Cornerstone Capital Bank Logo

Cornerstone Capital Bank

Director, Integrated Security

Posted 19 Days Ago
Be an Early Applicant
Remote or Hybrid
Hiring Remotely in United States
Expert/Leader
Remote or Hybrid
Hiring Remotely in United States
Expert/Leader
Develop, implement, and maintain the banks enterprise information security program. Independently assess first-line security risk management, regulatory compliance, incident response, and control effectiveness. Oversee security governance, policy, KRIs, business continuity, and third-line coordination. Provide unfiltered reporting and challenge to executive management and the Board and lead post-incident reviews and resilience testing.
The summary above was generated by AI

Cornerstone Capital Bancorp, Inc., headquartered in Houston, is a Texas-based financial services company dedicated to helping families, businesses, and communities thrive. Through its primary subsidiary, Cornerstone Capital Bank, the organization operates a community and business banking franchise alongside a premier national home lending, servicing, and home insurance platform-based financial services company dedicated to helping families, businesses, and communities thrive.

Guided by a core Mission, Vision and Convictions statement, Cornerstone operates 17 full-service banking locations across major Texas markets and more than 150 mortgage offices nationwide.  The company has served nearly 700,000 customers through its family of brands, including Cornerstone Home Lending, Roscoe Bank, Peoples Bank, Cornerstone Servicing, and Cornerstone Insurance. Supported by 1,600 team members, Cornerstone is consistently recognized as a Fortune-certified Great Place to Work® and a Top Workplace. 

Formed through the combination of Cornerstone Home Lending and The Roscoe State Bank, Cornerstone brings more than a century of experience and is the highest-capitalized new bank in Texas history.

We honor God by using our talents to make a positive difference in the lives of our Team Members, Clients, Shareholders, Communities, and the People who provide services to us.

Who we are looking for:

The Director, Integrated Security, is responsible for developing, implementing, and maintaining a comprehensive information security program to protect the bank's data and systems, ensuring compliance with regulations and industry standards.  Areas of oversight include Enterprise Security Governance,  the Bank’s policies and programs for Information Security, IT Risk Management, and Corporate Security.

What you’ll do:

Security Risk Framework and Policy:

  • Establish and maintain the enterprise security risk management framework, including risk appetite statements, policies, minimum control standards, and risk taxonomies that the first line is required to implement.
  • Review and challenge first-line policies, standards, and procedures to confirm alignment with regulatory expectations, the Bank’s risk appetite, and industry frameworks (e.g., NIST CSF, FFIEC CAT, ISO 27001).

Independent Risk Assessment and Challenge:

  • Perform independent assessments of the first line’s identification, measurement, and management of security risks, including review of risk and control self-assessments (RCSAs), issue management, and key risk indicators.
  • Provide credible challenge to first-line risk treatment decisions, exception requests, and risk acceptances; escalate unresolved concerns through governance committees to executive management and the Board.

Regulatory and Compliance Oversight:

  • Monitor and independently assess first-line compliance with applicable laws, regulations, and supervisory expectations (e.g., GLBA, FFIEC IT Handbook, NYDFS Part 500, SEC cybersecurity disclosure rules, state privacy laws); track remediation of regulatory findings and matters requiring attention (MRAs).
  • Partner with the Chief Privacy Officer to provide oversight and challenge of the first line’s implementation of GLBA’s privacy provisions and other consumer data protection requirements

Incident Oversight:

  • Establish minimum standards for the first line’s incident response, business resilience, and cyber recovery programs; review and challenge the design, testing, and continuous improvement of those programs.
  • Serve in an advisory and oversight capacity during material security incidents; perform independent post-incident reviews of first-line response effectiveness and root-cause remediation, and report findings to executive management and the Board.

Security Culture and Awareness Oversight:

  • Establish enterprise expectations for the first line’s security awareness and role-based training programs, and independently assess their effectiveness through metrics, phishing test results, and behavioral indicators.
  • Monitor and report on the enterprise security risk culture; identify gaps and recommend improvements to executive management and the Board.

Technology and Control Oversight:

  • Set control objectives and minimum technical standards for security architecture and tooling; review and challenge first-line technology selection, design, and deployment decisions for alignment with risk appetite.
  • Independently test and validate the design and operating effectiveness of key security controls operated by the first line; document findings and track remediation through closure.

Three Lines of Defense Coordination:

  • Coordinate with first-line technology and business owners, Enterprise Risk Management, Compliance, Legal, and Internal Audit (3LOD) to ensure clear roles, avoid duplication, and maintain the independence of the second-line challenge function.
  • Engage with business and technology leaders to understand strategic initiatives, provide advisory input on emerging security risks, and assess whether first-line risk management is commensurate with the risks taken.

Independent Reporting and Governance:

  • Produce independent reporting on the Bank’s security risk posture, control effectiveness, key risk indicators, and emerging threats for executive management, the Risk Committee, and the Board, with an unfiltered reporting line that does not require first-line approval.
  • Review first-line security metrics, key risk indicators (KRIs), and breach/event trends to form an independent view of risk position relative to appetite.

