Sumitomo Mitsui Banking Corporation

Information Security Officer

Finance & Insurance
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • CISSP certification is required.
  • Over 8 years of experience in Information Security, with a preference for IT Audit experience.
  • Strong knowledge of Information Security principles and technologies.
  • Familiarity with Information Risk Management frameworks and principles is essential.
  • Ability for thorough analysis and design of security monitoring procedures preferred.
  • Expertise in Technology Risk Assessments and Risk Analysis is crucial.
  • Excellent verbal and written communication skills are necessary.
  • Proficiency in Microsoft Office applications, particularly Excel and Word.,

Responsibilities

  • Maintain and enhance the information risk framework for branch operations.
  • Serve as the Information Security Officer, providing subject-matter expertise to senior management.
  • Coordinate incident response efforts during cyber security events.
  • Monitor industry trends in information risk that may affect operations.
  • Establish communication guidelines for data classification governance.
  • Oversee employee training on information security awareness.
  • Manage critical risk management assessments and trend analyses.,

Benefits

  • Hybrid working model with a mix of in-office and remote work.
  • Comprehensive health benefits including medical, dental, and vision coverage.
  • 401(k) plan with profit-sharing options.
  • Tuition assistance and paid professional development opportunities.
  • Paid Time Off and a range of social wellness activities.
  • Supportive environment with emphasis on diversity and inclusion.
Full Job Description
This role is located in New York City and will require a hybrid work schedule of at least 2 days in office per week.

This role is for Vice President level candidates.

Department Overview:

The Americas Division ("AD") was established in the Sumitomo Mitsui Trust Bank, Limited, New York Branch) ("SMTBNY") to perform corporate functions and supervise U.S. entities. Established under the AD are the "Global Banking Unit ("GBU"), Americas Division" and "Global Markets Unit ("GMU"), Americas Division" which performs business functions. Information Risk Governance ("IRG") provides oversight to information and cyber security risk by maintaining and improving branch wide framework that is in-line with the Head Office and regulatory requirements and addresses Confidentiality, Integrity, and Availability for information assets. IRG establishes appropriate policies, procedures, measurement, and monitoring processes to proactively assess and evaluate cyber security and information security risks inherent in the Branch Operations. IRG is directly involved in all information and cyber security related projects, matters, and issues.

Your Role Overview:

The Information Security Officer (ISO) serves as the Chief Information Security Officer's principle operational delegate. The ISO is responsible for leading the day-to-day governance, administration, and continuous improvement of the Americas Division's Information Security and Cybersecurity program.

Working under the direction of the CISO, the ISO translates the Americas Division's information security strategy, risk appetite, regulatory obligations, and enterprise requirements into an effective operating program.

Your Duties and Responsibilities:

  1. Administer and continuously improve the Americas Division information security and cybersecurity program, including policies, standards, procedures, control requirements, and evidence repositories.
  2. Translate CISO direction, enterprise security requirements, Americas Division risk appetite, and regulatory expectations into actionable objectives, work plans, control requirements, and measurable deliverables.
  3. Maintain Americas Division information security policies and procedures lifecycle, including periodic review, stakeholder coordination, approval tracking, publication, and exception management.
  4. Assist the CISO to coordinate with Head Office and US regional affiliate information security teams to ensure that the US-level Information Security risk framework is appropriately adhered to and evidenced.
  5. Coordinate with security operations, IT, Legal, Compliance, BCP, Head Office, and other relevant stakeholders during cybersecurity incidents, as part of the Incident Response Team.
  6. Monitor relevant changes in laws, regulations, supervisory expectations, industry practices, and emerging threats and recommend updates to the Americas Division cybersecurity and information security program.
  7. Oversee and challenge the information security risk assessments as performed by the Risk Management Section of IRG. This includes risk assessments for new products, material technology changes, Cloud/SaaS services, third party engagements, Artificial Intelligence use cases, and other material business initiatives.
  8. Oversee the effectiveness of key cybersecurity controls, including identity and access management, privileged access, vulnerability management, systems patching, endpoint protection, logging and monitoring, data encryption, secure configuration based on best practices, secure development lifecycle, backup and recovery, as well as data protection.
  9. Coordinate risk-based control testing and evidence collection, identify control deficiencies, validate remediation, and escalate material or overdue issues to the CISO and appropriate Senior Management. Administer the information security exception process, including documentation of business justification, compensating controls, expiration dates, ownership, risk ratings, and required approvals.
  10. Ensure that material residual risk decision and risk acceptances are escalated to the CISO and/or other authorized risk acceptance authorities in accordance to policy.
  11. Coordinate the Americas Division's operational readiness for applicable cybersecurity and information security regulatory obligations.
  12. Prepare and maintain documentation, risk assessments, testing records, policy evidence, incident records, third party evidence, and other artifacts needed to support regulatory examinations, internal/external audits, and management reviews.
  13. Track regulatory and audit findings, drive remediation governance, validate closure evidence, and escalate overdue or high-risk findings.
  14. Produce timely, accurate, and actionable cybersecurity management information for the CISO, including key risk indicators, control metrics, significant incidents, vulnerabilities, exceptions, audit issues, third-party risks, training results, and remediation status.
  15. Support the CISO in preparing periodic and annual cybersecurity program reports for Senior Management, governing bodies, and other stakeholders.
  16. Assist the CISO with the management of all matters related to Information Security and Information Risk Management, including providing guidance to other IRG Department members.
  17. Performs other duties and responsibilities as assigned by management.


Your Qualifications:

  1. Certification in Information Security (ISC2 CISSP or ISACA CISM) required.
  2. 8+ years of Information Security related experience, IT Audit experience, preferred.
  3. Strong knowledge of Information Security principles, terminologies, and technologies required.
  4. Strong knowledge of Information Risk Management framework and principles required.
  5. Ability to analyze and design information security policy, procedures, and activities required.
  6. Detailed Knowledge and expertise in Technology Risk Assessments and Risk Analysis required.
  7. Excellent written and verbal communication skills, required.
  8. Strong skills and prior experience with Microsoft Office (PowerPoint, Excel, and Word) required.
  9. Strong project management and people management skills required.
  10. Prior experience developing Risk Management and Oversight Frameworks for Systems Automation, AI, and other novel technologies.
  11. Prior experience in the Financial Services Industry preferred, especially in a FBO with exposure to NYDFS and FRBNY regulations.


Check out our LinkedIn for our employee experience: https://www.linkedin.com/company/smtbny

About Sumitomo Mitsui Banking Corporation

Sumitomo Mitsui Banking Corporation (SMBC) is a Japanese multinational banking and financial services company headquartered in Tokyo, Japan. It is the second-largest bank in Japan by assets and market capitalization. SMBC offers a wide range of financial services, including commercial banking, investment banking, asset management, leasing, and consumer finance. The bank has a global presence, with operations in over 40 countries and regions. SMBC is a member of the Mitsubishi UFJ Financial Group (MUFG), one of the largest financial groups in the world.
Learn more about Sumitomo Mitsui Banking Corporation
Size
101,023 employees
Market Cap
$54.6 billion
Industry
Net Income
$526.9 billion
5 Year Trend
-0.2%
NASDAQ

Similar Jobs

More Jobs at Sumitomo Mitsui Banking Corporation

More Finance & Insurance Jobs

Find similar Information Security Officer jobs: