← All rolesVP
Vice President of Cyber Assurance and Defense
Broadview Federal Credit Union · Financial Services · 1,001-5,000 employees
Albany, NY · Hybrid · full_time
Listed by the employer as “VP, Cyber Assurance & Defense”. Title normalized for comparability.
CLI Career Level
SVP-equivalent
Moderate confidence
Opportunity Score
68/100
Solid
High confidence
Executive Fit
Sign in
Add your background to score this role against you
Career Level and Opportunity Score describe the role itself. Executive Fit is the only figure that depends on your profile.
First seen Aug 17, 2026 · Last verified 3 hours ago · Sourced from LinkedIn — VP / Head of Security (US)
CLI Take
Broader than the title suggests
This role reads SVP-equivalent despite being advertised as “VP, Cyber Assurance & Defense” — the stated scope is wider than the employer's title implies. CLI's analysis of the posting describes a strategic build or transformation mandate, and it reports to SVP Information Risk and Security and carries board-level exposure. The posting reads closer to an individual contributor mandate: hands-on delivery expected. Team size is not disclosed and remains the main open question before pursuing it.
Why this role scores the way it does
68/100 — solid opportunity quality. CLI reads this as a SVP-equivalent mandate. Strongest signal: CLI's analysis of the posting describes a strategic build or transformation mandate. Main drag on the score: The posting reads closer to an individual contributor mandate: hands-on delivery expected. 3 of 10 dimensions are not disclosed, which lowers confidence rather than the score.
Career level read
SVP-equivalent — The employer lists this as “VP, Cyber Assurance & Defense”. CLI reads it as SVP-equivalent because the role shows board-level exposure expected, reports to an SVP, 1,001-5,000 employee organization.
Moderate confidence
What makes it attractive
- CLI's analysis of the posting describes a strategic build or transformation mandate.
- Board-level exposure is expected in the role.
- Employer profile: 1,001-5,000 employee organization, nonprofit ownership, not applicable, revenue 250m 1b.
What to probe before applying
- The posting reads closer to an individual contributor mandate: hands-on delivery expected.
- The reporting line sits below the executive team — the role reports to an SVP.
Scoring components · Solid
Compensation versus comparable roles55 · weight 15%
The employer discloses a base range, but there is no comparable set to benchmark it against yet.
Reporting level36 · weight 12%
The reporting line sits below the executive team — the role reports to an SVP.
Functional and geographic scopeNot disclosed · excluded from the score
Scope: no enterprise, global or multi-unit remit is described.
Quality of the mandate100 · weight 12%
CLI's analysis of the posting describes a strategic build or transformation mandate.
Executive and board exposure100 · weight 10%
Board-level exposure is expected in the role.
Role authority versus title25 · weight 10%
The posting reads closer to an individual contributor mandate: hands-on delivery expected.
Company scale and trajectory83 · weight 10%
Employer profile: 1,001-5,000 employee organization, nonprofit ownership, not applicable, revenue 250m 1b.
Team ownershipNot disclosed · excluded from the score
Team size: not disclosed.
Budget ownershipNot disclosed · excluded from the score
Budget ownership: not disclosed.
Risk signals100 · weight 5%
No adverse signals identified in the posting.
Dimensions the employer does not disclose are excluded and the remaining weights are rebalanced, so missing information lowers confidence rather than the score.
Sign in to see how this role scores against your background, and add your career goal to evaluate career value.
Compensation
$200,000 – $250,000 base salary, disclosed by employer
Sample size not yet sufficient for a market comparison
See the full benchmark bands by level and region
The mandate
The VP is hired to design and operate a second-line technical cyber assurance and defense program for a highly regulated financial institution. The mandate focuses on maturing defensive/offensive capabilities, identity governance, and incident response to meet CFPB-scale regulatory expectations and provide independent oversight of IT and Engineering controls.
Reporting to the SVP Information Risk and Security, this role leads the second-line technical oversight function including Cyber Defense and Identity Governance. The remit covers independent validation of security controls across network, cloud (AWS), and SaaS environments.
