Demo

Information Security Governance Lead

Verve, a Credit Union
Oshkosh, WI Full Time
POSTED ON 4/17/2026
AVAILABLE BEFORE 5/16/2026
Position Summary

The Information Security Governance Lead supports the Credit Union by identifying, assessing, driving, and tracking the mitigation of information security risk across systems, applications, data, and third-party relationships. This role partners closely with Information Technology and business leaders throughout the organization to strengthen governance, improve control effectiveness, and enhance the organization’s security and compliance posture through ongoing risk assessments, vendor management, security program recommendations, and executive-level reporting. The Lead supports control assurance activities by evaluating and documenting safeguards against well-known security frameworks, helping the organization prioritize improvements and communicate risk and control maturity in clear, decision-useful terms. The Lead also supports business continuity and incident response governance, ensuring plans remain current through coordinated updates and facilitating periodic tests and exercises to validate readiness and drive continuous improvement.

Position Responsibilities

  • Assess risks associated with information technology including systems, applications, data and infrastructure.
  • Conduct periodic information security control assurance assessments by evaluating the design and effectiveness of safeguards against internal requirements and well-known frameworks (e.g., NIST, CIS), documenting results, gaps, and prioritized recommendations.
  • Lead the organization’s Vendor Management program for new and existing third-party relationships, including due diligence reviews of contract terms, penetration tests, and SOC or IT Audit reports.
  • Regularly review and recommend adjustments to information security training programs to ensure training is addressing the highest risks to the credit union and meeting all compliance requirements and best practices.
  • Develop and maintain a comprehensive IT risk register, documenting identified risks and their potential impacts.
  • Collaborate with IT and physical security to design and implement risk mitigation strategies.
  • Monitor and track the effectiveness of risk mitigation efforts, recommending adjustments as necessary.
  • Recommend adjustments to policies, procedures, and controls to better manage IT compliance risks.
  • Maintain awareness of relevant regulations and guidance (e.g., FFIEC, GLBA, PCI-DSS) and translate requirements into practical control expectations and assessment criteria.
  • Track response to information security alerts to ensure timely resolution based on risk severity.
  • Report on aging of vulnerabilities and penetration test findings and track remediation efforts.
  • Compile and present security posture metrics appropriate for dissemination to senior leaders and the board.
  • Perform and manage user access reviews for key systems, documenting exceptions and remediation efforts.
  • Prepare executive-level IT risk reports for senior management and stakeholders.
  • Maintain up-to-date knowledge of regulatory changes and industry best practices related to IT compliance.
  • Support business continuity and incident response governance by coordinating updates with plan owners, ensuring roles, escalation paths, business impact analysis, playbooks, and other documentation remain current.
  • Provide guidance and support to IT and business teams on compliance related issues.
  • Plan, facilitate, and document periodic business continuity and incident response tests/exercises, capturing outcomes and improvement actions and tracking follow-through to completion.
  • Prepare and assist with collecting evidence for regulatory exams and audits.
  • Assist in the investigation of IT compliance incidents and breaches and prepare reports on findings.
  • Coordinate with internal and external stakeholders during compliance investigations and audits.
  • Administer the information security risk acceptance process.
  • Promote a culture of compliance.
  • Additional duties as assigned.

Qualifications

EDUCATION AND EXPERIENCE

  • Bachelor’s degree or a combination of education and experience.
  • 3 years of experience working at a financial institution.
  • 3 years of experience in risk management, compliance, information security or a related field.
  • 3 years of experience working in or closely with the Information Technology.
  • Experience with regulatory compliance frameworks such as CIS, FFIEC, NIST, ACET, InTREx, GLBA, PCI-DSS, etc.
  • Experience conducting risk assessments and implementing risk mitigation strategies.
  • Familiarity with reviewing vendor due diligence including contract terms, penetration tests, and SOC reports.
  • Certifications such as CRISC, CISSP, CISM, CySA , CASP , CRVPM, or CRBCMA preferred but not required.

KEY COMPETENCIES

  • Strong understanding of information security.
  • Proficiency in using risk assessment tools and methodologies.
  • Ability to document and communicate risk and control maturity in clear terms for leadership reporting.
  • Strong facilitation skills to plan and run exercises and drive follow-through on improvement actions.
  • Strong written documentation discipline (standards, evidence organization, and repeatable processes).
  • Familiarity with compliance management software or Governance, Risk, Compliance (GRC) tools.
  • Excellent analytical and problem-solving skills.
  • Strong communication and interpersonal skills.
  • Ability to work independently and collaboratively in a team environment.
  • Attention to detail and proactive approach to identifying and addressing risk.
  • Possess a working knowledge of all relevant Banking Rules and Regulations.

PHYSICAL DEMANDS AND WORK ENVIRONMENT

  • Work Environment: Business office, the noise level in the work environment is usually quiet to moderate.
  • Physical Requirements: Ability to sit or stand at a desk the majority of the day; talk or hear; stand or walk occasionally. While performing the duties of this job, the team member is typically utilizing a computer, keyboard, and phone. May occasionally reach with hands and arms; stoop, kneel, and crouch.

WHAT DO WE OFFER?

Benefits

  • Medical, dental and vision insurances
  • Supplemental insurances
  • Pre-tax and Roth 401(k) Safe Harbor options
  • Flexible spending accounts
  • Health Savings Account (HSA)
  • Paid time off (PTO)
  • Paid holidays, including birthday
  • Bereavement and pet leave
  • Basic Life/AD&D, short-term and long-term disability coverage at no cost
  • Voluntary Life/AD&D
  • Employee Assistance Program

The above information has been designed to indicate the general nature and level of work performed by persons within this job this job classification. It is not designed to contain or be interpreted as a comprehensive inventory of all the duties, responsibilities, and qualifications required of persons assigned to this job. Additional duties may be required to perform the job effectively.

Salary.com Estimation for Information Security Governance Lead in Oshkosh, WI
$91,098 to $109,260
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Information Security Governance Lead?

Sign up to receive alerts about other jobs on the Information Security Governance Lead career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Verve, a Credit Union

  • Verve, a Credit Union Neenah, WI
  • POSITION SUMMARY The Digital Branch Manager is responsible for overseeing the daily operations of the branch to deliver exceptional member experiences, ach... more
  • 10 Days Ago

  • Verve, a Credit Union Oshkosh, WI
  • Position Summary The Digital Marketing Manager serves the Marketing team by leading Verve’s digital demand engine and member engagement across web, search,... more
  • 10 Days Ago

  • Verve, a Credit Union Neenah, WI
  • Position Summary The Member Experience Advisor I serves as a member ambassador, providing exceptional service and personalized solutions across in-person, ... more
  • 11 Days Ago

  • Verve, a Credit Union Sherwood, WI
  • POSITION SUMMARY The Member Experience Advisor I serves as a member ambassador, providing exceptional service and personalized solutions across in-person, ... more
  • 11 Days Ago


Not the job you're looking for? Here are some other Information Security Governance Lead jobs in the Oshkosh, WI area that may be a better fit.

  • Community First Credit Union Neenah, WI
  • We believe that the right opportunity can provide a huge jumpstart towards earned expertise. As our Information Security Analyst, you'll be part of the tea... more
  • 15 Days Ago

  • Heartland Business Systems Little Chute, WI
  • Job Type Full-time Description Position Summary: This role will provide security Incident Response (IR) services for our customers. IR activities would inc... more
  • 1 Day Ago

AI Assistant is available now!

Feel free to start your new journey!