Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Information Security Analyst

Bank of the Orient

Bank of the Orient is an independent Asian Community Bank that has proudly served the financial needs of multiple Bay Area communities for over 55 years and the Texas area. We are committed to excellence in everything we do. We have an opening for the Information Security Analyst supports the operation, monitoring, maintenance, and continuous improvement of the Bank's information security, cybersecurity risk, privacy, technology risk, and third-party risk programs. The role works across security operations, identity and access management, vulnerability management, incident response, cloud and SaaS security, data protection, business continuity/cyber resilience, security awareness, and governance, risk and compliance (GRC). The Analyst also supports the secure adoption and oversight of artificial intelligence (AI), including generative AI and large language model (LLM) technologies, and may serve as backup administrator for selected security and banking applications as needed. ESSENTIAL DUTIES: Support the maintenance and continuous improvement of the Bank's Information Security, Cybersecurity, Technology Risk, Privacy, GRC, Third-Party Risk Management, and Business Continuity/Cyber Resilience programs in alignment with the Bank's risk appetite, policies, and applicable regulatory requirements. Monitor and analyze security events, alerts, logs, and telemetry from endpoints, servers, networks, identity platforms, cloud/SaaS services, email, and other critical systems. Triage, investigate, document, and elevate suspicious activity in accordance with established procedures and service-level expectations. Support security operations technologies such as SIEM/SOAR, EDR/XDR, network security, email security, cloud security, and threat intelligence platforms; assist with alert tuning, use-case development, log-source onboarding, and operational health monitoring. Perform and coordinate vulnerability and exposure management activities, including vulnerability scanning, risk-based prioritization, configuration reviews, patch/remediation tracking, penetration-test findings, security exceptions, and validation of corrective actions. Participate in and coordinate cybersecurity incident response activities, including phishing/business email compromise, credential compromise, malware/ransomware, data exposure, cloud/SaaS incidents, and AI-related security events. Support evidence collection, root-cause analysis, lessons learned, tabletop exercises, and post-incident improvement actions. Support identity and access management (IAM) controls, including multi-factor authentication (MFA), role-based access control (RBAC), privileged access, joiner/mover/leaver processes, periodic access certifications, service accounts, and segregation of duties for critical banking and technology systems. Assist with data security and privacy controls, including information classification, encryption, data loss prevention (DLP), secure file transfer, retention, sensitive-data handling, and monitoring of non-public customer and Bank information. Support security reviews for technology projects, system changes, cloud/SaaS implementations, APIs, integrations, digital banking capabilities, and new vendors. Document security requirements, identify risks/control gaps, and track remediation through implementation. Support secure cloud and modern infrastructure practices, including security configuration and monitoring for Microsoft 365, Azure and/or AWS environments, SaaS applications, remote access, Zero Trust principles, endpoint/device security, and secure network connectivity. Support the Bank's AI security and governance program. Perform security and risk assessments for AI/GenAI use cases and vendors; evaluate risks such as sensitive-information disclosure, prompt injection, insecure output handling, excessive agency, model/supply-chain risk, unauthorized data use, and inadequate logging or access control; and help implement appropriate guardrails, monitoring, human oversight, and acceptable-use requirements. Monitor the use of approved AI-enabled tools and services, where applicable, and support controls for enterprise AI platforms such as Microsoft 365 Copilot, Azure OpenAI, ChatGPT Enterprise, AWS Bedrock, Google Gemini, or equivalent technologies. Assist with evaluation of AI-enabled cybersecurity tools for accuracy, access, data handling, and operational risk. Support third-party/vendor risk management across onboarding, due diligence, contracting, ongoing monitoring, risk assessment, issue remediation, renewal, and termination. Review security documentation such as SOC reports, penetration-test summaries, business continuity information, cyber insurance, privacy practices, subcontractors/fourth parties, and AI/model-provider dependencies where relevant. Collaborate with business owners, Technology, Compliance, Risk, Audit, Operations, and other stakeholders to ensure technology and vendor risks are identified, documented, accepted or remediated, and supported by appropriate controls. Support cybersecurity threat intelligence and threat-informed defense activities using authoritative sources and industry information-sharing channels. Map relevant threats and incidents to recognized frameworks such as MITRE ATT&CK when useful for investigation, control improvement, or reporting. Conduct and coordinate security awareness activities, including phishing simulations, role-based training, emerging-threat communications, secure use of AI/GenAI, social-engineering awareness, and targeted education for employees, contractors, and third parties. Maintain security policies, standards, procedures, risk registers, control evidence, issue trackers, inventories, diagrams, and other documentation. Support regulatory examinations, internal/external audits, risk assessments, and management responses. Develop and analyze cybersecurity metrics, dashboards, key risk indicators (KRIs), control-performance reports, and executive-level materials to identify trends, highlight material risks, and support management decision-making. Maintain current knowledge of cybersecurity threats, AI security risks, privacy and security laws, regulatory guidance, and industry practices relevant to financial institutions. Support alignment, as appropriate, with frameworks such as FFIEC guidance, GLBA, NIST Cybersecurity Framework (CSF) 2.0, NIST AI Risk Management Framework, CIS Controls, and OWASP guidance. Serve as backup security/application administrator for selected Bank systems as assigned, including Fiserv Premier and related applications, with responsibilities focused on secure configuration, access administration, periodic access reviews, logging, and least-privilege controls. Support other operational systems (such as EZ Teller, Business Analytics, or Enterprise Output Manager) when security, access, resilience, or controlled file-transfer support is required. Demonstrate quality customer service with internal and external stakeholders, actively participate in required Bank and compliance training, maintain strict confidentiality of non-public information, and comply with all applicable Bank policies, security requirements, and banking laws and regulations. Perform other duties and special projects as assigned. REQUIREMENTS: Bachelor's degree in Cybersecurity, Information Security, Information Technology, Computer Science, Management Information Systems, or a related discipline; or four (4) or more years of equivalent relevant work experience. Two (2) or more years of experience in information security, cybersecurity operations, technology risk, systems/network administration, IT audit, GRC, or a related technology role is preferred. Experience in banking, financial services, or another regulated environment is strongly preferred. Working knowledge of Windows and Linux operating systems, TCP/IP, DNS, firewalls, VPN/remote access, Active Directory/identity services, Microsoft 365, endpoint management, cloud/SaaS concepts, and common enterprise security architectures. Practical experience with security monitoring, vulnerability management, incident response, IAM/access reviews, third-party risk, security awareness, or GRC activities. Experience across multiple areas is preferred; deep specialization in every area is not required. Knowledge of financial-services cybersecurity and privacy expectations, including GLBA and FFIEC guidance, and working familiarity with recognized security frameworks such as NIST CSF 2.0, CIS Controls, MITRE ATT&CK, and incident-response practices. Working knowledge of AI/GenAI security concepts and risks, with familiarity with resources such as the NIST AI Risk Management Framework and OWASP guidance for LLM/GenAI applications. Direct enterprise AI security experience is preferred but not required. Experience with reporting, data analysis, or query tools such as SQL, Power BI, Excel, or equivalent is preferred. Basic scripting/automation experience with PowerShell, Python, APIs, or workflow/SOAR tools is a plus. Familiarity with Fiserv Premier or other core banking/application security administration is a plus. PREFERRED CERTIFICATIONS: CompTIA Security+, CySA+, SSCP, GSEC, CISA, CISSP, GIAC certifications, Microsoft/Azure or AWS security certifications, or comparable credentials are preferred depending on experience level. The candidate will be subject to investigation through credit checks, reference checks, background checks and fingerprinting checks performed at the time permissible under relevant law. Visit our website at: for additional information. Bank of the Orient is proud to be an Affnitive Action, Equal Opportunity Employer. #J-18808-Ljbffr Bank of the Orient