Scope
- Reports to SVP Information Risk and Security
- Board-level exposure expected
Domains and regulation
- Cyber Defense
- Incident Response
- Identity
- GRC
- Cloud Security
- Application Security
- Infrastructure Security
- NYDFS Part 500
- GLBA
- PCI DSS
Requirements
Must have
- 15+ years of progressive, hands-on technical information security experience in financial services or similar industries.
- 5+ years at a VP level or equivalent senior leadership role managing enterprise-scale cybersecurity programs.
- 10+ years leading highly technical security teams (Forensics, Penetration Testing, SOC, IR).
- Demonstrated experience operating under FFIEC, NCUA, CFPB, and NYS DFS regulatory scrutiny.
- Hands-on expertise with AWS cloud security and Microsoft 365 E5 security stack.
- CISSP or CEH certification.
Preferred / bonus
- Nothing listed as optional.
Only must-have items are scored as hard constraints in Executive Fit.
Likely challenges
- Maturing an evolving program into a repeatable, regulator-ready capability suitable for CFPB-scale supervision.
- Centralizing access risk decisions and architecting an enterprise Identity & Access Governance (IAG) program.
- Operating as a second-line technical oversight function while maintaining deep hands-on expertise across modern security tooling.
- Transitioning security capabilities from ad-hoc processes to defined, measurable, and defensible documentation.
Not stated in the posting: Total team size (headcount) not specified..
About Broadview Federal Credit Union
Broadview Federal Credit Union is a member-owned financial institution formed in 2022 through the merger of SEFCU and CAP COM Federal Credit Union. It serves over 500,000 members across New York's Capital Region and beyond, managing more than $8 billion in assets. The organization operates within a highly regulated banking environment requiring robust cybersecurity frameworks for retail and commercial financial services.
- Industry
- Financial Services
- Headcount
- 1,001-5,000 employees
- Headquarters
- Albany, New York
- Founded
- 1934
- Ownership
- Nonprofit
- Funding
- Not applicable
- Revenue
- $250M – $1B
Full company profile for Broadview Federal Credit Union →
View original job description
If you are ready to join a company that truly cares about its employees, our members, and our community then you have come to the right place!Summary of Role:The Vice President of Cyber Assurance and Defense is responsible for designing, operating, and maturing a comprehensive, risk‑based cyber assurance and defense program for a complex, highly regulated financial institution. This role ensures Broadview Federal Credit Union (BFCU) maintains strong defensive and offensive cyber capabilities, a robust access access governance, and measurable cyber risk reduction aligned with regulatory expectations, business strategy, and member protection.This position is responsible for the second‑line technical cyberassurance and defense function, providing independent oversight, challenge, and assurance over controls, while partnering closely with IT, Engineering, and Business leadership. The VP will mature an evolving program into a repeatable, defensible, regulator‑ready capability suitable for CFPB‑scale supervision or a best-in-class organization.The role requires a deep technical hands on expertise across modern security tooling, cloud and SaaS platforms, offensive security, digital forensics, SIEM/SOC operations, identity governance, and incident response combined with the ability to to translate cyber risk into business and regulatory terms.Essential Job Functions/Responsibilities:Cyber Assurance & Defense LeadershipProvide oversight of the Cyber Assurance & Defense function (includes Cyber Defense and Identity Governance), encompassing:Defensive security monitoring and detectionOffensive security (penetration testing, red/purple teaming)Digital forensics and investigationsIdentity and Access governance (IAG)Act as the technical security expert, independently validating initiatives/ project situations, security control design, effectiveness, and sustainability. Program Maturity & Continuous ImprovementDesign and execute a multi‑year cybersecurity maturity roadmap addressing:Vulnerability and exposure managementSecurity architecture and technical design reviewsSecurity tool rationalization and roadmap planningEarly warning detection capabilities using SIEM and UEBADeception technologies and advanced detection engineeringMature security capabilities from ad‑hoc to defined, repeatable, and measurable, with regulator defensible documentation and evidence. Cyber Defense, Detection & Incident