Skip to main content
Posted 27 July, 2026

Director Information Security

LHH US
San Francisco, CA, US Full Time

Job Description

Job Description
LHH is seeking an experienced Director of Information Security to lead and evolve the organization's enterprise information security, cybersecurity, and technology risk management programs.

This is a highly visible leadership role responsible for protecting the systems, networks, applications, and member data while ensuring compliance with regulatory requirements and industry best practices. The Director of Information Security will partner closely with Information Technology, Risk, Compliance, Internal Audit, executive leadership, and business stakeholders to strengthen the organization's security posture and support continued growth.

This is a hands-on leadership position that combines strategic planning, security program ownership, regulatory oversight, cybersecurity operations, and technology risk management. The role is not a pure compliance position and is not a purely technical individual contributor role.

Key Responsibilities

Information Security Strategy & Governance
  • Develop, implement, and maintain the enterprise information security program and cybersecurity roadmap.
  • Establish and maintain policies, standards, procedures, and controls aligned with business objectives and regulatory expectations.
  • Provide executive leadership with regular updates on cybersecurity risks, program maturity, vulnerabilities, incidents, and remediation efforts.
  • Promote a culture of information security awareness and accountability throughout the organization.
Cybersecurity Operations
  • Oversee security monitoring, threat detection, incident response, and remediation activities.
  • Lead vulnerability management, penetration testing coordination, security assessments, and risk mitigation initiatives.
  • Manage controls related to endpoint security, identity and access management, network security, email security, and cloud security.
  • Coordinate cybersecurity incident response activities, including investigation, containment, recovery, and post-incident review.
  • Maintain incident response procedures and escalation protocols.
Regulatory Compliance & Technology Risk
  • Support NCUA examination readiness and regulatory compliance activities.
  • Lead security governance efforts related to FFIEC, GLBA, and other applicable regulatory frameworks.
  • Partner with Risk, Compliance, and Internal Audit teams to assess and mitigate technology-related risks.
  • Oversee third-party technology risk management initiatives and vendor security reviews.
Business Continuity & Operational Resilience
  • Coordinate business continuity planning and disaster recovery readiness efforts.
  • Ensure security and resilience considerations are integrated into business operations and strategic initiatives.
  • Help ensure the Credit Union can effectively respond to operational and cybersecurity disruptions.
AI Governance & Emerging Technologies
  • Provide oversight and governance related to AI-enabled technologies and emerging digital capabilities.
  • Partner with business leaders to evaluate technology risks, innovation opportunities, and responsible AI implementation practices.
Required Qualifications
  • Bachelor's degree in Information Security, Computer Science, Information Technology, Cybersecurity, or related field; equivalent experience considered.
  • 10+ years of progressive experience in cybersecurity, information security, technology risk, or related fields.
  • Experience leading enterprise information security programs.
  • Strong understanding of cybersecurity operations, incident response, vulnerability management, and technology risk management.
  • Experience with regulatory environments, risk assessments, and security governance.
  • Exceptional communication skills with the ability to influence technical and non-technical stakeholders.
  • Experience presenting security risks and recommendations to senior leadership.
Preferred Qualifications
  • Direct experience supporting NCUA, FFIEC, and GLBA regulatory requirements.
  • Experience within a credit union, community bank, or regulated financial services environment.
  • Experience leading security programs in organizations with lean teams where strategic thinking and hands-on execution are both required.
  • Professional certifications such as CISSP, CISM, CRISC, GIAC, or equivalent.
  • Experience with AI governance, third-party risk management, and business continuity planning.
What Success Looks Like

The successful candidate will:
  • Strengthen and mature the Credit Union's information security program.
  • Improve cybersecurity resilience and regulatory readiness.
  • Build strong partnerships across Technology, Risk, Compliance, and business teams.
  • Drive proactive risk management and continuous improvement initiatives.
  • Help enable secure innovation and digital transformation while maintaining member trust.
Why Join
  • Meaningful leadership opportunity within a growing financial institution.
  • Ability to influence cybersecurity strategy and organizational risk management.
  • Collaborative culture focused on member service and community impact.
  • Growth-oriented executive team committed to technology modernization and operational excellence.
help protect the systems, people, and members that power our mission while shaping the future of cybersecurity and technology risk management across the organization.

Pay Details: $150,000.00 to $180,000.00 per year

Search managed by: Jeff Schweiger

Equal Opportunity Employer/Veterans/Disabled

Military connected talent encouraged to apply

To read our Candidate Privacy Information Statement, which explains how we will use your information, please navigate to https://www.lhh.com/us/en/candidate-privacy

The Company will consider qualified applicants with arrest and conviction records in accordance with federal, state, and local laws and/or security clearance requirements, including, as applicable:
  • The California Fair Chance Act
  • Los Angeles City Fair Chance Ordinance
  • Los Angeles County Fair Chance Ordinance for Employers
  • San Francisco Fair Chance Ordinance
Massachusetts Candidates Only: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.