes next.

Why this Role Matters

The VP, Information Security Officer is responsible for the development, implementation, maintenance, and oversight of Workers Credit Union's enterprise Information Security Risk Management Program. This role serves as the Credit Union's Information Security Officer and is responsible for the design and implementation of the credit union's information security strategy and program. The role provides governance, risk oversight, regulatory alignment, incident response leadership, security awareness, and executive reporting to help protect member information, confidential business information, technology assets, and the overall security posture of the organization.

What You'll Contribute

Information Security Program Governance and Oversight

  • Serve as the Credit Union's designated Information Security Officer and primary leader for the enterprise Information Security Risk Management Program.
  • Develop, maintain, and continuously improve information security policies, standards, procedures, controls, and governance practices.
  • Provide strategic oversight of the Credit Union's information security and physical security risk posture, including alignment with enterprise risk appetite and regulatory expectations.
  • Monitor emerging cybersecurity threats, regulatory guidance, industry trends, and supervisory expectations impacting the Credit Union.
  • Provide governance oversight for the secure and responsible use of emerging technologies, including artificial intelligence, by ensuring risks are identified, escalated, and reported appropriately.
  • Ensure security considerations are embedded into new products, services, technology changes, vendor relationships, and enterprise initiatives.
  • Partner with Risk, Compliance, Legal, Information Technology, Enterprise Data, business leaders, and external security partners to support a coordinated and risk-based security program.

Risk Assessment, Regulatory Readiness, and Reporting

  • Lead or coordinate information security risk assessments, maturity assessments, control testing, and remediation tracking.
  • Ensure appropriate review and reporting of security-related assessments, including NCUA, FFIEC Cybersecurity Assessment Tool, GLBA Safeguards, governance, risk and compliance assessments, new product reviews, vendor reviews, and related examinations.
  • Develop meaningful metrics and reporting to assess information security risk exposure, control effectiveness, remediation progress, and program maturity.
  • Provide regular updates to executive leadership, management committees, the Risk Oversight Committee, and the Board of Directors on the status of the Information Security Program.
  • Serve as the primary liaison with internal audit, external auditors, regulatory examiners, and third-party assessors for information security reviews and examinations.
  • Maintain documentation, evidence, and reporting needed to support audits, regulatory exams, incident reviews, and management oversight.

Security Operations Coordination and Control Oversight

  • Coordinate with Information Technology and business units to monitor policy compliance, remediate vulnerabilities, address control gaps, and strengthen secure operating practices.
  • Provide oversight of identity and access control governance, including privileged access, administrative access, access review processes, and separation of duties.
  • Oversee phishing defense, security awareness, vulnerability management coordination, incident escalation, and related security operations processes.
  • Participate in technology governance processes, including change management and risk review forums, to evaluate potential security impacts.
  • Oversee coordination with managed security service providers, cybersecurity vendors, and external information security partners to ensure effective delivery, accountability, and continuous improvement.
  • Support the alignment of security controls across cloud, identity, endpoint, data, network, vendor, and physical security domains.

Incident Response, Business Resilience, and Enterprise Risk Alignment

  • Lead or support cyber incident response activities in coordination with the Chief Finance and Risk Officer, Information Technology, Legal, Compliance, BSA, business leaders, and external partners.
  • Maintain and improve the cyber incident response plan, playbooks, escalation procedures, communication protocols, and evidence collection practices.
  • Ensure timely and appropriate escalation, reporting, investigation, and regulatory or member notification support for security incidents.
  • Coordinate post-incident reviews and ensure corrective actions are tracked and completed.
  • Support alignment between the Information Security Program and related enterprise programs, including business continuity, disaster recovery, privacy, fraud prevention, third-party risk management, physical security, and enterprise risk management.
  • Collaborate with Fraud and Vendor Risk teams to ensure security controls and risk management practices support broader organizational resilience.

Security Awareness, Culture, and Leadership

  • Oversee the information security awareness and training program to ensure employees understand their role in protecting member, employee, and Credit Union information.
  • Promote a security-aware culture that balances risk management, business enablement, member experience, and operational practicality.
  • Build trusted relationships with senior leaders, business units, technology teams, auditors, regulators, and external partners.
  • Lead, coach, and develop Information Security team members and related working groups to strengthen capability, accountability, and program maturity.
  • Communicate complex security and risk matters clearly to technical and non-technical audiences.
  • Demonstrate sound judgment, discretion, and professionalism when handling sensitive security, member, employee, and organizational information.

