Hiring.Camp

Third Party Security Lead

Old National Bank

·

Today

Location
Evansville, IN, US
Type
Full-time
Department
Security
Seniority
Lead
Experience
5+ years
Closing date
Today
Source
iCIMS

Description

Overview

Old National Bank has been serving clients and communities since 1834. With over $70 billion in total assets, we are a regional powerhouse deeply rooted in the communities we serve. As a trusted partner, we thrive on helping our clients achieve their goals and dreams, and we are committed to social responsibility and investing in our communities through volunteering and charitable giving. 

 

We continually seek highly motivated and talented individuals as our people are critical to our success. In return, we offer competitive compensation with our salary and incentive program, in addition to medical, dental, and vision insurance.  401K, continuing education opportunities and an employee assistance program are also included in our benefit suite. Old National also offers a variety of Impact Network Groups led by team members who are passionate about driving engagement, creating awareness of diverse backgrounds and experiences, and building inclusion across the organization.  We offer a unique opportunity to join a growing, community and client-focused company that is firmly rooted in its core values.

Responsibilities

Salary Range

The salary range for this position is $81,700/yr - $165,100/yr plus bonus. The base salary indicated for this position reflects the compensation range applicable to all levels of the role across the United States. Actual salary offers within this range may vary based on a number of factors, including the specific responsibilities of the position, the candidate’s relevant skills and professional experience, educational qualifications, and geographic location.

 

The Third‑Party Security Lead is responsible for the design, execution, and continuous improvement of ONB’s third‑party cybersecurity and technology risk oversight, ensuring risks introduced through external vendors, partners, and applications are effectively identified, assessed, and mitigated across the lifecycle. This role will lead and oversee inherent risk assessments, cybersecurity due diligence, and application security reviews, including application security testing across both third‑party delivered solutions and internally managed systems and integrations, to evaluate end-to-end control effectiveness and shared responsibilities. The position oversees comprehensive control evaluations including due diligence questionnaires, documentation review, and control testing/validation across information security and technology risk domains, such as Identity and Access Management, Security Operations, Network Security, Cryptography, and Logging/Monitoring, while driving risk-based decisions, remediation activities, and formal risk acceptance where appropriate.

 

The Third‑Party Security Lead partners closely with business units, procurement, legal, and technology stakeholders to ensure information security and technology risk requirements are embedded into third‑party engagements, assess vendor connectivity and integration risks (e.g., cloud, APIs, and network access), and validate that both vendor and ONB-controlled application components meet established standards and regulatory expectations. The role ensures effective governance over ongoing monitoring, issue management, and remediation, while supporting audit and regulatory activities. Additionally, this position advances risk assessment methodologies beyond traditional due diligence toward integrated third‑party and application security testing, continuous monitoring, and threat-informed assessments, strengthening ONB’s overall information security and technology security posture. This role will foster a strong risk-aware culture across the enterprise and influence behaviors to reduce risk.

 

Key Accountabilities

Execution of Security Risk Assessments and Control Testing

  • Provide subject matter expertise within ONB’s ISTRM Program by assessing the impact of new vendors, technologies, processes, or partnerships including vendor-hosted solutions, SaaS platforms, and third-party integrations (e.g., APIs, cloud services, and network connectivity), and risk-based decision making.
  • Lead and oversee end-to-end risk assessments, control testing, and risk management review processes to analyze third-party, application, and organization risk and control effectiveness assisting vendors and team members in risk and control identification.
  • Evaluate the design and operating effectiveness of controls across key information security and technology risk domains, including Identity and Access Management (IAM), Security Operations, Network Security, Cryptography and key management, Security Assessment and Testing, and Logging, Monitoring, and Incident Response.
  • Translate technical findings into business risk statements for stakeholders and governance forums.
  • Escalate issues and recommendations to management, using a risk-based approach, for immediate attention as needed.
  • Validate remediation actions and ensure identified control gaps are effectively addressed.
  • Establish and enforce effective information security and technology risk management practices across the vendor and application lifecycle, including onboarding, periodic reviews, and trigger-based reassessments, ensuring consistency, quality, and defensibility of risk evaluations.
  • Identify applicable laws and regulations and validate adherence to required standards for vendors, business applications, infrastructure, processes, etc.