Response (IR)Enhance and oversee the Cybersecurity Incident Response Team (CIRT) program, including:Maintain updated IR plans, playbooks, and runbooks to align with evolving threatsDefine roles and escalation pathsExecutive and regulator communication standardsTabletop exercises and live simulationsOversee forensic investigations involving:Endpoint, network, cloud, and SaaS platformsInsider threat activityCredential misuse and account compromiseEnsure lessons learned are operationalized into control improvements. Support SVP Information Risk and Security managing incident responseIdentity & Access Governance (IAG)Architect and lead a centralized enterprise IAG program, including:Encourage Role Based Access Control (RBAC)Least privilege enforcementSegregation of duties (SoD)Privileged Access Management (PAM)Assess, select, and implement user access governance platforms appropriate for financial services scale and risk. Centralize access risk decisions based on application criticality, data sensitivity, and regulatory impact. Risk Identification, Assessment & ReportingIdentify emerging cyber threats and systemic risks impacting:Core banking systemsCloud (AWS) and SaaS platforms (Microsoft 365)Digital channels and member facing technologiesTranslate technical findings into clear risk statements with prioritized remediation recommendations. Develop cyber risk metrics, KRIs, and dashboards to:Inform senior leadership and board committeesOptimize investment decisionsDemonstrate risk reduction over timeTechnology, Cloud & Secure Engineering AdvisementReview and challenge technology controls across are required:Network and infrastructureCloud (AWS IaaS/PaaS)SaaS (Salesforce Shield, Microsoft 365 E5)DevSecOps pipelines and CI/CD toolingEnsure security is embedded in (security by design):System acquisitionsProjects and initiativesSoftware development lifecyclesChange and release managementProvide guidance on secure AI usage, automation, and emerging technologies. People Leadership & Executive PartnershipBuild, lead, and mentor a team of highly technical cybersecurity practitioners capable of:Threat modeling and attack simulationDetection engineeringForensic analysisTechnology and security control validationServe as a trusted advisor to leadership and peers. Communicate complex security concepts clearly to both technical and non technical stakeholders. Minimum Job Qualifications:15+ years of progressive, hands‑on technical information security experience in financial services or similarly regulated industries. Ability to deliver risk focused recommendations balancing cost and benefit5+ years at a VP level or equivalent senior leadership role managing enterprise scale cybersecurity programs. 10+ years leading highly technical security teams, including direct involvement in:Forensic investigationsEthical hacking / penetration testingSIEM/SOC operations and threat analysisIncidence responseED/EXRSecurity tool implementationsDemonstrated experience operating under FFIEC, NCUA, CFPB, NYS DFS Cybersecurity, GLBA, PCI and regulatory scrutiny. Technical Expertise (Required)Network, endpoint, and application securityEncryption, key management, and data protectionCloud security (AWS IaaS/PaaS)SaaS security controlsCertificationsOne or more of the following required:CISSPCEHAdditional certifications (AWS Security, GIAC, OSCP) are strongly preferred. Work Location RequirementOnsite in Albany, NY with a minimum of four (4) days per week. Hands on leadership presence is required to support teams, regulators, and critical incident response. SIEM/SOAR platforms and detection engineeringIdentity and access governance systemsMicrosoft 365 E5 security stackDevSecOps and secure SDLC practicesRed team, purple team, and adversary simulationAI Security MonitoringAI usage in cybersecurity operations and detectionStarting Compensation: $200,000-$250,000, plus a competitive benefits package.Bilingual individuals who are fluent in a second language in addition to English are highly encouraged to apply.All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other status protected by applicable law.Broadview FCU is committed to ensuring individuals with disabilities and/or those who have special needs participate in the workforce and are afforded equal opportunity to apply and compete for jobs. If you would like to contact us regarding the accessibility of our Website or need assistance completing the application process, please contact us at talentacquisition@broadviewfcu.com
Cyber Leadership Index is not the employer and does not represent candidates for these roles. Verify all details with the employer before acting.