Information Security Officer
Sumitomo Mitsui Trust Bank Limited New York Branch
This role is located in New York City and will require a hybrid work schedule of at least 2 days in office per week.
This role is for Vice President level candidates.
About the Bank:
Sumitomo Mitsui Trust Bank, Limited was established through the merger of The Sumitomo Trust and Banking Co., Ltd with Chuo Mitsui Trust and Banking, Ltd. on April 1, 2012. We are one of the largest asset managers in Asia and number one among Japanese financial institutions by AUM, with approximately $850 Billion USD in AUM. The Bank provides an assortment of financial solutions and manages a broad spectrum of financial products across its global branches.
Department Overview:
The Americas Division (“AD”) was established in the Sumitomo Mitsui Trust Bank, Limited, New York Branch) (“SMTBNY”) to perform corporate functions and supervise U.S. entities. Established under the AD are the “Global Banking Unit (“GBU”), Americas Division” and “Global Markets Unit (“GMU”), Americas Division” which performs business functions. Information Risk Governance (“IRG”) provides oversight to information and cyber security risk by maintaining and improving branch wide framework that is in-line with the Head Office and regulatory requirements and addresses Confidentiality, Integrity, and Availability for information assets. IRG establishes appropriate policies, procedures, measurement, and monitoring processes to proactively assess and evaluate cyber security and information security risks inherent in the Branch Operations. IRG is directly involved in all information and cyber security related projects, matters, and issues.
Your Role Overview:
The Information Security Officer (ISO) serves as the Chief Information Security Officer’s principle operational delegate. The ISO is responsible for leading the day-to-day governance, administration, and continuous improvement of the Americas Division’s Information Security and Cybersecurity program.
Working under the direction of the CISO, the ISO translates the Americas Division’s information security strategy, risk appetite, regulatory obligations, and enterprise requirements into an effective operating program.
Your Duties and Responsibilities:
- Administer and continuously improve the Americas Division information security and cybersecurity program, including policies, standards, procedures, control requirements, and evidence repositories.
- Translate CISO direction, enterprise security requirements, Americas Division risk appetite, and regulatory expectations into actionable objectives, work plans, control requirements, and measurable deliverables.
- Maintain Americas Division information security policies and procedures lifecycle, including periodic review, stakeholder coordination, approval tracking, publication, and exception management.
- Assist the CISO to coordinate with Head Office and US regional affiliate information security teams to ensure that the US-level Information Security risk framework is appropriately adhered to and evidenced.
- Coordinate with security operations, IT, Legal, Compliance, BCP, Head Office, and other relevant stakeholders during cybersecurity incidents, as part of the Incident Response Team.
- Monitor relevant changes in laws, regulations, supervisory expectations, industry practices, and emerging threats and recommend updates to the Americas Division cybersecurity and information security program.
- Oversee and challenge the information security risk assessments as performed by the Risk Management Section of IRG. This includes risk assessments for new products, material technology changes, Cloud/SaaS services, third party engagements, Artificial Intelligence use cases, and other material business initiatives.
- Oversee the effectiveness of key cybersecurity controls, including identity and access management, privileged access, vulnerability management, systems patching, endpoint protection, logging and monitoring, data encryption, secure configuration based on best practices, secure development lifecycle, backup and recovery, as well as data protection.
- Coordinate risk-based control testing and evidence collection, identify control deficiencies, validate remediation, and elevate material or overdue issues to the CISO and appropriate Senior Management. Administer the information security exception process, including documentation of business justification, compensating controls, expiration dates, ownership, risk ratings, and required approvals.
- Ensure that material residual risk decision and risk acceptances are escalated to the CISO and/or other authorized risk acceptance authorities in accordance to policy.
- Coordinate the Americas Division’s operational readiness for applicable cybersecurity and information security regulatory obligations.
- Prepare and maintain documentation, risk assessments, testing records, policy evidence, incident records, third party evidence, and other artifacts needed to support regulatory examinations, internal/external audits, and management reviews.
- Track regulatory and audit findings, drive remediation governance, validate closure evidence, and elevate overdue or high-risk findings.
- Produce timely, accurate, and actionable cybersecurity management information for the CISO, including key risk indicators, control metrics, significant incidents, vulnerabilities, exceptions, audit issues, third-party risks, training results, and remediation status.
- Support the CISO in preparing periodic and annual cybersecurity program reports for Senior Management, governing bodies, and other stakeholders.
- Assist the CISO with the management of all matters related to Information Security and Information Risk Management, including providing guidance to other IRG Department members.
- Performs other duties and responsibilities as assigned by management.
Your Qualifications:
- Certification in Information Security (ISC2 CISSP or ISACA CISM) required.
- 8+ years of Information Security related experience, IT Audit experience, preferred.
- Strong knowledge of Information Security principles, terminologies, and technologies required.
- Strong knowledge of Information Risk Management framework and principles required.
- Ability to analyze and design information security policy, procedures, and activities required.
- Detailed Knowledge and expertise in Technology Risk Assessments and Risk Analysis required.