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Information Security Analyst in Millbrae, CA vacancy
  • Information Security Analyst Location: San Francisco, CA; Los Angeles, CA; Salt Lake City, Utah Duration: 12+ Months, 5 days onsite Must Have: SPL that Splunk uses Actual incident tickets - resolve actual security incident tickets Qualifications: Bachelor's degree... 
    Suggested
    Contract work
    Work at office

    Compunnel Inc.

    San Francisco, CA
    1 day ago
  • $118.68k - $175.8k

     ...offices in New York, Washington D.C., London and Amsterdam.Team:The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s...  ..., focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission... 
    Suggested
    Work experience placement
    Work at office
    Local area

    Plaid Financial

    San Francisco, CA
    2 days ago
  • $150k - $180k

     ...one of the world's largest construction and engineering companies. We are hiring a Senior IT Security Analyst to serve as the hands-on technical lead for NARHQ's information security program. The role is onsite full-time (5 days/week). The successful candidate will own... 
    Suggested
    Full time
    For contractors
    Work at office
    Local area
    Flexible hours

    Obayashi

    Foster, CA
    3 days ago
  •  ...appropriate union. The Cybersecurity Awareness Analyst leads the design and execution of the organization’s security awareness and training programs in support of...  ...analysis Establishing policies and standards for information security Providing guidance and conducting... 
    Suggested
    Work experience placement
    Worldwide

    University of California , San Francisco

    San Francisco, CA
    2 days ago
  •  ...Telecom, Energy, Pharmaceutical, Financial, Manufacturing, Information Technology, Government, Entertainment, and more. Our core competencies...  .... Job Description JOB DETAILS: Job title: Info Security Analyst Location : 6 months Potential to extend duration Duration:... 
    Suggested
    Flexible hours