Business Continuity Ownership:

  • Develop and maintain business continuity and resiliency plans.
  • Conduct business impact analyses and continuity risk assessments.
  • Coordinate continuity testing, exercises, and corrective actions.
  • Maintain business continuity governance, reporting, and documentation.
  • Lead crisis response and recovery coordination during disruptions.
  • Partner with business units and vendors to strengthen operational resilience.
  • Monitor compliance with continuity policies and regulatory expectations.
  • Deliver business continuity training and awareness programs.
  • Report continuity risks and program performance to management.
  • Align business continuity, disaster recovery, and incident management activities.

What you’ll need to be successful: 

Success in this job relies on your time management skills, organization, and positive attitude.  In addition, you’ll need the following qualifications:

    • Minimum of 10 years of experience in information security, technology risk, or operational risk management within the Financial Services sector, with at least 5 years in a second line of defense, risk oversight, or audit capacity
    • Minimum of 5 years Mid to Large Bank experience, including direct interaction with regulators (OCC, FRB, FDIC, NYDFS, or state banking departments) and the Board or its Risk Committee
    • Bachelor’s Degree preferred
    • Expert knowledge of three-lines-of-defense risk governance, enterprise risk management frameworks, regulatory expectations (FFIEC IT Handbook, NIST CSF, NYDFS Part 500, GLBA, SR Letters), and the principles of independent challenge and effective challenge.
    • Strong analytical reasoning, problem solving and critical thinking skills
    • Strong computer and organizational skills
    • Strong oral and written presentation skills
    • Ability to work independently with a multi-level team
    • Ability to multi-task and meet deadlines
    • Strong proficiency with Microsoft Office (Word, Excel, Outlook, etc.);
  •  

    • Preferred Certifications:

      • Current Certified Information Systems Security Professional (CISSP)
      • Current Certified in Risk and Information Systems Control (CRISC)
      • Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), or equivalent risk/audit certification preferred

     

    What we offer: 

    Because we recognize and reward hard work, we offer a competitive salary, a full benefits package, and the potential for a performance-based bonus. 

    What to do next: If Cornerstone sounds like the place for you (and if you have the qualifications, drive, and passion to match), we invite you to become a member of our winning team! And remember, once you're part of our Cornerstone family, we'll continue to invest in you as a valuable asset in our company. As many of our team members can tell you, there's something special about working at Cornerstone.

    Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
    This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.

    Cornerstone Capital Bank Austin, Texas, USA Office

    13640 Briarwick Drive, Suite 110, Austin, United States, 78729

    Cornerstone Capital Bank Round Rock, Texas, USA Office

    1 Chisholm Trail Road, Suite 450 - Office 437, Round Rock, United States, 78681

    Similar Jobs

    6 Minutes Ago
    Remote or Hybrid
    45K-85K Annually
    Junior
    45K-85K Annually
    Junior
    Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
    Handles inbound calls and warm leads, consults customers on insurance needs, recommends appropriate coverages, and converts prospects into policyholders. The role includes paid licensing and training, customer communication, sales closing, and remote work using company-provided equipment. Representatives must work four weekdays and one weekend day, maintain a professional home workspace, and meet minimum wired internet requirements.
    Top Skills: Cable/Fiber/Dsl High-Speed InternetPersonal Computer
    8 Minutes Ago
    Easy Apply
    Remote or Hybrid
    Easy Apply
    103K-174K Annually
    Senior level
    103K-174K Annually
    Senior level
    Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
    Serve as a strategic operating partner to the VP of Customer Success by managing calendar, communications, travel, expenses, meetings, events, stakeholder relationships, and special projects. Build scalable processes, coordinate executive briefings and cross-functional initiatives, maintain organizational accountability, and support Pacific Time business hours. This remote US role requires approximately one trip per month for executive support and onsites.
    Top Skills: Ai AssistantsGoogle WorkspaceNotionSlack
    8 Minutes Ago
    Remote
    United States
    165K-185K Annually
    Senior level
    165K-185K Annually
    Senior level
    Fintech • Payments
    Build and expand fintech and payment systems using Go, microservices, databases, and cloud technologies. Design production APIs and tooling, diagnose customer issues, manage full release lifecycles, document systems, and mentor engineers. Collaborate with product and business teams while guiding AI agents to produce maintainable, observable, testable code that meets engineering standards. Work independently in a high-availability environment and contribute to next-generation financial products.
    Top Skills: AlloydbDockerGitGoHttp/2JSONKafkaKubernetesMicroservicesPostgresProtobufSpannerTypescriptWebhooks

    What you need to know about the Austin Tech Scene

    Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

    Key Facts About Austin Tech

    • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
    • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
    • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
    • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
    • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
    • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

    Sign up now Access later

    Create Free Account

    Please log in or sign up to report this job.

    Create Free Account