Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Information Security Risk Analyst

SUMITOMO MITSUI TRUST BANK, LIMITED

Job Description

Job Description

This role is located in New York City and will require a hybrid work schedule of at least 2 days in office per week.

This role is for Officer level candidates.

About the Bank:Sumitomo Mitsui Trust Bank, Limited was established through the merger of The Sumitomo Trust and Banking Co., Ltd with Chuo Mitsui Trust and Banking, Ltd. on April 1, 2012. We are one of the largest asset managers in Asia and number one among Japanese financial institutions by AUM, with approximately $850 Billion USD in AUM. The Bank provides an assortment of financial solutions and manages a broad spectrum of financial products across its global branches.

Department Overview:

The Americas Division (“AD”) was established in the Sumitomo Mitsui Trust Bank, Limited, New York Branch) (“SMTBNY”) to perform corporate functions and supervise U.S. entities. Established under the AD are the “Global Banking Unit (“GBU”), Americas Division” and “Global Markets Unit (“GMU”), Americas Division” which performs business functions. Information Risk Governance (“IRG”) provides oversight to information and cyber security risk by maintaining and improving branch wide framework that is in-line with the Head Office and regulatory requirements and addresses Confidentiality, Integrity, and Availability for information assets. IRG establishes appropriate policies, procedures, measurement, and monitoring processes to proactively assess and evaluate and cyber security and information security risks inherent in the Branch Operations. IRG is directly involved in all information and cyber security related projects, matters and issues.

Your Role Overview:

The Information Security Risk Analyst is responsible for supporting the organization’s vulnerability management program and performing assigned information security risk assessments. This role will perform the day-to-day vulnerability management activities, perform risk-based analysis of identified vulnerabilities, coordinate remediation efforts with the IT Department, and help ensure systems are maintained in accordance with the organization’s information security standards.

Your Duties and Responsibilities:

  1. Administer and support the organization’s system vulnerability management program.
  2. Conduct regular vulnerability scans across servers, endpoints, applications, network infrastructure, and Cloud environments.
  3. Monitor vulnerability scanning coverage and coordinate with the IT Department to identify missing, newly added, or decommissioned IT assets and ensure that the scanning scope remains accurate and up to date.
  4. Review and analyze vulnerability scan results and cross-reference with other sources such as the CISA Known Exploited Vulnerabilities (KEV) catalog to identify high-criticality areas for remediation. Identify potential false-positive findings and review with ITD for validity.
  5. Collaborate with ITD to prioritize system vulnerability remediation and patching based on system risk severity, vulnerability exploitability, asset criticality, and potential business impact.
  6. Track identified vulnerabilities through remediation and/or mitigation, validate remediation through re-scanning or review of appropriate supporting evidence, and generate regular system vulnerability remediation status reports.
  7. Monitor compliance of system vulnerability remediation based on pre-defined risk-based remediation targets. Escalate critical or significant delays of system vulnerability remediation based on pre-defined targets to Management, as necessary.
  8. Create vulnerability management-related reports with risk summaries and recommendations to Management.
  9. Perform risk assessments on proposed new systems to be introduced to the organization.
  10. Perform other duties and responsibilities as assigned by management.

Your Qualifications:

  1. Strong understanding and prior experience working with network components and devices such as Firewalls, IPS, IDS, switches, routers, NDR, and NAC.
  2. Strong understanding and prior experience working with Microsoft Windows-based environments including components such as domain controllers, DHCP, DNS, and Active Directory.
  3. Foundational understanding of Information Security frameworks such as NIST Cybersecurity Framework and SP 800-53 as well as Cyber Risk Institute Profile v2.x
  4. 3+ Years of experience managing System Vulnerability Management tools such as Qualys or Tenable.
  5. 3+ Years of experience with risk assessment methodologies and techniques
  6. Prior experience with financial industry structure and concepts a plus.
  7. Strong verbal and written communication skills.
  8. Strong analytical skills with attention to detail and accuracy.
  9. Self-motivated with good time management skills.

Why you should join SuMi Trust:SuMi Trust embraces flexible ways of working when the business and role permits. We provide employees with a hybrid working model, allowing for in-office work and work from home. Our diverse and inclusive environment along with our global presence enables us to collaborate and communicate to meet our business needs. We believe that efficient teams need truth, loyalty, and a strong sense of purpose to balance risk and their targets. We make sustainable business decisions to improve our society and the world. We believe that each person brings a unique value that drives the business though their creativity and passion.

  • The Employee Benefits package includes: Paid Time Off, medical, HSA, vision, dental, FSA, 401(k), profit sharing, legal plan, cancer indemnity plan, disability insurance, life insurance, employee assistance program, commuter benefits, business travel accident, paid volunteer day, paid memberships, paid seminars, and tuition assistance.
  • We offer many socialization opportunities for wellness, financial wellbeing, runs/walks, team building, happy hours, and activities to support the Sustainable Developmental Goals.

