Information Security Analyst
Bank of the Orient
Bank of the Orient is an independent Asian Community Bank that has proudly served the financial needs of multiple Bay Area communities for over 55 years and the Texas area. We are committed to excellence in everything we do. We have an opening for the Information Security Analyst supports the operation, monitoring, maintenance, and continuous improvement of the Bank's information security, cybersecurity risk, privacy, technology risk, and third-party risk programs. The role works across security operations, identity and access management, vulnerability management, incident response, cloud and SaaS security, data protection, business continuity/cyber resilience, security awareness, and governance, risk and compliance (GRC). The Analyst also supports the secure adoption and oversight of artificial intelligence (AI), including generative AI and large language model (LLM) technologies, and may serve as backup administrator for selected security and banking applications as needed. ESSENTIAL DUTIES: Support the maintenance and continuous improvement of the Bank's Information Security, Cybersecurity, Technology Risk, Privacy, GRC, Third-Party Risk Management, and Business Continuity/Cyber Resilience programs in alignment with the Bank's risk appetite, policies, and applicable regulatory requirements. Monitor and analyze security events, alerts, logs, and telemetry from endpoints, servers, networks, identity platforms, cloud/SaaS services, email, and other critical systems. Triage, investigate, document, and elevate suspicious activity in accordance with established procedures and service-level expectations. Support security operations technologies such as SIEM/SOAR, EDR/XDR, network security, email security, cloud security, and threat intelligence platforms; assist with alert tuning, use-case development, log-source onboarding, and operational health monitoring. Perform and coordinate vulnerability and exposure management activities, including vulnerability scanning, risk-based prioritization, configuration reviews, patch/remediation tracking, penetration-test findings, security exceptions, and validation of corrective actions. Participate in and coordinate cybersecurity incident response activities, including phishing/business email compromise, credential compromise, malware/ransomware, data exposure, cloud/SaaS incidents, and AI-related security events. Support evidence collection, root-cause analysis, lessons learned, tabletop exercises, and post-incident improvement actions. Support identity and access management (IAM) controls, including multi-factor authentication (MFA), role-based access control (RBAC), privileged access, joiner/mover/leaver processes, periodic access certifications, service accounts, and segregation of duties for critical banking and technology systems. Assist with data security and privacy controls, including information classification, encryption, data loss prevention (DLP), secure file transfer, retention, sensitive-data handling, and monitoring of non-public customer and Bank information. Support security reviews for technology projects, system changes, cloud/SaaS implementations, APIs, integrations, digital banking capabilities, and new vendors. Document security requirements, identify risks/control gaps, and track remediation through implementation. Support secure cloud and modern infrastructure practices, including security configuration and monitoring for Microsoft 365, Azure and/or AWS environments, SaaS applications, remote access, Zero Trust principles, endpoint/device security, and secure network connectivity. Support the Bank's AI security and governance program. Perform security and risk assessments for AI/GenAI use cases and vendors; evaluate risks such as sensitive-information disclosure, prompt injection, insecure output handling, excessive agency, model/supply-chain risk, unauthorized data use, and inadequate logging or access control; and help implement appropriate guardrails, monitoring, human oversight, and acceptable-use requirements. Monitor the use of approved AI-enabled tools and services, where applicable, and support controls for enterprise AI platforms such as Microsoft 365 Copilot, Azure OpenAI, ChatGPT Enterprise, AWS Bedrock, Google Gemini, or equivalent technologies. Assist with evaluation of AI-enabled cybersecurity tools for accuracy, access, data handling, and operational risk. Support third-party/vendor risk management across onboarding, due diligence, contracting, ongoing monitoring, risk assessment, issue remediation, renewal, and termination. Review security documentation such as SOC reports, penetration-test summaries, business continuity information, cyber insurance, privacy practices, subcontractors/fourth parties, and AI/model-provider dependencies where relevant. Collaborate with business owners, Technology, Compliance, Risk, Audit, Operations, and other stakeholders to ensure technology and vendor risks are identified, documented, accepted or remediated, and supported by appropriate controls. Support cybersecurity threat intelligence and threat-informed defense activities using authoritative sources and industry information-sharing channels. Map relevant threats and incidents to recognized frameworks such as MITRE ATT&CK when useful for investigation, control improvement, or reporting. Conduct and coordinate security awareness activities, including phishing simulations, role-based training, emerging-threat communications, secure use of AI/GenAI, social-engineering awareness, and targeted education for employees, contractors, and third parties. Maintain security policies, standards, procedures, risk registers, control evidence, issue trackers, inventories, diagrams, and other documentation. Support regulatory examinations, internal/external audits, risk assessments, and management responses. Develop and analyze cybersecurity metrics, dashboards, key risk indicators (KRIs), control-performance reports, and executive-level materials to identify trends, highlight material risks, and support management decision-making. Maintain current knowledge of cybersecurity threats, AI security risks, privacy and security laws, regulatory guidance, and industry practices relevant to financial institutions. Support alignment, as appropriate, with frameworks such as FFIEC guidance, GLBA, NIST Cybersecurity Framework (CSF) 2.0, NIST AI Risk Management Framework, CIS Controls, and OWASP guidance. Serve as backup security/application administrator for selected Bank systems as assigned, including Fiserv Premier and related applications, with responsibilities focused on secure configuration, access administration, periodic access reviews, logging, and least-privilege controls. Support other operational systems (such as EZ Teller, Business Analytics, or Enterprise Output Manager) when security, access, resilience, or controlled file-transfer support