Apply now »

Chief Information Security Officer

Req ID: 78435 

Location: Tulsa -TUL 

Areas of Interest: Risk Management; Information Security 

Pay Transparency Salary Range: Not Available 

Application Deadline: 09/03/2026

BOK Financial Corporation Group includes BOKF, NA; BOK Financial Securities, Inc. and BOK Financial Private Wealth, Inc. BOKF, NA operates TransFund and Cavanal Hill Investment Management, Inc. BOKF, NA operates banking divisions: Bank of Albuquerque; Bank of Oklahoma; Bank of Texas and BOK Financial®.

Bonus Type

Discretionary

Summary

Protect what matters most at a $54 billion financial institution.

This is a senior executive role with enterprise-wide visibility, positioned to define how BOK Financial protects its systems, data and the customers who trust us with their financial lives.

As Chief Information Security Officer, you will lead the enterprise information security strategy and build a security program sized to our complexity — a bank, SEC-registered investment advisers, FINRA-supervised broker-dealers, and trust and fiduciary businesses, with more than $120 billion in assets under management or administration. You will also serve as the organization’s Privacy Officer, owning the enterprise privacy program end to end.

Reporting to the Chief Risk Officer, you will partner directly with executive leadership and the Board to define, assess and communicate our cyber-risk profile — inherent risk, control effectiveness, residual risk and where the trajectory is heading. You will lead security engineering, cyber threat management and response, identity and access management, and security risk and compliance, while shaping how we govern emerging risk across cloud and artificial intelligence.

If you are energized by operating at scale, translating complex risk into decisions executives can act on, and building a security culture that holds up under regulatory scrutiny, this role offers exceptional visibility and real influence over the future of the enterprise.

Job Description

The Chief Information Security Officer (CISO) is responsible for leading the enterprise information security strategy and protecting the organization’s systems, data, customer information, and information assets from compromise, unauthorized access, disclosure, or disruption. This role designs, implements, and matures an enterprise-wide information security program aligned to the organization’s size, complexity, risk profile, regulatory obligations, and business strategy.

BOKF’s information security program must also support the risk and regulatory complexity associated with more than $120B in assets under management or administration, two SEC-registered investment advisers, and two FINRA-supervised broker-dealer affiliates/subsidiaries.

The CISO is expected to support SEC and FINRA regulatory readiness by coordinating with affiliate compliance, legal, supervision, and business leaders on cybersecurity examinations, incident escalation and response, customer and client data protection, books-and-records considerations, third-party risk oversight, remediation tracking, and evidence-based demonstration of effective security governance across regulated advisory and broker-dealer affiliates.

The CISO also serves as the organization’s Privacy Officer and is responsible for overseeing the enterprise privacy program, including privacy governance, privacy risk management, regulatory readiness, customer/client information protection, privacy incident response, breach notification coordination, and alignment of privacy controls with cybersecurity, data governance, business, and regulated affiliate requirements.

The CISO partners closely with executive leadership, the Board, Risk, Information Technology, Compliance, Legal, Audit, business leaders, and external partners to identify, assess, monitor, and communicate the organization’s cyber-risk profile. This includes oversight of inherent risk, control effectiveness, residual risk, risk trajectory, security incidents, regulatory expectations, third-party risk, and emerging threats. The role is accountable for ensuring the organization maintains a strong security culture, operates within established risk thresholds, and has the leadership, governance, resources, controls, and response capabilities needed to protect the organization and its customers.

Team Culture

At BOK Financial, your potential is our priority. We invest in people, not just positions, because when you succeed, we all do.

You will be joining a culture that values:

  • Enterprise mindset — aligning teams and priorities to protect clients and the business as one organization
  • Innovation with discipline — advancing cloud, AI and modern security capabilities while maintaining strong governance
  • Leadership at every level — empowering teams while influencing across a matrixed, highly regulated organization
  • Continuous evolution — staying ahead of threats, technologies and regulatory expectations

This is a team where leaders are accessible, decisions get made, and the impact of your work is visible all the way to the Board.

