
Cybersecurity Risk Lead
- Risk Management
- GLBA
- Change Management
- Threat Modeling
- SIEM
- Incident Response
- Vulnerability Management
- AI
- Identity Management
- CISSP
- CRISC
- CISM
- CCSP
- Zero Trust
- Server-Sent Events
- Technical Writing
- Pension
Live here. Play here. Bank here.Work here.
If you’re looking to build your career at a forward-thinking organization with deep community roots and a vision for growth, success, and giving back, you’ve come to the right place.
Get to know us:
We’re your local community bank—and have been since 1875—that is committed to providingexcellent customer service andgiving back to our communities.
We foster acollaborative, inclusive work environment as part of a close-knit team where yourvoice is valued and heard.
Ourhighly engaged employees are rewarded for their performance and have ample opportunities for cross-training andadvancement within the organization.
We’ve been named one of thebest places to work in Maine, and offerrobust benefits focused on your holistic well-being.
______________________________________________________________________________________________________________
Job DescriptionPosition Summary:
The Cybersecurity Risk Lead is responsible for aligning cybersecurity capabilities, processes, and controls with regulatory requirements, industry frameworks, and organizational risk objectives. This role serves as the primary cybersecurity subject matter expert for technology risk analysis, architecture review, security strategy, control effectiveness, and framework alignment. The position partners with technology teams, business stakeholders, and third-party providers to ensure cybersecurity initiatives support the Bank's overall risk management strategy.
Essential Duties and Responsibilities:
Align cybersecurity capabilities and controls with regulatory and industry frameworks including NIST CSF, GLBA, FFIEC guidance, and applicable banking regulations.
Conduct cybersecurity risk assessments for technologies, projects, systems, and third-party solutions.
Participate in security reviews of vendor technologies, SaaS platforms, cloud services, and technology integrations.
Analyze and recommend security controls throughout system acquisition, development, implementation, and change management processes.
Conduct threat modeling, attack path analysis, and architecture risk reviews using frameworks such as STRIDE, MITRE ATT&CK, or similar methodologies.
Contribute to the administration, effectiveness, and continuous improvement of enterprise security controls and technologies, including firewalls, SIEM/SOAR, email security, incident response, vulnerability management, and data loss prevention.
Develop and maintain cybersecurity standards, governance requirements, and security control frameworks.
Provide cybersecurity guidance for enterprise initiatives involving cloud services, artificial intelligence, identity management, and emerging technologies.
Partner with technology and business stakeholders to ensure security requirements are integrated into project planning and solution development.
Assess the effectiveness of existing security controls and recommend improvements based on risk and business objectives.
Support the development and maintenance of cybersecurity strategy, roadmap, and long-term security initiatives.
Identify emerging risks, regulatory changes, and technology trends impacting the organization.
Assist in the evaluation of compensating controls and risk acceptance decisions.
Support audit, examination, and regulatory activities related to cybersecurity governance and risk management.
Basic Qualifications:
Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or related field
5 years of cybersecurity, information security, technology risk, security architecture, or governance experience
Experience with Firewalls, SIEM/SOAR, Email security, Incident Response, Vulnerability Management, and Data Loss Prevention
Working knowledge of NIST CSF, GLBA, FFIEC guidance, and cybersecurity governance practices
Experience with development, implementation, operation, and testing of information technology within regulated environments
Understanding of security controls across cloud, network, identity, endpoint, and application domains
Experience assessing technology implementations and recommending risk-based security controls.
Preferred Qualifications:
CISSP, CRISC, CISM, CCSP, or similar certification
Risk management experience
Experience with Zero Trust, SASE/SSE, ZTNA, or cloud security architecture
Understanding of securing AI tools, AI integrations, and AI oversight
Experience with third-party risk management and vendor security assessments
Prior experience working in a regulated environment or financial services industry
Skills and Abilities:
Strong risk analysis and problem-solving skills
Ability to translate complex cybersecurity concepts into business-focused recommendations
Technical writing expertise
Strategic planning and project management capabilities
Strong Stakeholder relationship management skills
Ability to balance security requirements with business objectives
Ability to influence and collaborate across teams
The statements contained herein reflect general details as necessary to describe the principal functions for this job, the level of knowledge and skill typically required, and the scope of responsibility, but should not be considered an all-inclusive listing of work requirements. Individuals may perform other duties as assigned, including work in other functional areas to cover absences or to equalize peak work periods to balance workloads.
We encourage candidates to consult with their Talent Partner throughout the recruiting process to better understand how their experience aligns with the role, as well as details on compensation and our total rewards offerings. The prospective range of pay we will offer to a successful applicant to this position is $68,350.00-$101,550.00, which represents a good faith estimate of what we expect to offer at the time of posting based on the role’s responsibilities, level and location. Actual starting salary will be determined by the Bank in the Bank’s discretion, and shall depend on the applicant’s experience, skills, education, certifications, as well as other relevant business conditions. Final offers will reflect these considerations and may vary accordingly.________________________________________________________
Our comprehensive total rewards package offers something for everyone!
- Robust medical, dental, and vision insurance packages
- Generous time off, including paid federal holidays and paid day off for your birthday
- 401(k) retirement savings plan
- Tuition reimbursement, professional development, and career growth opportunities
- Employee assistance program
- Comprehensive wellness program
Pursuea career at Camden National Bank andapply today. We can't wait to hear from you!
_____________________________________________________________________
We are guided and inspired by our Core Values:
- Honesty and Integrityabove all else
- Trustbuilt on fairness
- Service that creates remarkable experiences
- Responsibilityto use our resources for the greater good
- Excellencethrough hard work and lifelong learning
- Diversityrealized through inclusion and respect
Equal Opportunity Employer
Employment with Camden National is on an at-will basis, meaning employment is not guaranteed for any specific period of time, and any employment relationship established may be terminated by either party at any time, for any reason, with or without notice. Completion of an employment application is not a contract, express or implied, guaranteeing employment. Camden National Bank is an Equal Opportunity Employer and does not discriminate on the grounds of race, color, religion, sex, sexual orientation, including gender identity and gender expression, national origin, citizenship status, age, disability, genetic information or veteran status.
Learn more about why employees love working at Camden National Bank!
Cybersecurity Risk Lead · Camden National Bank