- Excellent written and verbal communication skills, required.
- Strong skills and prior experience with Microsoft Office (PowerPoint, Excel, and Word) required.
- Strong project management and people management skills required.
- Prior experience developing Risk Management and Oversight Frameworks for Systems Automation, AI, and other novel technologies.
- Prior experience in the Financial Services Industry preferred, especially in a FBO with exposure to NYDFS and FRBNY regulations.
Why you should join SuMi Trust:
SuMi Trust embraces flexible ways of working when the business and role permits. We provide employees with a hybrid working model, allowing for in-office work and work from home. Our diverse and inclusive environment along with our global presence enables us to collaborate and communicate to meet our business needs. We believe that efficient teams need truth, loyalty, and a strong sense of purpose to balance risk and their targets. We make sustainable business decisions to improve our society and the world. We believe that each person brings a unique value that drives the business though their creativity and passion.
- The Employee Benefits package includes: Paid Time Off, medical, HSA, vision, dental, FSA, 401(k), profit sharing, legal plan, cancer indemnity plan, disability insurance, life insurance, employee assistance program, commuter benefits, business travel accident, paid volunteer day, paid memberships, paid seminars, and tuition assistance.
- We offer many socialization opportunities for wellness, financial wellbeing, runs/walks, team building, happy hours, and activities to support the Sustainable Developmental Goals.
Check out our LinkedIn for our employee experience:
We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, national origin, disability status, protected veteran status or any other characteristic protected by law. SuMi Trust provides reasonable accommodations for employees and applicants with disabilities consistent with applicable law. If you need a reasonable accommodation during the application
#J-18808-Ljbffr$420k
...Who are we?Cohere is the leading security-first enterprise AI company. We build cutting-... ...in Toronto and San Francisco, with key offices in London, New York City, Montreal, Seoul... ...us!The OpportunityCohere seeks a Chief Information Security Officer who can help shape Cohere...SuggestedFull timeWork at officeLocal areaRemote workHome office$300k - $350k
...Chief Information Security Officer (CISO)The CISO is our chief protector. Our infrastructure, threat model, and customer expectations are more complex than a typical mobile carrier or a typical software company. Your challenge is to enable rapid product innovation without...SuggestedWork at officeImmediate start- ...Chief Information Security Officer (CISO)New York CityCAIS is the pioneer in democratizing access to and education about alternative investments and structured products for independent financial advisors, empowering them to engage and transact with leading asset managers...Suggested
$350k - $400k
...Group Chief Information Security Officer Organization: Location: New York, NY Description: Job Summary The Chief Information Security Officer (CISO) will lead and oversee the Information Security program across the entire organization. The role will...SuggestedContract workLocal areaShift work- ...Chief Information Security Officer (CISO) & Head of Information TechnologyAt Trustly, we're building a smarter, faster, and more secure financial future by revolutionizing the world of payments. As a global leader in Open Banking Payments, we are establishing Pay by Bank...SuggestedContract workWork at officeWorldwideFlexible hours
$350k - $400k
...Job Summary The Chief Information Security Officer (CISO) will lead and oversee the Information Security program across the entire organization. The role will be responsible for developing, implementing, and maintaining a unified enterprise security strategy that ensures...Full timeContract work$300k - $375k
...regulatory compliance in everything we do. Join us and help build the future of global investing! About the Role As Chief Information Security Officer, you will be responsible for leading and strengthening the company’s entire security function across four key domains:...Full timeWork at officeWorldwide$250.44k - $375.67k
...Americas Regional Chief Information Security Officer (CISO) New York, United States; San Jose, California, United States Who We Are At OKX, we believe that the future will be reshaped by crypto, and ultimately contribute to every individual's freedom. OKX is a leading...- ...Compass International Holdings seeks a seasoned Chief Information Security Officer to own and evolve the enterprise security program. This executive role balances security strategy with technology and business, protecting the platform, agents, buyers, sellers, and sensitive...
$299k - $344k
...human judgment to AI outputs, and keep building AI fluency in ways that support their role and our mission. The Chief Information Security Officer will be responsible for defining, leading, and advancing Spring Health’s enterprise-wide information security, technology...Full timeWork at officeWorldwideRelocationSleeping nights2 days per week3 days per week$225k - $275k
...platform includes a mix of instrument, consumable, reagent, CDMO, and software businesses — each with its own security profile.The Platform Information Security Officer (PISO), Life Sciences Platform is responsible for end-to-end cybersecurity execution across all operating...Full timeContract workRemote work$225k - $275k
...clinical decisions — making cybersecurity a patient-safety, regulatory, and brand-trust priority for the platform.The Platform Information Security Officer (PISO), Diagnostics Platform is responsible for end-to-end cybersecurity execution across all operating companies (OpCos...Full timeRemote work- ...Chief Information Security Officer (CISO) About the Company Innovative provider of data safety & recovery solutions Industry Information Technology and Services Type Privately Held Founded 2024 Employees 51-200 Specialties cloud backup...