Check out our LinkedIn for our employee experience:

We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, national origin, disability status, protected veteran status or any other characteristic protected by law. SuMi Trust provides reasonable accommodations for employees and applicants with disabilities consistent with applicable law. If you need a reasonable accommodation during the application

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Information Security Risk Analyst in New York, NY vacancy
  •  ...Division” which performs business functions. Information Risk Governance (“IRG”) provides oversight to information and cyber security risk by maintaining and improving branch...  ...Overview: The Security Operations Center (SOC) Analyst is responsible for monitoring, detecting,... 
    Suggested
    Work at office
    Work from home
    Flexible hours
    2 days per week

    SUMITOMO MITSUI TRUST BANK, LIMITED

    New York, NY
    1 day ago
  • Job Description The Security Risk & Compliance Analyst supports the organization’s global information security program by assisting in the identification, assessment, and management of information security risks and compliance demands across Victaulic’s entire organization... 
    Suggested
    Work at office

    Victaulic

    New York, NY
    3 days ago
  •  ...York, Washington D.C., London and Amsterdam. Team: The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security...  ...focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission... 
    Suggested
    Full time
    Work experience placement
    Local area

    Plaid

    New York, NY
    9 days ago
  • Maritz is seeking an Information Security Analyst II to drive security assessments, enforce corporate standards, and manage vulnerabilities in a virtual...  ...supports internal stakeholders with security questions and risk assessments, and coordinates audits with clients and... 
    Suggested
    Remote job

    Maritz

    New York, NY
    1 day ago
  • Mercury is seeking an Information Security GRC Analyst to mature security, risk, and compliance programs and build guardrails for business continuity and resilience. You will lead risk assessments, partner with cross‑functional teams, and drive audit readiness across SOC... 
    Suggested

    Embedded Shishya

    New York, NY
    2 days ago
  • Principal Duties:Security review background- AI adaption knowledge for security risk review backgroundCore Must-Haves: AI Security expertise - background in AI security reviews and AI adaptation risks Security Risk Assessment - experience with risk management frameworks... 

    Integrated Resources

    New York, NY
    3 days ago
  • Job-ID31409788Reference25-31660Title : SOC Analyst Location : New York City, Boston MA, Atlanta GA Shift : 3PM to 12AM EST Mon -...  ...rotationDescription: The SOC Analyst serves as the first line of defense for information security operationsmonitoring, investigating, and responding to... 
    Shift work

    Axelon

    New York, NY
    3 days ago
  •  ....C., London and Amsterdam. About the Team: The Security Governance, Risk, and Compliance (GRC) team is part of Plaid's security organization...  ...focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our... 
    Contract work
    Work experience placement
    Local area

    PLAID

    New York, NY
    1 day ago
  • $87k - $92k

     ...Information Security Analyst Posting Details Job # 042836 Department Code 20703-6034 Department Information Technology Services Job Title Information...  ...program, including scan configuration, finding analysis, risk prioritization based on exploitability and business impact,... 
    Full time
    Summer work
    Remote work

    Syracuse University

    New York, NY
    4 days ago
  •  ...We are looking for an IT Security Analyst to help protect enterprise systems, data, and cloud...  ...threats. This role focuses on identifying risk, detecting abnormal behavior,...  ...incidents, and improvement initiatives. Stay informed on attacker techniques, industry trends... 

    The Phoenix Group

    New York, NY
    12 hours ago
  •  ...operational processes necessary to attain and maintain security authorizations and certifications supporting State, Local...  ...requirements. The individual will be experienced in information security governance, risk management, compliance, authorization package development... 
    For contractors
    Work experience placement
    Work at office
    Local area

    Presidio

    New York, NY
    12 hours ago
  • Success Academy Charter Schools seeks a Security Analyst to advance our information security and privacy program within a K‑12 environment. The role is hands‑on across security operations, endpoints, cloud security, DLP, and compliance, reporting to the Head of Security... 

    Successacademycharterschool

    New York, NY
    2 days ago
  • Success Academy Charter Schools is seeking a Senior Security Analyst to join their Information Security & Privacy team in New York City. This role is essential in building and operationalizing security programs within a rapidly expanding network of public charter schools... 

    Successacademycharterschool

    New York, NY
    3 days ago
  •  ...Cybersecurity/Information Security Analyst About the job Cybersecurity/Information Security Analyst Job Title: Cybersecurity / Information Security...  ...regulatory requirements. This role is instrumental in assessing risk, managing vulnerabilities, monitoring threats, and... 
    Full time
    Work experience placement
    Remote work
    Flexible hours

    Bee On The Job

    New York, NY
    3 days ago
  • $65k - $75k

     ...Position Details Advertising/Posting Title Security Operations Analyst Posting Summary Conduct in-depth...  ..., integrity, and availability of information within the University of Vermont’s digital...  ...document and remediate incidents and risks to the University. Minimum... 
    Full time
    Work at office
    Remote work
    Afternoon shift

