First Entertainment Credit Union Logo

First Entertainment Credit Union

Sr. Manager, Information Security

Posted 2 Days Ago
Be an Early Applicant
Easy Apply
Hybrid
Hollywood, Los Angeles, CA
130K-170K Annually
Senior level
Easy Apply
Hybrid
Hollywood, Los Angeles, CA
130K-170K Annually
Senior level
Lead and mature the enterprise information security program, oversee cybersecurity operations, GRC, risk management, IAM, vulnerability and third-party risk programs, ensure regulatory compliance, drive incident response and cyber resilience, and advise executive leadership and the Board on security strategy and investments.
The summary above was generated by AI

First Entertainment Credit Union is looking for a Sr. Manager, Information Security who is responsible for leading the organization’s information security program to protect information assets, technology infrastructure, and customer data. This role develops security strategy, oversees cybersecurity operations, governance, risk, and compliance (GRC), ensures regulatory compliance, manages security risks, and partners across the organization to strengthen the overall security posture.

 

The Sr. Manager will serve as a trusted advisor on cybersecurity strategy, emerging threats, risk exposure, and security investments. They will provide advice on security architecture, technology implementations, cloud adoption, and security requirements for new systems and initiatives. The role maintains and enhances cyber resilience through business continuity planning, disaster recovery management, cyber incident response planning, ransomware preparedness exercises, tabletop testing, and recovery readiness.

 

This is a full-time hybrid in Hollywood, CA and reports to the VP, Enterprise Risk Management. For candidates in California, the targeted pay range is between $130,000 to $170,000.

 

Responsibilities

 

  • Develop, execute, and continuously mature the enterprise Information Security Program, including security strategy, governance frameworks, policies, standards, procedures, roadmaps, and annual planning initiatives.
  • Establish and maintain security governance practices aligned with organizational objectives and provide cybersecurity reporting, metrics, risk insights, and strategic recommendations to executive leadership and the Board.
  • Lead enterprise cyber risk management activities, including risk assessments, cyber risk register ownership, emerging threat analysis, risk treatment planning, and integration with the enterprise risk management framework.
  • Oversee security operations, including security monitoring, incident detection, SOC relationships, incident response coordination, forensic investigations, vulnerability remediation, and post-incident corrective actions.
  • Direct identity and access management (IAM) programs, including least-privilege access controls, privileged access management, user access certifications, and segregation of duties compliance.
  • Lead vulnerability and threat management programs, including vulnerability scanning, pen test, threat intelligence review, risk-based remediation prioritization, and patch management oversight.
  • Oversee third-party cybersecurity risk management, including vendor assessments, SOC report reviews, cloud security evaluations, ongoing risk monitoring, and remediation of control gaps.
  • Ensure compliance with applicable cybersecurity laws, regulations, frameworks, and industry standards, including but not limited to NCUA, FFIEC, GLBA, PCI DSS, NIST, CIS Controls.
  • Lead cybersecurity audits, exams, and regulatory readiness efforts, including regulatory requests, corrective action tracking, policy exception management, risk acceptance processes, and control assessments.
  • Maintain and enhance cyber resilience through business continuity planning, disaster recovery coordination, cyber incident response planning, ransomware preparedness exercises, tabletop testing, and recovery readiness.
  • Develop and promote enterprise security awareness and education programs, including phishing simulations, executive cybersecurity education, and initiatives that foster a security-first culture.
  • Develop and maintain cybersecurity KRIs, KPIs, dashboards, and reporting processes while administering and optimizing Governance, Risk, and Compliance (GRC) platforms and tools.

 

At First Entertainment, your role and every role are essential to our Mission [We build lifelong financial relationships with the people in entertainment based on a deep understanding of how they live and work], Core Values [ Members First + Ownership + Integrity + Innovation + Inclusivity + One Team], and we expect you to uphold them.

 

Requirements

 

  • Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Systems, or a related field. A Master's degree preferred but not required.
  • 8+ years of progressive information security, cybersecurity, risk management, or IT governance experience, including 5+ years in a leadership or people management role.
  • Strong knowledge of cybersecurity frameworks, standards, and regulations, including NIST Cybersecurity Framework, NIST 800-53, FFIEC guidance, GLBA, CIS Controls, ISO 27001, and applicable financial services regulatory requirements.
  • Professional certifications such as CISSP, CISM, CRISC, CISA, CGEIT, CCSP, or equivalent preferred but not required.
  • Prior experience within the banking, credit union, financial services, fintech, or other highly regulated industries preferred but not required.
  • Experience conducting enterprise cyber risk assessments, maintaining risk registers, developing risk treatment plans, and integrating cyber risk into enterprise risk management programs.
  • Proficiency in security operations, vulnerability management, threat intelligence, penetration testing, and third-party cybersecurity risk management programs.
  • Strong understanding of identity and access management, privileged access controls, segregation of duties, and security governance best practices.
  • Experience reviewing technology implementations, cloud environments, network architectures, and system designs to identify and mitigate security risks.
  • Experience supporting business continuity, disaster recovery, cyber resilience planning, tabletop exercises, and ransomware preparedness activities.
  • Exceptional written, verbal, and presentation skills, with the ability to effectively communicate across all audience levels.

Similar Jobs at First Entertainment Credit Union

An Hour Ago
Easy Apply
Hybrid
Easy Apply
Mid level
Mid level
Fintech • Financial Services
Lead and support day-to-day post-origination loan servicing across real estate, commercial, and consumer loans. Serve as first-level escalation for teammates and members, perform quality control reviews, ensure compliance with lending regulations, assist with audits, coach and develop staff, manage servicing workflows (payoffs, lien releases, escrow, insurance tracking), and partner cross-functionally to resolve servicing issues and improve processes.
Top Skills: EncompassMeridian LinkMS OfficeSymitar
3 Days Ago
Easy Apply
Remote or Hybrid
Easy Apply
36K-36K Annually
Mid level
36K-36K Annually
Mid level
Fintech • Financial Services
Generate and manage a self-sourced residential mortgage pipeline through outside sales, referral cultivation, and community engagement. Advise clients from application to closing, ensure compliance with mortgage regulations, maintain pipeline reporting, and represent the credit union at events and seminars to drive referral activity.
Top Skills: Encompass 360Loan Origination System (Los)
4 Days Ago
Easy Apply
Remote or Hybrid
9 Locations
Easy Apply
35-42 Hourly
Mid level
35-42 Hourly
Mid level
Fintech • Financial Services
Develop, maintain, and update policies, procedures, and member-facing disclosures to ensure regulatory compliance and clarity. Partner with compliance, legal, risk, and business stakeholders, conduct gap analyses and document reviews, manage version control and publication, and maintain audit-ready centralized repositories under tight timelines.
Top Skills: Documentation ToolsMS OfficeSharepoint

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account