    Softpath System

    Redwood City, CA
    3 days ago
  • $209.25k - $271.71k

     ...civil shared experiences for everyone.As a member of the Roblox Security Governance, Risk, and Compliance (GRC) team, you will play a...  ...security organization — empowering every builder to make risk-informed decisions by establishing a portfolio of governing policies and... 
    Full time
    Work experience placement
    H1b
    Work at office
    Local area
    Visa sponsorship
    Monday to Friday

    Roblox

    San Mateo, CA
    11 hours ago
  • $117.2k - $176.7k

     ...! Agentforce is the future of AI, and you are the future of Salesforce.The ExperienceEnterprise Security is looking for a Senior Analyst to support our Business Information Security Officers (BISOs) in their day-to-day work with Enterprise business unit customers. BISOs... 
    Full time

    Salesforce

    San Francisco, CA
    2 days ago
  • $123.7k - $254.67k

     ...our recruiting process here.Pinterest’s Security team (Pinfosec) is seeking an IC14 Security...  ..., Risk & Compliance (GRC Senior Analyst) to support and strengthen our security...  ...working cross-functionally and gathering information or evidence from technical and non-technical... 
    Interim role
    Work at office
    Local area
    Relocation
    Relocation package

    Pinterest

    San Francisco, CA
    2 days ago
  • $144k - $162k

     ...playing games. Discord's Legal team is growing its Security GRC function, and we're looking for a Security Analyst to help run and scale it. You'll own the day-to-...  ...Discord’s collection and usage of personal information relating to the application and recruitment process... 
    Full time
    Work at office
    Immediate start
    Relocation
    Relocation package
    2 days per week

    Discord

    San Francisco, CA
    3 days ago
  • $1,750 - $2,150 per month

    Role Overview Mercor is partnering with leading AI labs to engage experienced cybersecurity professionals — security analysts, penetration testers, incident responders, threat intelligence specialists, and security architects — to improve AI systems' reasoning around threat... 
    Remote job
    Hourly pay

    Obsidian

    San Francisco, CA
    3 days ago
  • $151.05k - $166.95k

     ...About the role Point Digital Finance is expanding its Information Security function, and this is the team's first dedicated monitoring...  ...immediate, measurable impact. As Senior Security Operations Analyst (Detection & Response), you will be the second half of an incident... 
    Temporary work
    Work experience placement
    Immediate start
    Remote work
    Home office
    Flexible hours
    2 days per week
    3 days per week
    1 day per week

    Point Digital Finance, Inc.

    San Francisco, CA
    5 days ago
  •  ...Job Description Job Description Job43 – EITS Security Risk Analyst B (Engagement) Location: 100% Remote Max Submissions: 5 Proposed...  ...efforts. Act as a subject matter expert (SME) on information security and regulatory compliance. Key Responsibilities... 
    Immediate start
    Remote work
    Flexible hours

    DELTASOFT SOLUTIONS LLC

    San Francisco, CA
    19 days ago
  •  ...in our Allergan Aesthetics portfolio. For more information about AbbVie, please visit us at . Follow @abbvie...  .... Job Description Working in the Border Security operations space, the Associate Border Security Analyst performs the day-to-day operations on Firewalls,... 
    Full time
    Temporary work
    Local area
    Weekend work

    AbbVie

    San Francisco, CA
    1 day ago
  • $135k - $180k

     ...sensitive AI-powered platform that includes solutions for video security, access control, air quality sensors, alarms, intercoms, and...  ...Communications teams. You will also partner closely with Verkada’s Chief Information Security Officer (CISO) and Chief Privacy Officer. This role... 
    Full time
    Work at office
    Work visa
    Flexible hours
    Shift work

    Verkada

    San Mateo, CA
    10 hours ago
  • $90k - $100k

     ...access for millions more.  Watch our story and see why we do what we do . What we are looking for:  We’re looking for a Security Analyst to help keep Forage’s security and compliance programs running smoothly as we scale. You’ll own the operational backbone of our... 
    Work at office

    Forage

    San Francisco, CA
    more than 2 months ago
  • $265k - $356k

     ...for related fees.Fraud AlertTo all candidates: your personal information and online safety are a top priority for us. At Structure Therapeutics...  ...account information or sensitive information like social security numbers. If you are unsure if a message is from Structure... 
    Contract work

    Structure Therapeutics

    South San Francisco, CA
    4 days ago
  • $280k - $320k

    Security at most companies is reactive. A checkbox for auditors. A speed bump for engineers. A department that says no. That's not what...  ...is to take it further. You'll own Sendbird's comprehensive information security programs, manage and evolve our compliance frameworks... 
    Temporary work
    Work at office
    Flexible hours
    3 days per week