Due Diligence & Documentation Review

  • Review and analyze due diligence artifacts including security questionnaires, SOC reports, penetration test results, policies, standards, and control documentation.
  • Validate completeness and accuracy of vendor and team member responses and supporting evidence.
  • Perform gap analysis against internal standards, regulatory expectations, and industry frameworks (e.g., NIST, CRI, ISO 27001, FFIEC, GLBA).
  • Support pre-assessment readiness activities and guide vendors and team members through required documentation expectations.
  • Support the creation, maintenance, and continuous improvement of ONB’s ISTRM policies, program, procedures, standards, security documentation, regulatory documentation, etc.
  • Provide leadership and effort in the buildout, maintenance, and detailed mapping of global regulatory and industry frameworks to organizational control standards.
  • Organize and prepare metrics and dashboards for committee, council, and regulatory reporting, ensure smooth execution of meetings, present information as requested, and communicate and track outcomes of meetings.
  • Participate in departmental activities and assignments including meetings, updates, planning, reporting, and other responsibilities as needed.

Collaborate with internal and external stakeholders:

  • Partner with business owners, procurement, legal, and technology teams to support secure vendor and application onboarding and ongoing monitoring ensuring requirements are incorporated into their program, business processes, and projects.
  • Interface directly with third parties to clarify controls, request evidence, and discuss findings.
  • Support contract security requirements and risk acceptance decisions.
  • Collaborate with security engineering, SOC, and incident response teams to ensure alignment of monitoring and threat detection for vendor risks.
  • Partner with the first line of defense and risk offices on risk control assessments and provide guidance on development and enhancement of key controls and risk management.
  • Assess and respond to information security events and incidents. Assist in coordination with internal and external parties and assist in evaluation, communication and documentation of issues and incidents
  • Support and coordinate internal audits, collaborating with auditors to ensure adherence to standards
  • Develop, publicize, and support education and training initiatives for all team members to raise awareness of information security and risk management requirements.
  • Act as an information security and technology risk advocate to management, team members, and business/process owners.
  • Influence behaviors to reduce risk and foster a strong ISTRM culture throughout the enterprise.

Key Competencies for Position

  • Planning, Organization, and Execution: Self-starter, motivated, able to drive efforts and propose paths forward independently. Ability to effectively prioritize, track, and execute tasks in a consistent and timely manner while simultaneously managing multiple assignments. Thorough in accomplishing a task through concern for all the areas involved, no matter how small.  Monitors and checks work on information and plans while organizing time and resources efficiently.  Adapts well to changes in assignments and priorities; yet, can maintain focus and stay current with day-to-day responsibilities. Committed to achieving established goals and overcoming obstacles. Ability to effectively prioritize, track, and execute tasks in a consistent and timely manner
  • Problem Solving/Decision Making - Ability to define problems, collect data, establish facts, and draw valid conclusions. Ability to interpret an extensive variety of technical instructions in mathematical or diagram form and deal with several abstract and concrete variables.  Able to identify issues and potential risks; incorporates input from multiple sources (e.g., lines of business, subject matter experts, industry leaders, data, policies, procedures, etc.) to ensure complete views determining an effective course of action and to promote shared ownership; decisions are sound based on what was known at the time and are based on a blend of analysis, wisdom, experience, and judgement.
  • Communication: Ability to present ideas, decisions, and recommendations effectively to all levels of management in a clear and professional manner, including excellent written, oral communication, and interpersonal skills. Ability to confidently educate and advise senior leaders.
  • Technical Knowledge: Possesses the required technical knowledge to perform the role effectively; ability to comprehend new information rapidly in the everchanging technical landscape; desire for continuous learning to adapt to emerging risks and threats. 

