Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Information Security Risk Analyst

SUMITOMO MITSUI TRUST BANK, LIMITED

Job Description

Job Description

This role is located in New York City and will require a hybrid work schedule of at least 2 days in office per week.

This role is for Officer level candidates. 

About the Bank:Sumitomo Mitsui Trust Bank, Limited was established through the merger of The Sumitomo Trust and Banking Co., Ltd with Chuo Mitsui Trust and Banking, Ltd. on April 1, 2012. We are one of the largest asset managers in Asia and number one among Japanese financial institutions by AUM, with approximately $850 Billion USD in AUM. The Bank provides an assortment of financial solutions and manages a broad spectrum of financial products across its global branches.

Department Overview:

The Americas Division (“AD”) was established in the Sumitomo Mitsui Trust Bank, Limited, New York Branch) (“SMTBNY”) to perform corporate functions and supervise U.S. entities. Established under the AD are the “Global Banking Unit (“GBU”), Americas Division” and “Global Markets Unit (“GMU”), Americas Division” which performs business functions. Information Risk Governance (“IRG”) provides oversight to information and cyber security risk by maintaining and improving branch wide framework that is in-line with the Head Office and regulatory requirements and addresses Confidentiality, Integrity, and Availability for information assets. IRG establishes appropriate policies, procedures, measurement, and monitoring processes to proactively assess and evaluate and cyber security and information security risks inherent in the Branch Operations. IRG is directly involved in all information and cyber security related projects, matters and issues.

Your Role Overview:

The Information Security Risk Analyst is responsible for supporting the organization’s vulnerability management program and performing assigned information security risk assessments. This role will perform the day-to-day vulnerability management activities, perform risk-based analysis of identified vulnerabilities, coordinate remediation efforts with the IT Department, and help ensure systems are maintained in accordance with the organization’s information security standards. 

Your Duties and Responsibilities:

  1. Administer and support the organization’s system vulnerability management program.
  2. Conduct regular vulnerability scans across servers, endpoints, applications, network infrastructure, and Cloud environments.
  3. Monitor vulnerability scanning coverage and coordinate with the IT Department to identify missing, newly added, or decommissioned IT assets and ensure that the scanning scope remains accurate and up to date.
  4. Review and analyze vulnerability scan results and cross-reference with other sources such as the CISA Known Exploited Vulnerabilities (KEV) catalog to identify high-criticality areas for remediation. Identify potential false-positive findings and review with ITD for validity.
  5. Collaborate with ITD to prioritize system vulnerability remediation and patching based on system risk severity, vulnerability exploitability, asset criticality, and potential business impact. 
  6. Track identified vulnerabilities through remediation and/or mitigation, validate remediation through re-scanning or review of appropriate supporting evidence, and generate regular system vulnerability remediation status reports.
  7. Monitor compliance of system vulnerability remediation based on pre-defined risk-based remediation targets. Escalate critical or significant delays of system vulnerability remediation based on pre-defined targets to Management, as necessary.
  8. Create vulnerability management-related reports with risk summaries and recommendations to Management.
  9. Perform risk assessments on proposed new systems to be introduced to the organization.
  10. Perform other duties and responsibilities as assigned by management.

Your Qualifications:

  1. Strong understanding and prior experience working with network components and devices such as Firewalls, IPS, IDS, switches, routers, NDR, and NAC.
  2. Strong understanding and prior experience working with Microsoft Windows-based environments including components such as domain controllers, DHCP, DNS, and Active Directory.
  3. Foundational understanding of Information Security frameworks such as NIST Cybersecurity Framework and SP 800-53 as well as Cyber Risk Institute Profile v2.x 
  4. 3+ Years of experience managing System Vulnerability Management tools such as Qualys or Tenable.
  5. 3+ Years of experience with risk assessment methodologies and techniques
  6. Prior experience with financial industry structure and concepts a plus.
  7. Strong verbal and written communication skills.
  8. Strong analytical skills with attention to detail and accuracy.
  9. Self-motivated with good time management skills.

