Jobs · OTHR · New York

Information Security Risk Analyst (SOC)

HybridOTHRFull-time

This role is located in New York City and requires a hybrid work schedule of at least 2 days in office per week. Officer-level candidates preferred.

About the Bank

Sumitomo Mitsui Trust Bank, Limited was established through the merger of The Sumitomo Trust and Banking Co., Ltd with Chuo Mitsui Trust and Banking, Ltd. on April 1, 2012. We are one of the largest asset managers in Asia and number one among Japanese financial institutions by AUM, with approximately $850 billion USD in AUM. The Bank provides an assortment of financial solutions and manages a broad spectrum of financial products across its global branches.

Department Overview

The Americas Division (“AD”) was established in the Sumitomo Mitsui Trust Bank, Limited, New York Branch (“SMTBNY”) to perform corporate functions and supervise U.S. entities. Information Risk Governance (“IRG”) provides oversight to information and cyber security risk by maintaining and improving a branch-wide framework that aligns with Head Office and regulatory requirements, addressing Confidentiality, Integrity, and Availability for information assets. IRG establishes appropriate policies, procedures, measurement, and monitoring processes to proactively assess and evaluate cyber security and information security risks inherent in Branch Operations. IRG is directly involved in all information and cyber security-related projects, matters, and issues.

About the Role

The Security Operations Center (SOC) Analyst is responsible for monitoring, detecting, investigating, and responding to cybersecurity events and alerts across the organization’s technology environment. This role serves as a frontline defender within the Information Risk Governance Department, identifying potential threats, investigating suspicious activities, and supporting incident response efforts to protect the confidentiality, integrity, and availability of organizational assets.

Responsibilities

  • Monitor and analyze security events and alerts generated by security systems such as the Security Information and Event Management (SIEM) system, Endpoint Detection & Response (EDR) system, Firewalls, Network Access Control (NAC), Network Detection & Response (NDR) system, and Intrusion Detection and Prevention (IDS/IPS) systems.
  • Triage and analyze security alerts to determine severity, scope, and potential impact and business risk.
  • Investigate suspicious system, network, and user activity, escalating potential security incidents to the Incident Response Team and Management as appropriate.
  • Maintain awareness of the evolving cybersecurity landscape including emerging threats, attack techniques, vulnerabilities, and indicators of compromise (IoC).
  • Conduct proactive threat-hunting activities to identify, investigate, and mitigate emerging threats, anomalous behavior, and potential indicators of compromise that may evade existing security controls.
  • Participate as a member of the Incident Response Team during cybersecurity incidents and investigations. Tasks include documenting incident findings, actions taken, and collecting system log evidence and forensic artifacts.
  • Maintain, administer, and tune SIEM and NDR Security tools including ongoing optimization of detection rules, use cases, dashboards, reports, and alert configurations.
  • Liaise and coordinate with vendors, service providers, and contractors to support security operations and incident response activities.
  • Assist with internal and external audits, regulatory examinations, and information security assessments.
  • Assist with the evaluation, testing, and comparative analysis of security monitoring and SOC-related technologies.
  • Serve as the subject matter expert (SME) for assigned security monitoring and detection platforms.
  • Maintain procedures, playbooks, and documentation related to security monitoring and incident response processes.
  • Perform other duties and responsibilities as assigned by management.

Requirements

  • Bachelor’s degree or equivalent in Information Technology, Cybersecurity/Information Security, or a related field with 3+ years of experience.
  • Minimum of three (3) years of experience in cybersecurity, security operations, or a related technical field.
  • Strong understanding of security principles, frameworks, and best practices.
  • Experience with security monitoring, event analysis, and threat detection technologies.
  • Experience with incident investigation and response.
  • Excellent communication and problem-solving skills.
  • Knowledge of threat intelligence concepts, frameworks, and operational use cases.
  • Understanding of Cloud Security principles and controls.
  • Strong knowledge of Microsoft Windows Server 2019/2022/2025 and Active Directory environments.
  • Strong knowledge of networking protocols, architecture, and security concepts.
  • Strong understanding of firewall technologies and security controls.
  • Strong understanding and correlation skills of security logs, including Windows Event logs, Active Directory, DNS, proxy, firewall, EDR, and Cloud platform logs.
  • Strong knowledge and prior experience with SIEM platforms and security event correlation tools.
  • Strong knowledge and prior experience with User and Entity Behavioral Analytics (UEBA) and behavioral analysis tools.
  • Working knowledge of Amazon Web Services (AWS) architecture, services, and operations.
  • Working knowledge of Linux systems would be a plus.
  • Excellent analytical, organization, and multi-tasking skills with strong attention to detail and accuracy.
  • Prior experience in the financial institution or banking industry would be preferred.

Benefits

  • Paid Time Off
  • Medical, HSA, vision, and dental insurance
  • Flexible Spending Account (FSA)
  • 401(k) with profit sharing
  • Legal plan
  • Cancer indemnity plan
  • Disability and life insurance
  • Employee assistance program
  • Commuter benefits
  • Business travel accident insurance
  • Paid volunteer day
  • Paid memberships and seminars
  • Tuition assistance

We offer many socialization opportunities for wellness, financial wellbeing, runs/walks, team building, happy hours, and activities to support the Sustainable Development Goals.

Similar jobs

Security Analyst (SOC)

SpaceXHawthorne, CA· 4 wk ago
Information Technology$95k–$115k/yrapply on boards.greenhouse.io

SOC Security Analyst

Allied UniversalSalt Lake City Metropolitan Area· 1 mo ago
Information Technology$19.86/hrapply on securitycareers-aus.icims.com

SOC Security Analyst

Allied UniversalSalt Lake City, UT· 1 mo ago
Information Technology$19.86/hrapply on securitycareers-aus.icims.com

SOC Security Analyst

JobgetherUnited States· 2 mo ago
RemoteInformation Technologyapply on jobs.lever.co