How You'll Spend Your Time

  • Lead the enterprise information security program — policies, standards, controls, governance and reporting.
  • Define the organization’s cyber-risk profile, including inherent risk, control effectiveness, residual risk and risk trajectory against Board-approved thresholds.
  • Report security strategy, program effectiveness, incidents, and audit and examination outcomes to executive leadership and the Board.
  • Direct enterprise security operations — threat monitoring, vulnerability management, incident response, remediation and regulatory notification.
  • Serve as the organization’s Privacy Officer, owning privacy governance, risk assessments, training, incident response and breach notification.
  • Govern cloud security across SaaS, PaaS and IaaS, from architecture and identity to encryption, monitoring, resilience and cloud incident response.
  • Establish cybersecurity governance for AI and generative AI, including acceptable use, sensitive data protection and third-party AI risk.
  • Oversee third-party cyber risk from due diligence and contracting through ongoing monitoring, control validation and incident coordination.
  • Partner with affiliate compliance, legal and business leaders to drive SEC and FINRA regulatory readiness.
  • Secure a defensible, risk-based security budget by quantifying cyber risk in financial terms.
  • Build a high-performing security leadership team with strong talent pipelines, succession planning and a culture of accountability.

Education & Experience Requirements

Bachelor’s degree in Computer Science, Information Security, Information Assurance, Technology, Risk Management, Business, or a related field, with 15+ years of progressively responsible experience in information security, cybersecurity, technology risk, or related disciplines, including 8–10+ years in senior cybersecurity leadership roles; or an equivalent combination of education and experience.

Strongly preferred experience includes leadership of enterprise cybersecurity, privacy, cloud security, AI governance, technology risk, incident response, third-party risk management, and regulatory compliance programs within a large regulated financial services organization, including SEC-registered, FINRA-regulated, wealth management, fiduciary, and banking environments. Experience presenting to executive leadership and Boards, supporting regulatory examinations, and leading security program transformation initiatives is preferred.

Professional certifications such as CISSP, CISM, CISA, CRISC, GIAC, or related security, risk, audit, or privacy certifications are preferred. 

  • Deep expertise in cybersecurity, information security governance, risk management, security operations, cloud security, data protection, identity and access management, incident response, and third-party risk management.
  • Strong knowledge of financial services regulations and industry frameworks, including banking, privacy, cybersecurity, SEC, FINRA, and other applicable regulatory and compliance requirements.
  • Understanding of AI, generative AI, and emerging technology governance, including data protection, third-party risk, regulatory considerations, and cybersecurity controls.
  • Expertise in cloud security governance and architecture, including SaaS, PaaS, IaaS, access management, encryption, monitoring, resilience, and cloud service provider oversight.
  • Strong knowledge of privacy governance and Privacy Officer responsibilities, including data protection, privacy risk management, breach response, regulatory compliance, and customer information protection.
  • Ability to develop and execute cybersecurity strategy, communicate complex risks to executive leadership, Boards, regulators, and business stakeholders, and align security initiatives with organizational objectives and risk appetite.
  • Proven leadership, collaboration, and decision-making skills, with the ability to build high-performing teams, lead through cyber incidents and regulatory events, influence across functions, and adapt security programs to evolving threats, technologies, and regulatory requirements.

BOK Financial Corporation Group is a stable and financially strong organization that provides excellent training and development to support building the long term careers of employees. With passion, skill and partnership you can make an impact on the success of the bank, customers and your own career!  
Apply today and take the first step towards your next career opportunity!

 
The companies in BOK Financial Corporation Group are equal opportunity employers.  We are committed to providing equal employment opportunities for training, compensation, transfer, promotion and other aspects of employment for all qualified applicants and employees without regard to sex, race, color, religion, national origin, age, disability, pregnancy status, sexual orientation, genetic information or veteran status.

Please contact recruiting_coordinators@bokf.com with any questions. 

Tulsa, OK, US, 74101

Top 3 reasons to apply

Investing in our talent and building a great workplace is a top priority for us.

  • Empowered employees
  • Award-winning culture
  • Community commitment


Nearest Major Market: Tulsa
Nearest Secondary Market: Oklahoma

Job Segment: Information Security, Risk Management, Security Guard, Security Officer, Executive, Technology, Finance, Management, Security

Apply now »