Posted 27 July, 2026
Director Information Security
LHH US
San Francisco, CA, US
Full Time
Job Description
Job Description
LHH is seeking an experienced Director of Information Security to lead and evolve the organization's enterprise information security, cybersecurity, and technology risk management programs.
This is a highly visible leadership role responsible for protecting the systems, networks, applications, and member data while ensuring compliance with regulatory requirements and industry best practices. The Director of Information Security will partner closely with Information Technology, Risk, Compliance, Internal Audit, executive leadership, and business stakeholders to strengthen the organization's security posture and support continued growth.
This is a hands-on leadership position that combines strategic planning, security program ownership, regulatory oversight, cybersecurity operations, and technology risk management. The role is not a pure compliance position and is not a purely technical individual contributor role.
Key Responsibilities
Information Security Strategy & Governance
The successful candidate will:
Pay Details: $150,000.00 to $180,000.00 per year
Search managed by: Jeff Schweiger
Equal Opportunity Employer/Veterans/Disabled
Military connected talent encouraged to apply
To read our Candidate Privacy Information Statement, which explains how we will use your information, please navigate to https://www.lhh.com/us/en/candidate-privacy
The Company will consider qualified applicants with arrest and conviction records in accordance with federal, state, and local laws and/or security clearance requirements, including, as applicable:
This is a highly visible leadership role responsible for protecting the systems, networks, applications, and member data while ensuring compliance with regulatory requirements and industry best practices. The Director of Information Security will partner closely with Information Technology, Risk, Compliance, Internal Audit, executive leadership, and business stakeholders to strengthen the organization's security posture and support continued growth.
This is a hands-on leadership position that combines strategic planning, security program ownership, regulatory oversight, cybersecurity operations, and technology risk management. The role is not a pure compliance position and is not a purely technical individual contributor role.
Key Responsibilities
Information Security Strategy & Governance
- Develop, implement, and maintain the enterprise information security program and cybersecurity roadmap.
- Establish and maintain policies, standards, procedures, and controls aligned with business objectives and regulatory expectations.
- Provide executive leadership with regular updates on cybersecurity risks, program maturity, vulnerabilities, incidents, and remediation efforts.
- Promote a culture of information security awareness and accountability throughout the organization.
- Oversee security monitoring, threat detection, incident response, and remediation activities.
- Lead vulnerability management, penetration testing coordination, security assessments, and risk mitigation initiatives.
- Manage controls related to endpoint security, identity and access management, network security, email security, and cloud security.
- Coordinate cybersecurity incident response activities, including investigation, containment, recovery, and post-incident review.
- Maintain incident response procedures and escalation protocols.
- Support NCUA examination readiness and regulatory compliance activities.
- Lead security governance efforts related to FFIEC, GLBA, and other applicable regulatory frameworks.
- Partner with Risk, Compliance, and Internal Audit teams to assess and mitigate technology-related risks.
- Oversee third-party technology risk management initiatives and vendor security reviews.
- Coordinate business continuity planning and disaster recovery readiness efforts.
- Ensure security and resilience considerations are integrated into business operations and strategic initiatives.
- Help ensure the Credit Union can effectively respond to operational and cybersecurity disruptions.
- Provide oversight and governance related to AI-enabled technologies and emerging digital capabilities.
- Partner with business leaders to evaluate technology risks, innovation opportunities, and responsible AI implementation practices.
- Bachelor's degree in Information Security, Computer Science, Information Technology, Cybersecurity, or related field; equivalent experience considered.
- 10+ years of progressive experience in cybersecurity, information security, technology risk, or related fields.
- Experience leading enterprise information security programs.
- Strong understanding of cybersecurity operations, incident response, vulnerability management, and technology risk management.
- Experience with regulatory environments, risk assessments, and security governance.
- Exceptional communication skills with the ability to influence technical and non-technical stakeholders.
- Experience presenting security risks and recommendations to senior leadership.
- Direct experience supporting NCUA, FFIEC, and GLBA regulatory requirements.
- Experience within a credit union, community bank, or regulated financial services environment.
- Experience leading security programs in organizations with lean teams where strategic thinking and hands-on execution are both required.
- Professional certifications such as CISSP, CISM, CRISC, GIAC, or equivalent.
- Experience with AI governance, third-party risk management, and business continuity planning.
The successful candidate will:
- Strengthen and mature the Credit Union's information security program.
- Improve cybersecurity resilience and regulatory readiness.
- Build strong partnerships across Technology, Risk, Compliance, and business teams.
- Drive proactive risk management and continuous improvement initiatives.
- Help enable secure innovation and digital transformation while maintaining member trust.
- Meaningful leadership opportunity within a growing financial institution.
- Ability to influence cybersecurity strategy and organizational risk management.
- Collaborative culture focused on member service and community impact.
- Growth-oriented executive team committed to technology modernization and operational excellence.
Pay Details: $150,000.00 to $180,000.00 per year
Search managed by: Jeff Schweiger
Equal Opportunity Employer/Veterans/Disabled
Military connected talent encouraged to apply
To read our Candidate Privacy Information Statement, which explains how we will use your information, please navigate to https://www.lhh.com/us/en/candidate-privacy
The Company will consider qualified applicants with arrest and conviction records in accordance with federal, state, and local laws and/or security clearance requirements, including, as applicable:
- The California Fair Chance Act
- Los Angeles City Fair Chance Ordinance
- Los Angeles County Fair Chance Ordinance for Employers
- San Francisco Fair Chance Ordinance