Why you should join SuMi Trust:SuMi Trust embraces flexible ways of working when the business and role permits. We provide employees with a hybrid working model, allowing for in-office work and work from home. Our diverse and inclusive environment along with our global presence enables us to collaborate and communicate to meet our business needs. We believe that efficient teams need truth, loyalty, and a strong sense of purpose to balance risk and their targets. We make sustainable business decisions to improve our society and the world. We believe that each person brings a unique value that drives the business though their creativity and passion.

  • The Employee Benefits package includes: Paid Time Off, medical, HSA, vision, dental, FSA, 401(k), profit sharing, legal plan, cancer indemnity plan, disability insurance, life insurance, employee assistance program, commuter benefits, business travel accident, paid volunteer day, paid memberships, paid seminars, and tuition assistance.
  • We offer many socialization opportunities for wellness, financial wellbeing, runs/walks, team building, happy hours, and activities to support the Sustainable Developmental Goals.

Check out our LinkedIn for our employee experience:

We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, national origin, disability status, protected veteran status or any other characteristic protected by law. SuMi Trust provides reasonable accommodations for employees and applicants with disabilities consistent with applicable law. If you need a reasonable accommodation during the application

Vacancy posted a month ago
Similar jobs that could be interesting for youBased on the Information Security Risk Analyst in New York, NY vacancy
  •  ...Division” which performs business functions. Information Risk Governance (“IRG”) provides oversight to information and cyber security risk by maintaining and improving branch...  ...Overview: The Security Operations Center (SOC) Analyst is responsible for monitoring, detecting,... 
    Suggested
    Work at office
    Work from home
    Flexible hours
    2 days per week

    SUMITOMO MITSUI TRUST BANK, LIMITED

    New York, NY
    a month ago
  •  ...York, Washington D.C., London and Amsterdam. Team: The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization...  ...focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our... 
    Suggested
    Full time
    Work experience placement
    Local area

    Plaid

    New York, NY
    13 days ago
  • GRC Security Analyst - Information Security At Appfire, we believe that great work happens when people get to choose how they work. After 20 years...  ...issues for our rapidly growing company, including managing risk through a shared vision with Appfire’s business leaders. You... 
    Suggested
    Summer work
    Work at office
    Local area
    Remote work
    Work from home
    Worldwide
    Home office
    Flexible hours

    Appfire

    New York, NY
    2 days ago
  • Principal Duties:Security review background- AI adaption knowledge for security risk review backgroundCore Must-Haves: AI Security expertise - background in AI security reviews and AI adaptation risks Security Risk Assessment - experience with risk management frameworks... 
    Suggested

    Integrated Resources

    New York, NY
    3 days ago
  • Job-ID31409788Reference25-31660Title : SOC Analyst Location : New York City, Boston MA, Atlanta GA Shift : 3PM to 12AM EST Mon -...  ...rotationDescription: The SOC Analyst serves as the first line of defense for information security operationsmonitoring, investigating, and responding to... 
    Suggested
    Shift work

    Axelon

    New York, NY
    3 days ago
  • $75 - $105 per hour

     ...Job Title: Information Security Analyst Term: 12 Month Contract (possible extensions of 12 to 24 months) Work Environment: On-Site Location...  .... Collaborate with internal security, technology, risk, and business teams. Coordinate and communicate with external... 
    Hourly pay
    Contract work

    The Custom Group of Companies

    New York, NY
    4 days ago
  •  ...given global team. Lead and Manage Security Operations: Oversee day-to-day security...  ...testing to identify and mitigate risks. Backup and Patch Management: Manage...  ...industry. Education: Bachelor’s degree in Information Security, Computer Science, or a related... 
    Full time

    PGMTEK Inc.

