Deputy Chief Information Security Officer
Job description
About the role
You will serve as the operating second to the Chief Information Security Officer and bear primary ownership of Mercury's bank-entity scope within the 2LOD Information Security program. You are responsible for ensuring the program is consistently examiner-ready by maintaining coherent policy architecture, evidenced controls, a credible gap-remediation track record, and a tested incident response program with documented exercise history. This is not a research or strategy role; it is a build-and-defend role that requires delivering tangible compliance and oversight outcomes for a national bank charter. You will sit across the table from OCC examiners, FFIEC IT audit teams, the Chief Risk Officer, and the board's risk committee, and you will be expected to answer for every line in our policies and every status in our control inventory. Mercury is a fintech company, not an FDIC-insured bank, with banking services provided through Choice Financial Group and Column N.A., Members FDIC. Your work will directly shape the security and regulatory posture of the bank-entity and protect its stakeholders.
Key facts
What you'll do
Define and govern the bank-entity second line of defense information security program scoped to the chartered bank and aligned with regulatory expectations.
Champion examiner posture by preparing narratives, coordinating evidence, and responding to inquiries from OCC, FFIEC, FDIC, and FRB examiners.
Lead remediation of FFIEC IT control deficiencies to achieve charter readiness ahead of the OCC pre-opening examination.
Carry the bank-scoped policy architecture, including Policy, Standard, and Procedure documents, ratification cycles, MRCC memos, and board approvals.
Partner with the Chief Risk Officer on business continuity, resilience, and recovery through tabletop exercises and full-scale drills.
Manage audit and assurance relationships across internal audit (3LOD) and external assessors such as SOC 2, FFIEC CAT, and regulator-led IT examinations.
Ensure third-party risk management evidence withstands bank-grade scrutiny for critical service providers and material outsourcing arrangements.
Coach and grow the GRC sub-team, run recurring training cadences, and build bench depth to meet the requirements of a national bank.
Operate with disciplined execution by maintaining cadences, producing executive-ready status documentation, and keeping controls, evidence, and risk registers current.
Operate within the three-lines-of-defense model, understanding the oversight role and collaborating effectively with first and third lines of defense.
Maintain a technical baseline that allows you to challenge architecture reviews and read incident timelines credibly without needing to be an engineer.
Drive continuous improvement in information security governance, risk, and compliance processes to support the bank's regulatory and business objectives.
Requirements
8+ years in Information Security, with 3+ years inside a regulated bank, trust bank, or de novo bank charter effort; Mercury is a startup chartering a national bank - this experience is non-negotiable.
Deep FFIEC and OCC fluency, including working knowledge of the FFIEC CAT, the FFIEC IT Examination Handbook, BSA/AML IT supervisory expectations, and the OCC Heightened Standards.
Direct examiner-facing experience defending controls to an OCC, FDIC, or Federal Reserve examiner and understanding what good evidence looks like before it gets challenged.
Ability to draft board-ratifiable policy and supporting standards that operationalize intent, not merely satisfy a checklist.
Demonstrated operating discipline to run cadences, write status that survives executive review, and maintain currency of controls, evidence, and risk registers.
Clear understanding of the three-lines-of-defense model and prior experience in an oversight role.
Strong commitment to regulatory compliance and the ability to translate regulatory expectations into operational security programs.
Capacity to manage multiple priorities in a fast-paced, regulated environment while maintaining attention to detail and accuracy.
Nice to have
Prior Deputy CISO or equivalent senior 2LOD role at a national bank, trust bank, or large credit union.
Charter or de novo bank experience; if you have stood up a bank before, that is a meaningful advantage here.
Strong technical baseline, allowing you to challenge an architecture review and read an incident timeline credibly.
CISSP, CISM, or CRISC certification.
Practical notes
This role requires availability within the United States, with possible work locations in San Francisco, CA, New York, NY, Portland, OR, or remote arrangements.
Travel may be required as part of the role, and specific hours may vary based on business and regulatory needs.
Visa sponsorship considerations may apply depending on candidate qualifications and location requirements.
Deadlines for onboarding will align with the timing of the OCC pre-opening examination and charter milestones.