Information Security Risk Analyst
This role is located in New York City and requires a hybrid work schedule of at least 2 days in office per week. Officer-level candidates are preferred.
About the Bank
Sumitomo Mitsui Trust Bank, Limited was established through the merger of The Sumitomo Trust and Banking Co., Ltd with Chuo Mitsui Trust and Banking, Ltd. on April 1, 2012. We are one of the largest asset managers in Asia and number one among Japanese financial institutions by AUM, with approximately $850 billion USD in AUM. The Bank provides an assortment of financial solutions and manages a broad spectrum of financial products across its global branches.
Department Overview
The Americas Division (“AD”) was established in the Sumitomo Mitsui Trust Bank, Limited, New York Branch (“SMTBNY”) to perform corporate functions and supervise U.S. entities. Established under the AD are the Global Banking Unit (“GBU”), Americas Division and Global Markets Unit (“GMU”), Americas Division which perform business functions.
Information Risk Governance (“IRG”) provides oversight to information and cyber security risk by maintaining and improving a branch-wide framework that aligns with Head Office and regulatory requirements, addressing Confidentiality, Integrity, and Availability for information assets. IRG establishes appropriate policies, procedures, measurement, and monitoring processes to proactively assess and evaluate cyber security and information security risks inherent in Branch Operations. IRG is directly involved in all information and cyber security-related projects, matters, and issues.
About the Role
The Information Security Risk Analyst is responsible for supporting the organization’s vulnerability management program and performing assigned information security risk assessments. This role will handle day-to-day vulnerability management activities, perform risk-based analysis of identified vulnerabilities, coordinate remediation efforts with the IT Department, and help ensure systems are maintained in accordance with the organization’s information security standards.
Responsibilities
- Administer and support the organization’s system vulnerability management program.
- Conduct regular vulnerability scans across servers, endpoints, applications, network infrastructure, and Cloud environments.
- Monitor vulnerability scanning coverage and coordinate with the IT Department to identify missing, newly added, or decommissioned IT assets, ensuring the scanning scope remains accurate and up to date.
- Review and analyze vulnerability scan results and cross-reference with other sources such as the CISA Known Exploited Vulnerabilities (KEV) catalog to identify high-criticality areas for remediation.
- Identify potential false-positive findings and review with ITD for validity.
- Collaborate with ITD to prioritize system vulnerability remediation and patching based on system risk severity, vulnerability exploitability, asset criticality, and potential business impact.
- Track identified vulnerabilities through remediation and/or mitigation, validate remediation through re-scanning or review of appropriate supporting evidence, and generate regular system vulnerability remediation status reports.
- Monitor compliance of system vulnerability remediation based on pre-defined risk-based remediation targets. Escalate critical or significant delays of system vulnerability remediation based on pre-defined targets to Management, as necessary.
- Create vulnerability management-related reports with risk summaries and recommendations to Management.
- Perform risk assessments on proposed new systems to be introduced to the organization.
- Perform other duties and responsibilities as assigned by management.
Qualifications
- Strong understanding and prior experience working with network components and devices such as Firewalls, IPS, IDS, switches, routers, NDR, and NAC.
- Strong understanding and prior experience working with Microsoft Windows-based environments including components such as domain controllers, DHCP, DNS, and Active Directory.
- Foundational understanding of Information Security frameworks such as NIST Cybersecurity Framework and SP 800-53 as well as Cyber Risk Institute Profile v2.x.
- 3+ years of experience managing System Vulnerability Management tools such as Qualys or Tenable.
- 3+ years of experience with risk assessment methodologies and techniques.
- Prior experience with financial industry structure and concepts is a plus.
- Strong verbal and written communication skills.
- Strong analytical skills with attention to detail and accuracy.
- Self-motivated with good time management skills.
Benefits
- Paid Time Off
- Medical, HSA, vision, and dental insurance
- FSA (Flexible Spending Account)
- 401(k) and profit sharing
- Legal plan
- Cancer indemnity plan
- Disability and life insurance
- Employee assistance program
- Commuter benefits
- Business travel accident insurance
- Paid volunteer day
- Paid memberships and seminars
- Tuition assistance
We offer many socialization opportunities for wellness, financial wellbeing, runs/walks, team building, happy hours, and activities to support the Sustainable Development Goals.