How will this role impact First Command?
Reporting to the Director, Information Security & Data Privacy, this role is responsible for leading the execution, and continuous improvement of Information Security Operations across First Command Financial Services. The Associate Director will oversee day-to-day operational security capabilities that protect the organization, support regulatory and audit expectations, and improve the effectiveness of security controls. This role partners closely with IT leadership, Infrastructure, Risk, Legal, Compliance, and business stakeholders to ensure security operations are reliable, measurable, and aligned to enterprise priorities. Key areas of focus include, operational control execution, reporting, audit response, process maturity, and team leadership.
What will the employee do in this role?
- Lead and mature the Information Security Operations function, including execution, reporting, and continuous improvement.
- Oversee daily security operations activities, including monitoring, triage coordination, escalation processes, control execution, and operational readiness.
- Partner with Infrastructure, Risk, Legal, Compliance, and business teams to ensure security controls are implemented, operating effectively, and aligned to enterprise risk priorities.
- Coordinate vulnerability management, threat response, incident readiness, remediation tracking, and operational follow-up across technology and business teams.
- Develop and ensure the consistent maintenance of operational procedures, playbooks, process documentation, metrics, dashboards, and leadership reporting for security operations.
- Support audit, regulatory, and risk management activities by providing evidence, control narratives, remediation status, and operational reporting.
- Drive operational improvements that reduce risk, increase response effectiveness, strengthen accountability, and improve visibility into security posture.
- Manage security operations priorities, resource needs, project dependencies, and production support demands without jeopardizing critical operational work.
- Collaborate with project managers and technology leaders to align security operations requirements with enterprise initiatives and implementation timelines.
- Supervise employees in the area of responsibility, provide daily work direction and project assignments, and monitor progress against scheduled tasks.
- Measure team and program effectiveness through agreed-upon operational metrics, service levels, risk indicators, and control performance measures.
Who will this employee lead?
This role manages members of the Information Security team responsible for executing and supporting day-to-day security operations, control activities, incident readiness, vulnerability coordination, and operational reporting. The Associate Director provides work direction, coaching, prioritization, performance feedback, and accountability to ensure the team delivers reliable, timely, and risk-aligned security outcomes.
What skills and qualifications does this employee need?
Education
- Bachelor’s degree preferred
Work Experience
- 5+ years of relevant work experience in information security operations, cybersecurity, technology risk, infrastructure security, or related IT functions.
- Experience leading operational security capabilities such as security monitoring, vulnerability management, incident response coordination, threat management, access/security control operations, or security tooling support.
- Experience supporting audit, regulatory, compliance, or risk management activities in a financial services, banking, or similarly regulated environment.
- Experience in project, program, or operational management, including prioritization, resource coordination, reporting, and stakeholder communication.
- A minimum of 3 years’ leadership experience managing teams, vendors, operational processes, or cross-functional security initiatives.
Certifications
- Information security, cybersecurity, risk, or technology certification preferred, such as CISSP, CISM, CISA, CRISC, Security+, GIAC, or equivalent experience.
Required Knowledge, Skills and Abilities
- Strong understanding of information security operations, security controls, incident response processes, vulnerability management, threat management, and operational risk reduction.
- Ability to translate technical security issues into business risks, priorities, action plans, and executive-level updates.
- Experience developing and maintaining operating procedures, playbooks, evidence packages, metrics, dashboards, and status reporting.
- Demonstrated ability to coordinate across technical teams, business stakeholders, vendors, audit, compliance, and risk partners to drive timely outcomes.
- Strong analytical, problem-solving, prioritization, and decision-making skills in a timeline-driven operational environment.
- Passion for well-organized documentation, repeatable processes, measurable controls, and operational accountability.
- Ability to manage multiple operational and project priorities, including staffing considerations, planning, resource allocation, timelines, and production support demands.
- Excellent communication skills for setting expectations, clarifying assignments, escalating risks, and keeping team members and stakeholders focused on priorities.
- Demonstrated ability to manage, coach, and develop a highly technical and diverse team while fostering collaboration, accountability, and continuous growth.
LI-NC1
LI-Hybrid