About the job
ABOUT NYMBUS:
Nymbus Inc. is an innovative fintech firm committed to providing cutting-edge technological solutions for banks and credit unions. Operating within a highly regulated landscape, we collaborate closely with financial institutions to drive modern core transformations and comprehensive outsourced digital banking brand solutions.
As we expand our operations, we are in search of a decisive and skilled Chief Information Security Officer (CISO) who can confidently lead and enhance our enterprise security program. The ideal candidate will possess the ability to make informed decisions and effectively communicate our overall security posture.
WORK ENVIRONMENT:
At Nymbus, we prioritize a remote-first culture. This role is entirely remote, though occasional travel may be necessary for client engagements or team meetings.
POSITION SUMMARY:
This strategic executive leadership position is crucial for our organization.
We are looking for a CISO with extensive knowledge of banking regulations (NIST, FFIEC, PCI, SOC) who can proactively evaluate and enhance our security program within the dynamic fintech sector that serves regulated financial institutions.
The successful candidate will:
- Have a deep understanding of regulated financial services environments.
- Possess a robust ability to address security vulnerabilities, influencing and leading necessary remediation efforts.
- Develop independent, well-informed perspectives on risk management.
- Advance initiatives independently without heavy oversight.
- Collaborate effectively with leaders in technology, product, and operations.
- Balance rapid innovation with prudent risk management.
- Be comfortable in a company that embraces AI in banking.
- Ensure timely remediation of identified risks through disciplined follow-up and accountability.
- Be a strategic builder, operator, and leader, rather than solely a policy overseer.
ESSENTIAL JOB FUNCTIONS/RESPONSIBILITIES:
Security Strategy & Program Maturity:
- Take ownership of and continuously improve the enterprise Information Security Program.
- Align our controls and architecture with NIST CSF, NIST 800-53, FFIEC guidance, PCI DSS, and SOC standards.
- Conduct proactive program assessments and identify security gaps to address potential issues before they arise.