    University of Vermont

    New York, NY
    2 days ago
  • Senior Consultant - Epic Security Analyst - Remote Join to apply for the Senior Consultant - Epic...  ...build strategy. Track and document risks and issues. Analyze and document workflows...  ...Full-time Job function Job function Information Technology Industries IT Services and IT... 
    Remote job
    Full time
    Contract work
    Local area

    Nordic Global

    New York, NY
    3 days ago
  • $65 - $75 per hour

     ...message the job poster from Insight Global Title: Senior Information Security Analyst Location: 100% Remote Pay Rate: $70-$75/hr Key Responsibilities...  ...gaps and recommend remediation strategies to mitigate risks. Collaborate with IT, DevOps, and business units to implement... 
    Contract work
    Remote work

    Insight Global

    New York, NY
    3 days ago
  •  ...excellence and genuine care for the people making it possible. The Information Security Analyst II performs necessary activities to assess, inform and...  ...concerns. Respond to client security questionnaires and risk assessments. Perform vendor and third-party risk assessments... 
    Full time
    Flexible hours

    Maritz

    New York, NY
    1 day ago
  • $85.2k - $115k

     ...platform, built to support flexible, secure, work-from anywhere experiences. We integrate...  ...privacy. What You’ll Do As an Information Security Analyst, you will be a subject matter expert in...  ...workflows to enhance efficiency and reduce risk. What You’ll Bring You should have a... 
    Work experience placement
    Local area
    Worldwide
    Flexible hours

    Omnissa, LLC

    New York, NY
    3 days ago
  • $100k - $121k

     ...complex challenges in science, security and sustainability. Our...  ...continents. The Data Security Analyst specializes in securing enterprise...  ...and recertifications. Risk Assessment, Auditing & Monitoring...  ...to present complex technical information to a non-technical audience.... 
    Hourly pay
    Contract work
    Local area

    Amentum

    New York, NY
    3 days ago
  •  ...implementing and maintaining security controls in compliance with FISMA...  ...Moderate baselines. Support Risk Management Framework (RMF)...  ...elevate findings to senior analysts. Assist in validating encryption...  ...’s degree in Cybersecurity, Information Systems, Computer Science, or... 
    For contractors
    Local area
    Remote work

    Page Mechanical Group, Inc.

    New York, NY
    2 days ago
  • Syracuse University is seeking an Information Security Analyst to join the Information Security group within ITS. The role defends university data assets through policy controls, security operations, incident response, and AI-assisted tooling in a SOC environment. The... 

    Syracuse University

    New York, NY
    4 days ago
  • IT Information Security Operation Analyst New York, United States | Posted on 03/06/2025 City New York State/Province New York Country United States About...  ...audits and penetration testing to identify and mitigate risks. Backup and Patch Management: Manage backup and... 
    Full time

    PGM Tek

    New York, NY
    1 day ago
  •  ...Division” which performs business functions. Information Risk Governance (“IRG”) provides oversight to information and cyber security risk by maintaining and improving branch...  ...Overview: The Third Party Information Security Analyst supports the Bank’s Third Party Risk... 
    Work at office
    Work from home
    Flexible hours
    2 days per week

    SUMITOMO MITSUI TRUST BANK, LIMITED

    New York, NY
    1 day ago
  • $78.9k - $123.3k

     ...environment. This role is responsible for managing the security authorization lifecycle for one or more information systems, ensuring compliance with Federal...  ...more information systems in accordance with Federal Risk Management Framework (RMF) requirements. Coordinate... 
    Permanent employment
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Noblis

    New York, NY
    1 day ago
  • Plaid Inc. is seeking an experienced security risk professional to lead end-to-end vendor risk assessments and manage the third-party risk lifecycle. You will evaluate security postures of customers, vendors, and partners onboarding to Plaid’s platform, ensuring high standards... 

    Plaid Inc

    New York, NY
    1 day ago
  • $60k - $80k

    A leading technology company in the US is seeking a Security Analyst to enhance their cybersecurity posture. This role involves monitoring threats, implementing security controls, and collaborating with cross-functional teams. Candidates should have formal education in... 
    Remote job

    ImageTrend

    New York, NY
    3 days ago
  • Okta is seeking a Senior Analyst within Customer Assurance to prioritize and respond to security due‑diligence requests. You will bridge customers and internal engineering, ensuring clear security posture communication. The role includes training regional sales teams and... 

    Okta

    New York, NY
    2 days ago
  • Aqua America, Inc. is looking for a GRC Security Analyst II in Pennsylvania to ensure the security and integrity of our information systems. Key responsibilities include managing risk assessments, developing security compliance frameworks, and ensuring that security practices... 

    Aqua America, Inc.

    New York, NY
    2 days ago
  •  ...Care District of Palm Beach County is seeking a Data Privacy & Security Analyst to support the Compliance, Privacy & Ethics Program. The role assists the VP/Chief Compliance and Privacy Officer, conducts risk assessments, audits, and evidence collection for HIPAA, NIST... 
    Remote work

    Remote Jobs

    New York, NY
    12 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Information Security Risk Analyst. Be the first to apply!