General information
Entity
About Crédit Agricole Corporate and Investment Bank (Crédit Agricole CIB)
Crédit Agricole CIB is the corporate and investment banking arm of Crédit Agricole Group, the 10th largest banking group worldwide in terms of balance sheet size (The Banker, July 2022).
8,600 employees in more than 30 countries across Europe, the Americas, Asia-Pacific, the Middle-East and North Africa, support the Bank's clients, meeting their financial needs throughout the world.
Crédit Agricole CIB offers its large corporate and institutional clients a range of products and services in capital market activities, investment banking, structured finance, commercial banking and international trade.
The Bank is a pioneer in the area of climate finance, and is currently a market leader in this segment with a complete offer for all its clients.
For more information, please visit www.ca-cib.com
Twitter: https://twitter.com/ca_cib
LinkedIn: https://www.linkedin.com/company/credit-agricole-cib/
By working every day in the interest of society, we are a group committed to diversity and inclusion. All our positions are open to people with disabilities.
Reference
2025-97128
Update date
24/02/2025
Job description
Business type
Types of Jobs - IT, Digital et Data
Job title
Cybersecurity Incident Response Team Lead – Vice President
Contract type
Permanent Contract
Job summary
Summary
The Cybersecurity Incident Response Team Lead is a leadership role responsible for leading and enhancing the bank’s Security Operations strategy. The Cybersecurity Incident Response Lead will oversee the incident response and threat intelligence programs to safeguard critical assets and data. The ideal candidate will combine technical expertise, operational efficiency, and a strategic mindset to mitigate risks and ensure compliance with regulatory requirements. This role requires exceptional leadership, technical skills, and communication skills to drive cross-functional collaboration and instill a culture of security across the organization.
Key Responsibilities
· Strategic Leadership
Develop and execute a comprehensive security operations strategy aligned with the bank's risk appetite and business objectives.
Provide thought leadership on emerging cyber risks and recommend proactive measures to mitigate them.
Serve as a trusted advisor to executive leadership, management committees, and the board on cyber risk issues.
o Define, maintain, and report operational metrics to evaluate Security Operations program performance, effectiveness, and adherence with organizational and regulatory requirements.
· Incident Response and Crisis Management
o Direct and manage Americas Cyber Security Incident Response Team (CSIRT) to ensure timely monitoring, detection, and response to threats.
o Lead the development and execution of the bank’s incident response plan and associated playbooks
o Coordinate responses to security incidents, ensuring minimal impact and quick recovery.
o Establish and maintain a threat intelligence program to proactively identify and respond to emerging threats.
· Process and Technology Optimization
o Evaluate, implement, and optimize security processes and technologies to enhance detection and response capabilities.
o Collaborate with IT and engineering teams to integrate security into systems and processes.
o Stay updated on emerging technologies and recommend solutions to address evolving threats.
· Regulatory Compliance and Audit Readiness
Ensure adherence to cyber risk management regulations, including FFIEC and other applicable laws.
Represent the bank during regulatory examinations, audits, and executive presentations on cyber risk topics.
o Maintain thorough documentation to demonstrate adherence to policies and standards.
· Team Leadership and Development
o Build and mentor a high-performing security operations team.
o Provide training and development opportunities to ensure team members stay current in the field.
o Foster a culture of accountability, collaboration, and continuous improvement
Supplementary Information
Core Competencies
Ability to work at both a strategic and tactical level, focusing on the broader picture while driving execution.
Ability to manage multiple initiatives simultaneously, determine prioritization, and work under minimal supervision.
Awareness of latest Information Security risks.
Comfort working in a highly global, diverse, and hybrid (office and virtual) work environment.
Strong technology, information security, and investigation skills.
Strong communication and documentation skills.
Knowledge of business, regulatory, and compliance requirements in the financial services industry
Salary Range: $150k - $180k
#LI-DNI
Position location
Geographical area
America, United States Of America
City
NEW YORK
Candidate criteria
Minimal education level
Bachelor Degree / BSc Degree or equivalent
Academic qualification / Speciality
Bachelor’s degree in Cybersecurity, Information Technology, Business Administration, or a related field.
Advanced degree (MBA, MS) is strongly preferred.
Relevant industry certifications (CISSP, CISM, GIAC) are strongly preferred.
Experience
Minimum 10+ years of experience in information security or related field.
At least 3 years of experience in a senior leadership role within the banking or financial services industry
Required skills
Incident Management: Ability to analyze, prioritize, and manage security incidents effectively.
Strategic Thinking: Ability to align cyber risk initiatives with business objectives
Communication and Documentation: Strong ensure thorough documentation and clear communications over security operations activities.
Leadership and Team Management: Proven track record of building and leading high performing teams
Regulatory Compliance: Expertise in navigating banking regulations
Technical Knowledge: Strong knowledge with information security technologies such as SIEM, SOAR, EDR, NDR, etc.
Investigations: Strong knowledge with leading security investigations.
Cybersecurity Frameworks: Deep understanding of frameworks such as NIST Cybersecurity Framework
Policy and Procedure Development: Proficiency in drafting and enforcing policies, procedures, and playbooks.
Industry Thought Leadership: Recognized as a subject matter expert in the cybersecurity or risk management space