Salary
💰 $98,577 - $152,795 per year
About the role
- Establishes foundational security for staff, members, and partners through scheduled audits of policies and procedures.
- Identifies gaps for collaborative procedural change within IT and the business.
- Establishes and applies risk management principles for consistent tracking and measurement in compliance with industry standards.
- Supports a near-zero risk enterprise using telemetry from security incident and event management systems and solutions to maintain transparency of risks.
- Tests solutions effectively utilizing industry standard analysis methods and delivers technical reports and documentation concerning test results.
- Engineers security solutions efficiently with a minimal technology footprint where possible.
- Manages vendor solutions and partnerships to ensure business and data privacy.
- Audits and reports on identity and access management to ensure a zero-trust framework for production and development business application systems.
- Collaborates with other IT and business teams on security program initiatives and resolves security related issues.
- Performs audits of computing platforms to ensure versioning and patching are compliant and current.
- Supervises changes in software, hardware, facilities, and user needs to ensure no degradation in security.
- Documents security control requirements for new and existing business systems and revises IT purchase specifications to ensure security interface controls are appropriate.
- Provides security guidance enabling new products and solutions to be built securely; performs vulnerability assessments and technical business risk assessments.
- Defines Indicators of Compromise (IOC) and develops Indicators of Exposure (IOE); incorporates lessons learned from cybersecurity and privacy incidents.
Requirements
- Bachelor’s Degree in related field or equivalent experience is required.
- Must have at least 4-6 years information security experience preferably in the financial services industry.
- Minimum Years of Experience: 4
- Preferred Years of Experience: 6
- Recognized Information Security Certification(s) are required.
- Must have advanced computer skills and a thorough working knowledge systems and applications.
- Experience with security monitoring, security and data/log analysis, and forensic analysis.
- Experience with security incident and event management systems and telemetry.
- Ability to perform vulnerability assessments and technical business risk assessments.