mycareers logo


Showing: 3584  jobs
IT Security Analyst
Spectraforce
New York, New York

2 hours ago

Job Description

Job Title: IT Security Analyst
Location Address: 250 Vesey Street 23-24 FL (NEWYORK) – onsite 2x/week at least
Contract Duration: 6 months, Possibility of Extension
Schedule Hours: 8:30am-5:30pm Monday-Friday; standard 40 hrs/week (Possible OT)
Reason: additional workload

Story Behind the Need
Business group: U.S. Information Security and Control
This is a security advisory team that provides various security services across the enterprise, including assessing systems and their security posture, aligning technology into the network environment, supporting secure by design initiatives, and providing guidance to business lines on best practices and adhering to the bank’s security standards. The successful candidate must have an understanding of regional and US regulatory requirements.

Candidate Value Proposition:
The successful candidate will have the opportunity to work for a global legacy Canadian bank with a strong multi-regional US presence that is undergoing significant transformations, including Cloud.

Typical Day in Role:
Reporting to the Senior Manager of Security Advisory (US Advisory), the Information Security Advisor provides guidance to business lines to ensure design, development and implementation of complex projects and initiatives are in accordance with the Bank's Information Security Standards and in compliance with industry regulations. In this role, you will be supporting various business lines while assisting them in making informed decisions to protect information assets deployed in various environments.

• Provide strategic guidance and technical expertise to business lines, IT support functions, and IS&C Control functions to include security within early stages of the design of Bank´s technological solutions.
• Providing the following functions to clienr's Initiatives:
• Conducting Threat Risk Assessments and performing security advisory work on specific applications and infrastructure associated with client's  US subsidiaries and other Initiatives ensuring that controls are adequate, meet Bank standards, and enable business objectives.?
• Conducting Risk Management activities.
• Provide Quality Assurance on Threat Risk Assessments and Threat Modelling as required for Cloud initiatives.?Provide design and technical expertise on security solutions and recommend best practices.
• Collaborate with cross-functional teams to design and implement robust security architectures for various systems, applications, and networks.
• Evaluate existing security solutions and propose enhancements or new designs to address emerging threats and business requirements.
• Ensure alignment with industry best practices, compliance standards, and organizational security policies.
• Identify security weaknesses, vulnerabilities, and gaps in existing systems and recommend remediation strategies.
• Provide support on how to apply the Bank's portfolio of standards to the technology footprint of client's subsidiaries.
• Provide oversight over the specific line of business security posture, ensuring that all tools available to detect and remediate security risks have been applied.
• Conduct industry reviews and benchmarking exercises to ensure our controls are aligned with our peers, emerging threats, and available mitigation strategies.
• Working directly with technical leads from assigned Lines of Businesses supporting their initiatives from an Information Security perspective.
• Providing relationship management function primarily to US subsidiaries from an Information Security perspective.

Candidate Requirements/Must Have Skills:
1) 5+ years of hands-on technical working experience in performing security assessments on various platforms, network infrastructure and complex applications.
2) 3+ years of Experience with Threat Risk Assessments of applications hosted on premise, cloud, hybrid cloud and SaaS.
3) 2+ years of experience in security solution architecture, software development, and/or hands-on experience with implementations to various environments, knowledge of application security controls, including compensating controls and cloud-based security solutions
4) 3+ experience reviewing and interpreting vulnerability reporting, server hardening requirements, and validating presence of controls through evidence
5) Strong understanding of US regulatory regulations and practices

Nice-To-Have Skills:
1) prior experience using ServiceNow platform
2) Basic knowledge of cloud technologies and cloud security (GCP or Azure or AWS)
3) security engineering, security architecture, and/or security risk based certifications (CISSP, CISM, CCSP, CRISC)
4) Familiar with industry standards and frameworks e.g., NIST 800-53, ISO 27001, ISO27002, ISO 27017, ISO27018, PCI DSS, CIS.

Soft Skills Required:
• You are a strong communicator and capable of creating clear documentation and communicating ideas to others
• You possess advanced communication (verbal/written/presentation) skills in English.

Education: Post-secondary education in Computer Science or in a related field.

Best VS. Average Candidate: The ideal candidate would be familiar with frameworks listed under nice to haves and would have solid knowledge of cloud security. The candidate must have strong US regulatory knowledge.

Candidate Review & Selection
2 rounds
1st round – HM – 45 mins – MS Teams Video
2nd round – HM + Project Lead – MS Teams Video
  
Applicant Notices & Disclaimers
  • For information on benefits, equal opportunity employment, and location-specific applicant notices, click here
 
At SPECTRAFORCE, we are committed to maintaining a workplace that ensures fair compensation and wage transparency in adherence with all applicable state and local laws. This position’s starting pay is: $ 65.00/hr.

Don't miss your next Big Opportunity!

Get notified when we find an opportunity for you