drjobs CyberSecurity Risk Analyst IV العربية

CyberSecurity Risk Analyst IV

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

Buffalo - USA

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

Our client an American bank holding company is currently seeking a Cybersecurity Risk Analyst IV to join their team on a 6 to 12month contract to hire basis.

Job Title: Cybersecurity Risk Analyst IV

Location: Onsite/Buffalo NY (preferred these candidates will get 1st preference) / Remote will also be considered for strong candidates

Duration: 6 to 12month Contract to Hire (MUST be able to convert to hire in 6 to 12 months)

FROM THE MANAGER:

Advanced knowledge of cybersecurity operation center technologies threat hunting incident response firewalls proxies web application firewall and IDP/IPS.

DESCRIPTION/OVERVIEW:
Supports a Cybersecurity risk management and governance practice focused on Cybersecurity risk assessments First Line of Defense and controls testing strategy development and maintenance of Cybersecurity policies and standards evaluation of Cybersecurity legal and regulatory requirements development and execution of the Cybersecurity awareness program and/or development and execution of the Cybersecurity Risk Management Program.

PRIMARY RESPONSIBILITIES:
Maintain current knowledge of the Banks Cybersecurity and Risk management policies standards and procedures as well as industry best practices and proposed new guidelines and regulations.
Identify and evaluate Cybersecurity risk to the business and drive development of strategies to mitigate identified risks based on diverse factors including the organizations overall risk appetite and tolerance.
Provide current data for key risk indicators (KRIs) and key performance indicators (KPIs). Present results to risk committees. Review current KRIs and KPIs recommend enhancements to management and present recommendations to risk committees.
Understand and adhere to the Companys risk and regulatory standards policies and controls in accordance with the Companys Risk Appetite. Identify riskrelated issues needing escalation to management.
Promote an environment that supports diversity and reflects the Banks brand.
Maintain the Banks internal control standards including timely implementation of internal and external audit points together with any issues raised by external regulators as applicable.
Complete other related duties as assigned.

SCOPE OF RESPONSIBILITIES:
This position requires regular interaction with nonmanagement middle management certain senior management and business units and partners. This position also requires occasional interaction with the Chief Information Security Officer.
This role is used in one or more of the following ways:
Risk Assessment Design and develop Cybersecurity risk assessments based on subject matter expertise and industry best practices. Execute risk assessments analyze results recommend and implement remediation plans to address defined risks. Present recommendations to area management and various risk committees. Work with other areas of Cybersecurity to define and document controls associated with identified risks.
Controls Testing Design Develop document and maintain the Banks Cybersecurity controls testing program and plan. Confirm the program aligns with Cybersecurity policies and standards Risk Management policies and regulatory requirements.
Policy and Standards Research recommend and develop new Cybersecurity policies and standards based on the Banks strategic direction and aligned with legal and regulatory requirements and industry best practices. Present recommendations to area management and various risk committees for approval. Update and enhance existing Cybersecurity policies and standards as needed.
Regulatory Review assigned regulatory notifications to identify impact to organization. Discuss results with stakeholders and develop recommendations along with associated action plans to address gaps. Summarize results recommendations and action plans and present to management and various risk committees. Lead efforts to address action plans.
Risk Management Program Design and develop the Cybersecurity Risk Management program ensure proper alignment with bank policies and procedures. Analyze program results recommend enhancements. Present recommendations to area management and various risk committees. Work with other areas of Cybersecurity to define and document key risks and controls.

EDUCATION AND EXPERIENCE REQUIRED:
Associates degree and a minimum of 7 years relevant work experience or in lieu of a degree a combined minimum of 9 years higher education and/or work experience including a minimum of 7 year relevant work experience.
Excellent knowledge of Cybersecurity principles relevant to confidentiality integrity availability authentication and nonrepudiation.
Proven ability facilitating targeted discussions with peers line managers and senior management within business unit.
Experience conducting research and evaluating information for reliability validity objectivity and relevance.
Excellent ability communicating complex information concepts or ideas in a confident and wellorganized manner through verbal written and/or visual means.
Experience conducting information searches.
Excellent ability to discern protection needs (i.e. security controls) of information systems and networks.
Proven ability to design and develop effective risk management processes (e.g. methods for assessing and mitigating risk).
Experience recognizing vulnerabilities in security systems.
Excellent ability designing valid and reliable assessments.
Experience conducting knowledge mapping.
Experience anticipating new security threats.

EDUCATION AND EXPERIENCE PREFERRED:
Bachelors degree.
Certified Information Systems Security Professional (CISSP) or Certified Risk and Information Systems Control (CRISC) certification or Cybersecurity domainrelated industryrecognized certification.
Knowledge of organizations risk tolerance and/or risk management approach.
Knowledge of organizational security policies.

Employment Type

Full Time

Company Industry

Accounting & Auditing

About Company

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.