is required. Demonstrate quality customer service with internal and external stakeholders, actively participate in required Bank and compliance training, maintain strict confidentiality of non-public information, and comply with all applicable Bank policies, security requirements, and banking laws and regulations. Perform other duties and special projects as assigned. REQUIREMENTS: Bachelor's degree in Cybersecurity, Information Security, Information Technology, Computer Science, Management Information Systems, or a related discipline; or four (4) or more years of equivalent relevant work experience. Two (2) or more years of experience in information security, cybersecurity operations, technology risk, systems/network administration, IT audit, GRC, or a related technology role is preferred. Experience in banking, financial services, or another regulated environment is strongly preferred. Working knowledge of Windows and Linux operating systems, TCP/IP, DNS, firewalls, VPN/remote access, Active Directory/identity services, Microsoft 365, endpoint management, cloud/SaaS concepts, and common enterprise security architectures. Practical experience with security monitoring, vulnerability management, incident response, IAM/access reviews, third-party risk, security awareness, or GRC activities. Experience across multiple areas is preferred; deep specialization in every area is not required. Knowledge of financial-services cybersecurity and privacy expectations, including GLBA and FFIEC guidance, and working familiarity with recognized security frameworks such as NIST CSF 2.0, CIS Controls, MITRE ATT&CK, and incident-response practices. Working knowledge of AI/GenAI security concepts and risks, with familiarity with resources such as the NIST AI Risk Management Framework and OWASP guidance for LLM/GenAI applications. Direct enterprise AI security experience is preferred but not required. Experience with reporting, data analysis, or query tools such as SQL, Power BI, Excel, or equivalent is preferred. Basic scripting/automation experience with PowerShell, Python, APIs, or workflow/SOAR tools is a plus. Familiarity with Fiserv Premier or other core banking/application security administration is a plus. PREFERRED CERTIFICATIONS: CompTIA Security+, CySA+, SSCP, GSEC, CISA, CISSP, GIAC certifications, Microsoft/Azure or AWS security certifications, or comparable credentials are preferred depending on experience level. The candidate will be subject to investigation through credit checks, reference checks, background checks and fingerprinting checks performed at the time permissible under relevant law. Visit our website at: for additional information. Bank of the Orient is proud to be an Affnitive Action, Equal Opportunity Employer. #J-18808-Ljbffr
- ...Information Security Analyst Location: San Francisco, CA; Los Angeles, CA; Salt Lake City, Utah Duration: 12+ Months, 5 days onsite Must Have: SPL that Splunk uses Actual incident tickets – resolve actual security incident tickets Qualifications: Bachelor's degree in...SuggestedContract workWork at office
- ...Responsibilities: Excellent employment opportunity for a in the IT Security & Risk Analyst Foster City, CA area. IT Security Engineer that will... ...key infrastructure and application decisions to facilitate informed decisions that may impact security and the user experience...SuggestedContract work
- ...appropriate union. The Cybersecurity Awareness Analyst leads the design and execution of the organization’s security awareness and training programs in support of its... ...Establishing policies and standards for information security Providing guidance and conducting risk...SuggestedWork experience placementWorldwide
- ...Security Contracts Manager We believe that the way people interact with their finances will drastically improve in the next few years... ..., focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission...SuggestedContract workWork experience placementLocal area
$118.68k - $175.8k
...offices in New York, Washington D.C., London and Amsterdam.Team:The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s... ..., focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission...SuggestedWork experience placementWork at officeLocal area$121.76k
A leading scientific institution in San Francisco is seeking a Senior Security Analyst to manage information security controls, focusing on cybersecurity and operational integration. The ideal candidate will have over 5 years of IT experience with extensive knowledge in...Full time$121.76k
...collaboration. Full Time San Francisco, CA Posted 5 months ago About The Opportunity Reporting to the Director of Information Technology, the Senior Security Analyst is responsible for configuring, maintaining, and monitoring internal security controls to prevent, detect,...Full time$75k - $100k
Senior Security Analyst - Heartflow Join to apply for the Senior Security Analyst - Heartflow role at ISC2 East Bay Chapter . Full Time... ...revolutionize precision heartcare. Overview The Heartflow Information Security team is responsible for security across our corporate...Full timeLocal areaWorldwideRelocation- A leading IT services company is seeking a mid-senior level Information Security Analyst based in San Francisco, CA. The role focuses on resolving security incidents and requires strong skills in SQL, SPL, and usage of Splunk. Candidates should have a Bachelor's degree...Contract workWork at office
- ...Telecom, Energy, Pharmaceutical, Financial, Manufacturing, Information Technology, Government, Entertainment, and more. Our core competencies... .... Job Description JOB DETAILS: Job title: Info Security Analyst Location : 6 months Potential to extend duration Duration:...Flexible hours
$121.76k
...people to the natural world and empower them to protect it. About the Opportunity Reporting to the Director of Information Technology, the Senior Security Analyst is responsible for configuring, maintaining, and monitoring internal security controls to prevent, detect,...Full timeContract work$75k - $100k
A leading medical technology firm in San Francisco is seeking a Senior Security Analyst to join their Information Security team. This role will focus on analyzing security events and implementing enhancements to detection capabilities, ensuring the safety of patient data...$130k - $155k
Cox Worldwide Funds plc is looking for a Trade Operations & Data Analyst to join the Investment Operations department in San Francisco. This role is pivotal for maintaining the integrity of security reference data and overall asset data quality. Successful candidates will...Work at officeWorldwide- Mercury is seeking an Information Security GRC Analyst to mature security, risk, and compliance programs and build guardrails for business continuity and resilience. You will lead risk assessments, partner with cross‑functional teams, and drive audit readiness across SOC...