- ...Chief Information Security Officer (CISO) About the Company Popular provider of workplace mental health solutions Industry Mental Health Care Type Privately Held, VC-backed Founded 2016 Employees 1001-5000 Funding $200+ million Categories...
- ...Information Systems Security Officer (ISSO)Employment Type: Full-Time, ExperiencedDepartment: Information TechnologyCGS is seeking an Information Systems Security Officer (ISSO) with DIACAP and/or RMF experience who has deep expertise in security assessment documentation...Full timeLocal area
- ...Deputy Chief Information Security OfficerOur top-notch Information Security team quickly finds and responds to real time threats. These critical... ...by all institutional policies.Proficiency in Microsoft Office Suite including Word, Excel, Power Point, Outlook, Co-Pilot,...Work at officeImmediate startRemote workFlexible hours
- ...The firm's work is distinguished by a unique combination of precision and vision. Based in New York, the Deputy Chief Information Security Officer (Deputy CISO) serves as the second-in-command of the information security organization, partnering with the CISO to...Local areaImmediate startFlexible hoursShift work
- ...Deputy Chief Information Security Officer (CISO), Security Technology About the Company Popular provider of revenue cycle management solutions Industry Hospital & Health Care Type Privately Held, Private Equity-backed Founded 2003 Employees...
- ...Deputy Chief Information Security Officer (CISO) About the Company Industry-leading cybersecurity platform Industry Computer & Network Security Type Privately Held, VC-backed Founded 2019 Employees 201-500 Funding $200+ million Categories...
- ...Field Chief Information Security Officer (CISO) About the Company Industry leading provider of security & compliance solutions Industry Outsourcing/Offshoring Type Privately Held Founded 2020 Employees 501-1000 Funding $200+ million Categories...Remote work
- ...Chief Information Security Officer (CISO), Information Security & Compliance About the Company Innovative artificial intelligence (AI) & marketing analytics platform Industry Information Technology and Services Type Public Company Founded 2014...
- ...Job Description Job Description Information System Security Officer (ISSO) Employment Type: Full-Time, Mid-Level Department: Administrative and Logistics Support As a FSR ISSO, you will be embedded on-site with U.S. Government customers to ensure the secure...Full timeFlexible hours
- %PDF-1.6%ÓôÌá1 0 obj /Rotate 0/StructParents 2/Tabs/S/Type/Page/Group endobj2 0 obj streamH‰ìW[—ÓÈ~÷¯èG;ÇÖè.yápÎ2L’IB€Å‡!'Gµm#Á² ~«U—nÉÏ,$yÚ—YêKÕWU_}uöÇuùU=|xöôüò‰ŠÔ£GŸœ«ÙÇYy¡Ê|/ U%žŸ«4_{y® éÙkUÍofg›¯µÙÍ|Ï÷ááZ¾·ÎÕÊW=¦©—ª,ñ½ W›³«ù‡EäÅjþv±Ôüþz¹š_›ÿ™š×Õ?ì»O‹˜-¾¨«¥*õ £E‹...
- ...These careers bring the expertise in all facets of Information Operations, making sure our fleet is capitalizing on... ...related to intelligence. INTELLIGENCE AND INFORMATION SECURITY CAREERS IN THE NAVY INTELLIGENCE OFFICER Analyze top-secret information, interpret spy...Full timePart timeWorldwide
- ...Chief Trust Officer (CTO) About the Company Highly respected wealth management firm with boutique, client-centric service for sophisticated families. Industry Financial Services Type Privately Held About the Role The Company is in search of a Chief...
- ...City, NJ / Chicago, IL / Brooklyn, NY / Houston, TXDrive the security of critical banking applications and platforms through hands-on... ...health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.Equal Opportunity Employer/Disability...
$148.5k - $223.9k
....Location: New York, NYThe ExperienceAs a Manager, Office of the CISO, you serve as a trusted security, compliance, privacy, and risk advisor to Salesforce... ..., or Public Sector.You've worked within a Business Information Security Office, Office of the CISO, Customer Trust...Full timeWork at office$150k - $200k
...Chief Information Security Officer (CISO) Vistrada is looking to hire strong Chief Information Security Officers (CISO). The CISO will provide strategic cybersecurity guidance and oversight to Vistrada clients by leading and managing their cybersecurity programs to...Full timeWork experience placementRemote workFlexible hours- ...detection models. You will use specialized detective skills to identify artifacts of AI-generated content, aiding in building a more secure digital world. Responsibilities include detecting synthetic artifacts, biometric stress-testing, and forensic reporting to support...FreelanceRemote workFlexible hours
- ...cybersecurity messaging, customer strategy, and executive engagement programs. Build long‑term trusted relationships with senior security leaders and industry influencers. Provide feedback from the field to product and leadership teams regarding customer priorities and...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security Officer. Be the first to apply!
- information security officer New York, NY
- information security officer iso New York, NY
- remote ciso New York, NY
- ciso New York, NY
- chief information security officer ciso New York, NY
- business information security officer New York, NY
- chief information security officer New York, NY
- information security compliance analyst New York, NY
- information security New York, NY
- information security analyst New York, NY