    New York, NY
    3 days ago
  •  ...Network Security Analyst Job Description: Position requires fully on-site reporting. Provide support for all corporate...  ...are required. The candidate must be knowledgeable of Information Security networking best practices and be able to evaluate... 
    Work experience placement
    Local area
    Rotating shift

    3B Staffing LLC

    New York, NY
    2 days ago
  •  ...Position Title * Information Security Analyst Position Responsibilities Information Security Analyst New York, NY (Hybrid role), look for Nearby...  ...responses to regulatory examiners, auditors, and risk management inquiries Collaborate with cross function teams... 
    Contract work

    Apex Informatics

    New York, NY
    1 day ago
  •  ...Sr Information Security Analyst Strivector Corp is a National Recruiting and Staffing agency established in 2012 and headquartered in Austin, Texas. We are a preferred partner for several Fortune 500 companies nationwide. Strivector has been consistently rated a rare... 
    Full time
    Contract work
    For contractors
    Work at office
    Remote work
    Relocation

    Strivector

    New York, NY
    12 hours ago
  • About the job Job Summary The Information Security Fresher will support the organization's efforts to protect sensitive customer, financial, and...  ...role involves monitoring security controls, assisting in risk assessments, supporting compliance with insurance and regulatory... 
    Internship

    Hacktech

    New York, NY
    4 days ago
  • Fuze Health is seeking a Senior Security Analyst to join our Information Security Team. You will lead comprehensive security testing of our applications, coordinate with vendors, and work with development teams to remediate findings before go-live. The role requires experience... 
    Remote job

    letsgetchecked.com

    New York, NY
    1 day ago
  • $125k - $150k

    NAKA Tech is looking for an IT Security Analyst to support hands-on security operations in a New...  ...security matters to support security risk analysis scenarios and response procedures...  ...enough but imperfect or incomplete information. Strong oral and written communication... 
    Work experience placement

    Cybersecurity Jobs

    New York, NY
    1 day ago
  •  ...Division” which performs business functions. Information Risk Governance (“IRG”) provides oversight to information and cyber security risk by maintaining and improving branch...  ...Overview: The Third Party Information Security Analyst supports the Bank’s Third Party Risk... 
    Work at office
    Work from home
    Flexible hours
    2 days per week

    SUMITOMO MITSUI TRUST BANK, LIMITED

    New York, NY
    a month ago
  •  ...technology environment supporting enterprise security, data protection, and governance...  ...partners closely with cybersecurity, privacy, risk, legal, data governance, and technology groups to strengthen how sensitive information is classified, protected, monitored, and governed... 
    Contract work

    Axiom Path

    New York, NY
    16 days ago
  • Senior Consultant - Epic Security Analyst - Remote Join to apply for the Senior Consultant - Epic...  ...build strategy. Track and document risks and issues. Analyze and document workflows...  ...Full-time Job function Job function Information Technology Industries IT Services and IT... 
    Remote job
    Full time
    Contract work
    Local area

    Nordic Global

    New York, NY
    3 days ago
  • Working remotely in a full-time, exempt capacity, the Senior Information Security Analyst will serve as a first responder to security events, monitor alerts and logs for threats, and collaborate with various teams to enhance the organization's security posture. Key responsibilities... 
    Full time
    Remote work

    Virtual Vocations Inc

    New York, NY
    1 day ago
  • $90k - $105k

     ...Looking For? The Vestwell Corporate Information Technology team is looking for an...  ...meticulous and detail-oriented Information Security compliance analyst to be responsible for monitoring the...  ...You Be Doing? Manage cybersecurity risk processes, including risk registers,... 
    Contract work
    For subcontractor
    Work at office
    Local area

    Vestwell

    New York, NY
    4 days ago
  •  ...improvement of global money movement.About the RoleWe’re hiring a Security Analyst / Program Manager to build and scale Bridge’s security...  ...This is a rare opportunity to design the security governance, risk and compliance programs from the ground up, while also leveraging... 