    Sendbird

    San Mateo, CA
    2 days ago
  • $140.9k - $261.7k

     ...innovation areas via research while ensuring all engineering and AI frameworks maintain absolute compliance with data privacy and security regulations like HIPAA and GDPR.Who You AreEducational & Professional Foundation: You hold a Master’s or PhD in Computer Science,... 
    Full time
    Local area

    Genentech

    South San Francisco, CA
    2 days ago
  • $105.4k - $207.8k

    Position Summary Cisco Network Security Engineer/ Senior Consultant, Strategy, Growth, and TransformationDeloitte’s Cyber business...  ...architectures, integrating Cisco platforms with security information and event management (SIEM) tools and automation solutions, and... 
    Work experience placement
    Local area
    Visa sponsorship

    Deloitte

    San Francisco, CA
    3 days ago
  • $97.9k - $181.7k

     ...innovation areas via research while ensuring all engineering and AI frameworks maintain absolute compliance with data privacy and security regulations like HIPAA and GDPR. Who you are: You hold a Bachelor’s or Master’s degree in Data Science, Informatics, Life Sciences... 
    Work experience placement
    Local area
    Relocation package

    Genentech

    South San Francisco, CA
    3 days ago
  • $68 - $78 per hour

     ...JOB TITLE: Product Data Analyst LOCATION: Foster City, CA (Hybrid; 3 days in office/week) PAY RANGE: $68 - 78/hr. DURATION: 6...  ...feedback we receive from riders with our service capabilities to inform the Product roadmap and feature prioritization.... 
    Hourly pay
    Full time
    Work at office
    3 days per week

    Ursus Inc

    San Mateo, CA
    3 days ago
  • $210k - $250k

    About the Role:PubMatic is seeking a Director of Information Security to lead and evolve our global security program across enterprise infrastructure, cloud platforms, products, corporate systems, and emerging AI technologies. Executive Communication Strong command of... 
    Work at office
    Remote work

    PubMatic

    Redwood City, CA
    11 hours ago
  •  ...trustworthy at the source. Drive the self-service experience — so analysts and data scientists can discover, access, and use data in tools...  ...vs. the lake. Align data engineering, analytics, data science, security, and business stakeholders around a shared platform vision.... 
    Flexible hours

    Asurion

    San Mateo, CA
    2 days ago
  • Genentech in South San Francisco is seeking a PX Governance & Portfolio Analyst to consolidate the enterprise Patient Experience portfolio, track milestones, dependencies, risks, and post-launch integrations. You will develop governance materials for senior leadership,... 

    Genentech

    South San Francisco, CA
    1 day ago
  • Arc70 is seeking a Portfolio Analyst to join its Portfolio Management team in Burlingame, CA. Ideal candidates will have 2-5+ years of experience working in real estate investments or asset management, familiarity with affordable housing, and distressed workouts. This role... 
    Temporary work

    Arc70 Capital LLC

    Burlingame, CA
    5 days ago
  • $141k - $205k

     ...and Finance leadership. Clearly communicate complex financial information and provide actionable recommendations.Minimum qualifications:...  ..., financial narrative development, and ROI analysis.Financial Analysts ensure that Google makes sound financial decisions. As a Financial... 

    Google

    San Bruno, CA
    2 days ago
  • $152.7k - $294k

     ...diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. The Global Information Security Strategist is a senior role responsible for shaping and implementing the long-term information security strategy of the firm... 
    Summer holiday
    Local area
    Flexible hours
    Shift work

    EY

    San Francisco, CA
    3 days ago
  • $225.8k - $282.3k

     ...governance and risk-management experience with sufficient technical fluency to work effectively with Data, Engineering, Product, Information Security, Legal, Compliance, and business teams. This person should be comfortable building in a fast-moving environment and... 

    Mercury

    San Francisco, CA
    1 day ago
  • $23.5 per hour

     ...Target Security SpecialistStarting Hourly Rate / Salario por Hora Inicial: $23.50 USD per hourWorking at Target means helping all families discover the joy of everyday life. We bring that vision to life through our values and culture. Learn more about Target here.Assets... 
    Hourly pay
    Local area
    Flexible hours
    Shift work
    Night shift
    Day shift

    Target

    San Mateo, CA
    2 days ago
  • $146.54k - $189.64k

     ...ready across systems and data domains.Leads and governs DOJ Data Security Program (DSP) IAM controls, including definition,...  ...Job Qualifications:Bachelor’s degree plus 6+ years of IT and/or Information Security experience.Strong experience owning and operating IAM... 
    Full time
    For contractors
    Local area

    GILEAD Sciences

    Foster, CA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Information Security Analyst. Be the first to apply!