Other Duties

  • Performs additional duties or responsibilities as required, requested, or deemed appropriate.
  • May be asked to provide coverage in other WCU departments, functions, or business units as needed.
  • Complies with all WCU policies and procedures.
  • Contributes to departmental and organizational projects and initiatives as assigned.
  • Maintains the confidentiality of all member and credit union information at all times.
  • Regularly demonstrate behaviors as defined by the credit union's core values: Choose Purpose Over Ego, Be Direct With Respect, Dare to Grow, Do the Right Thing Always, and Win Together.

What You'll Bring

  • Deep knowledge of information security governance, cybersecurity risk management, regulatory compliance, privacy, third-party risk, business continuity, disaster recovery, and incident response.
  • Strong understanding of regulatory expectations applicable to financial institutions, including NCUA, FFIEC, GLBA Safeguards, privacy, breach notification, and related supervisory guidance.
  • Ability to design, mature, and oversee enterprise-wide security programs that are practical, risk-based, measurable, and aligned with business objectives.
  • Demonstrated ability to communicate complex security, risk, regulatory, and technology matters clearly, concisely, and effectively to executive leadership, the Board of Directors, regulators, auditors, and non-technical stakeholders. Effectively translates technical and regulatory concepts into executive-level summaries, presentations, and recommendations that support informed decision-making and organizational alignment.
  • Strong judgment and decision-making skills in complex, time-sensitive, and high-risk situations.
  • Ability to synthesize complex security, regulatory, and technical information into clear executive and board-level reporting.
  • Excellent written and verbal communication skills with the ability to influence senior leaders, business partners, auditors, regulators, vendors, and technical teams.
  • Strong collaboration skills and ability to build effective partnerships across Risk, Compliance, Legal, Information Technology, Enterprise Data, business units, vendors, and executive leadership.
  • Strong analytical and problem-solving skills, including the ability to evaluate control gaps, assess risk exposure, prioritize remediation, and develop meaningful metrics.
  • Working knowledge of cloud security, identity and access management, endpoint security, data protection, security monitoring, vulnerability management, and artificial intelligence risk oversight.
  • Ability to balance security requirements with member experience, business needs, operational realities, and regulatory expectations.
  • High integrity, discretion, and professionalism when handling confidential security, member, employee, and organizational information.
  • Demonstrated leadership capability, including coaching, accountability, change leadership, and the ability to promote a strong security culture.

How You'll Work

  • Hybrid Work Environment: This position offers a hybrid work environment, combining remote work with regular on-site days at the Littleton Headquarters. This work environment is subject to change based on business needs.
  • This position may require availability outside normal business hours for security incidents, regulatory matters, urgent risk issues, executive updates, maintenance windows, or business continuity events.
  • Requires regular collaboration with internal technology teams, business leaders, executive leadership, auditors, regulators, vendors, and external security partners.

Compensation

Pay Grade: 18

FLSA Status: Exempt

Pay Grade Range: $188,113 - $250,817

Actual compensation offered may vary from the posted pay grade range based on factors such as relevant experience, time in role, base salary of internal peers, prior performance, business sector, licensure requirements and/or skill level, and will be finalized at the time of offer.

Total Rewards

  • Comprehensive medical, dental and vision plans
  • Basic life and AD&D insurance, short-term disability and long-term disability
  • 15+ days of paid time off (PTO) per year
  • Up to 16 hours of volunteer time off (VTO) per year
  • 11+ paid holidays
  • 401(k) that includes a Safe Harbor Match of up to 4%.
  • Tuition Reimbursement Program
  • Mental health resources including an Employee Assistance Program (EAP)
  • Individualized learning and development programs

Our Commitment to Inclusion

Workers Credit Union is an equal opportunity employer committed to creating an inclusive environment where all individuals feel respected, valued, and supported. We believe that diverse perspectives strengthen our organization and enhance our ability to serve our members and communities.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran status, disability, or any other protected characteristic under applicable law.

Applied = 0

(web-665cd84569-2d8ll)