    Stripe

    New York, NY
    12 hours ago
  • $60k - $80k

    A leading technology company in the US is seeking a Security Analyst to enhance their cybersecurity posture. This role involves monitoring threats, implementing security controls, and collaborating with cross-functional teams. Candidates should have formal education in... 
    Remote job

    ImageTrend

    New York, NY
    3 days ago
  • $160k - $180k

    Technology and Information Security Risk Specialist Vice President | Second Line of Defense Position Summary The Technology and Information Security Risk Specialist provides independent Second Line oversight of the Bank’s technology infrastructure, information security,... 
    Work at office
    Local area

    IDB Bank

    New York, NY
    12 hours ago
  •  ...RoleSuccess Academy is growing rapidly and security is at the forefront of enabling that...  .... We are seeking a Senior Security Analyst to join our Information Security & Privacy team. This...  ...CrowdStrike, proactively identifying risks, leading investigations, driving remediation... 
    Work at office
    Immediate start
    Remote work
    Visa sponsorship
    Monday to Friday

    Success Academy Charter Schools

    New York, NY
    1 day ago
  • $97.59k - $142.99k

     ...National Institutes of Health.For more information, go toNYU Langone Health, and interact...  ...opportunity to join our team as a Sr. II Security Analyst - Vulnerabilities. In this role, the...  ...ownersAnalyze threat intelligence reports, write risk analysis report for zero-day critical... 
    Full time

    NYU Langone Medical Center

    New York, NY
    3 days ago
  • $98.96k - $148.44k

     ...CitiThe Sec & Derivatives Sr Analyst is an intermediate level position...  ...and investigation of client securities and derivatives transactions....  ...assess risk when business decisions are made...  ...paid holidays. For additional information regarding Citi employee benefits... 
    Full time

    Citigroup

    New York, NY
    4 days ago
  • Job-ID29435394Reference26-01778Junior Security AnalystJob Number: 26-01778Want to be part...  ...ECLARO is looking for a Junior Security Analyst for our client in New York, NY. ECLARO...  ...Orientation, National Origin, Age, Genetic Information, Disability, Protected Veteran Status,... 

    Eclaro International

    New York, NY
    5 hours ago
  • $135k - $140k

     ...uniquely Richemont Americas. Senior Security Operation Center (SOC) Analyst - L2Cyber | New York, NYReports to:...  ...teams, including IT, security risk, forensics, and legal, to ensure a...  ...effectively communicate technical information to both technical and non-technical... 
    Permanent employment
    Full time
    Local area
    Flexible hours

    Richemont

    New York, NY
    3 days ago
  • $129.84k - $194.76k

     ...CitiThe Sec & Derivatives Lead Analyst is a senior level position...  ...and investigation of client securities and derivatives transactions....  ...work and budget, and mitigate risks vEnsure satisfactory completion...  ...holidays. For additional information regarding Citi employee benefits... 
    Full time

    Citigroup

    New York, NY
    4 days ago
  • $145k - $170k

    CLEAR is building THE secure identity company of the future. Our mission...  ...a Senior Security Operations Analyst III to join our SOC team to...  ...root causes, communicate risk, and drive timely remediation...  ...to validate findings and make informed decisionsSolving complex security... 
    Casual work
    Work at office
    Flexible hours

    Secure Identity

    New York, NY
    4 days ago
  •  ...Hudson Yards, NYC/Remote Key Responsibilities Vulnerability Analysis & Risk Assessment Review vulnerabilities identified through AI-based SAST, SCA, and related application security tools. Evaluate vulnerabilities beyond vendor-assigned severity scores by... 
    Contract work
    Remote work

    Perennial Resources International

    New York, NY
    12 hours ago
  •  ...confidential search on behalf of a client - a well-established global IT services and business consulting firm - to place a Security & Compliance Analyst with one of their enterprise customers, a regulated organization based in South Carolina. This is a 6-month contract... 
    Hourly pay
    Contract work
    Remote work

    E-Frontiers

    New York, NY
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Information Security Risk Analyst. Be the first to apply!