Qualifications and Education Requirements

  • Bachelor’s degree in Computer Science, Technology, related field, or equivalent work experience required
  • 5+ years experience in cybersecurity, information security risk, or third-party/vendor risk management within financial services.
  • Minimum of 3+ years of experience leading or supporting a third-party security risk management and application assessment program.
  • Detailed understanding of information security frameworks such as ISO27XXX, NIST, CRI, and industry best practices
  • Involvement in adhering to security laws and regulations affecting financial institutions including, but not limited to, GLBA, SOX, HIPAA, FFIEC, etc.
  • Extensive knowledge of and experience with information security and technology risk management, control development, and control validation.
  • Knowledge of application, infrastructure, cloud, and network security concepts with the ability to evaluate technical architectures and identify security weaknesses in vendor and application integrations.
  • Experience in policy, standards, and procedure creation based on selected framework and implementation issues related to regulatory and other requirements.
  • Thorough understanding of how to analyze business applications, perform application security assessments, and recommend appropriate security controls.
  • Knowledge and experience with an enterprise GRC and IT Service Management system.
  • Knowledge of OCC Heightened Standards for risk assessment, incident response, and third-party risk management.
  • Achieved or in pursuit of a globally recognized information security certification such as CISSP (Certified Information Systems Security Professional), CISA (Certified Information Systems Auditor), or equivalent preferred.

Key Measures of Success/Key Deliverables:

  • Demonstrate measurable effectiveness of the Information Security and Technology Risk Management Program through timely assessments, reduction of high-risk findings, and successful audit and regulatory outcomes.
  • Ensure existing and new technologies, partners, and processes meet the security standards of Old National and successful delivery per internal and external SLA agreements.
  • Development of strong relationships and technical work throughout the organization and with key vendors, to ensure the bank is benefiting from a procedural, security, compliance, and efficiency perspective
  • Continual development of knowledge base and applied learning to benefit the company

Old National is proud to be an equal opportunity employer focused on fostering an inclusive workplace and committed to hiring a workforce comprised of diverse backgrounds, cultures and thinking styles. 

 

As such, all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, protected veteran status, status as a qualified individual with disability, sexual orientation, gender identity or any other characteristic protected by law. 

 

We do not accept resumes from external staffing agencies or independent recruiters for any of our openings unless we have an agreement signed by the Director of Talent Acquisition, SVP, to fill a specific position.

 

Our culture is firmly rooted in our core values.

We are optimistic. We are collaborative. We are inclusive. We are agile. We are ethical.

We are Old National Bank.  Join our team!

 

Skills

CybersecuritySOCSOXRisk ManagementComplianceProcurementHIPAAISO 27001CISSP

Similar Jobs

17

Third Party Security - Programme Support

Experian · Nottingham, England, United Kingdom · Hybrid

1 week ago

Cyber Security Third Party Associate Manager

Pepsi Co · New Cairo, EG · Onsite

2 weeks ago

Senior Security Third Party Risk (TPRM) Analyst

OneTrust · Atlanta, Georgia +1

3 weeks ago

Senior IS Analyst-IT Security (Third party Security, Security Contracts, Security Regulations)

Franklintempleton · IND-HYSB-Hyderabad, India

1 month ago

Third Party Security Risk Operations Lead

Gsknch · Bengaluru Campus 31, India

1 month ago

Third Party Security Risk Product Lead

Gsknch · Bengaluru Campus 31, India

1 month ago

Third Party Security Risk Analyst

Gsknch · Bengaluru Campus 31, India · Onsite

1 month ago

IT Security Manager - Third-Party IT Risk Manager

Wk · USA - Riverwoods, IL, United States of America +4 · Hybrid

1 week ago

Senior Third-Party Cyber Security Risk Analyst

Toyota · Plano, United States of America

2 weeks ago

Third Party Cyber Security Assessor

Ghr · Denver, United States of America +2 · Onsite

1 month ago

Third Party Product Security Engineer

Rockwellautomation · India Chennai OMR · Hybrid

1 month ago

Third Party Product Security Engineer

Rockwell Automation · India Chennai OMR · Hybrid

1 month ago

Business Analyst – Third Party Cyber Security

TEC Partners Limited · London

5 months ago

Manager, Security Engineering, Secure Third Party Tools

Amazon

Today

Security Engineer, Secure Third Party Tools

Amazon

3 days ago

Third Party Risk Analyst, Security GRC

Anthropic · Remote-Friendly (Travel Required) | San Francisco, CA · Onsite, Remote

1 week ago

Security Compliance Specialist (Third-Party Risk)

Cloudpay · San Jose, Costa Rica · Hybrid

2 weeks ago