$209.25k - $271.71k
...civil shared experiences for everyone.As a member of the Roblox Security Governance, Risk, and Compliance (GRC) team, you will play a... ...security organization — empowering every builder to make risk-informed decisions by establishing a portfolio of governing policies and...Full timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday$130k - $134k
...their health, well-being, independence and participation in the community, fulfilling our mission. The Security Analyst is responsible for assessing information risk and facilitates remediation of identified vulnerabilities for IT security and risk across the agency....Full timeRelocation$117.2k - $176.7k
...! Agentforce is the future of AI, and you are the future of Salesforce.The ExperienceEnterprise Security is looking for a Senior Analyst to support our Business Information Security Officers (BISOs) in their day-to-day work with Enterprise business unit customers. BISOs...Full time- ...Security Analyst – Endpoint Security & InfrastructureLocation: Daly City, California, USAWork Mode: OnsiteEmployment Type: Full-TimeEligibility... ...for security automation.Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field.Soft Skills...Immediate startShift work
$144k - $162k
...playing games. Discord's Legal team is growing its Security GRC function, and we're looking for a Security Analyst to help run and scale it. You'll own the day-to-... ...Discord’s collection and usage of personal information relating to the application and recruitment process...Full timeWork at officeImmediate startRelocationRelocation package2 days per week$117.2k - $176.7k
...Salesforce.The ExperienceLocation: San Francisco, CAThe Senior Security GRC Analyst role is part of our Assurance team, sitting at the... ...external auditors, scheduling walkthroughs, responding to information requests, and coordinating responses to findings.You're Our...Full timeWork at office$90k - $100k
...access for millions more. Watch our story and see why we do what we do . What we are looking for: We’re looking for a Security Analyst to help keep Forage’s security and compliance programs running smoothly as we scale. You’ll own the operational backbone of our...Work at office- An established industry player is looking for a Senior Security Analyst to enhance the security and integrity of their systems and data.... ...fosters continuous improvement and innovation in the field of Information Security, where your contributions will play a crucial role...
- We are seeking a Senior Security Analyst for a Direct Hire/FTE position in Redwood City, CA. This position is onsite in Redwood City, CA.... ...culture of continuous improvement and innovation within the Information Security team. Monitor and identify potential threats from vulnerabilities...Full time
- California Academy of Sciences in San Francisco is seeking a Senior Security Analyst to configure, maintain, and monitor internal security controls across the academy’s IT environment. You will integrate security tools into daily operations, mature security architecture...
$1,750 - $2,150 per month
Role Overview Mercor is partnering with leading AI labs to engage experienced cybersecurity professionals — security analysts, penetration testers, incident responders, threat intelligence specialists, and security architects — to improve AI systems' reasoning around threat...Remote jobHourly pay- University of California, San Francisco seeks a Cybersecurity Awareness Analyst to design and execute security awareness programs across our healthcare and research mission. You will balance communications, training, and technical expertise to foster a culture of security...
- VRC (Valuation Research Corporation) is seeking an analyst for its complex securities valuation practice in San Francisco. You will value derivatives and other illiquid securities for financial reporting, tax, and regulatory needs, using rigorous modeling and client data...
- DoorDash is seeking a security-focused Third-Party Risk Management (TPRM) Sr. Analyst to mature our program and lead risk assessments across the vendor ecosystem. You will drive continuous security improvements, partner with security engineering, procurement, privacy, and...
$110k - $140k
...Security Compliance Analyst We are looking for a highly motivated individual with information security governance and compliance experience to be part of our team! As a Security Compliance Analyst at Hive, you will collaborate with engineers and auditors to meet security...$175k - $220k
...monitoring, and agentic systems for always-on visibility into our compliance posture. Work directly with Engineering to embed security and privacy controls into our products, including deletion pipelines, PII detection, access audit logging, and fine-grained data access...Contract workWork at officeFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security Analyst. Be the first to apply!


