Sumitomo Mitsui Banking Corporation

Information Security Risk Analyst

Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Strong understanding of network components like Firewalls, IPS, IDS, switches, and routers.
  • Experience with Microsoft Windows environments and components such as Active Directory.
  • Familiarity with Information Security frameworks including NIST Cybersecurity Framework.
  • 3+ years managing System Vulnerability Management tools such as Qualys or Tenable.
  • 3+ years of experience in risk assessment methodologies and techniques.
  • Experience in the financial industry is a plus.
  • Strong verbal and written communication skills.

Responsibilities

  • Administer and support the organization's system vulnerability management program.
  • Conduct regular vulnerability scans across various IT environments.
  • Coordinate with IT Department to maintain an accurate scanning scope.
  • Analyze vulnerability scan results and identify critical areas for remediation.
  • Collaborate with ITD to prioritize vulnerabilities based on risk and business impact.
  • Track vulnerabilities through remediation and generate status reports.
  • Monitor compliance with remediation targets and escalate delays to management.

Benefits

  • Paid Time Off and health benefits including medical, vision, and dental.
  • 401(k) plan with profit sharing and various insurance options.
  • Employee assistance programs and commuter benefits.
  • Paid volunteer days and tuition assistance.
  • Networking opportunities and wellness activities such as team building and runs.
Full Job Description
This role is located in New York City and will require a hybrid work schedule of at least 2 days in office per week.

This role is for Officer level candidates.

Department Overview:

The Americas Division ("AD") was established in the Sumitomo Mitsui Trust Bank, Limited, New York Branch) ("SMTBNY") to perform corporate functions and supervise U.S. entities. Established under the AD are the "Global Banking Unit ("GBU"), Americas Division" and "Global Markets Unit ("GMU"), Americas Division" which performs business functions. Information Risk Governance ("IRG") provides oversight to information and cyber security risk by maintaining and improving branch wide framework that is in-line with the Head Office and regulatory requirements and addresses Confidentiality, Integrity, and Availability for information assets. IRG establishes appropriate policies, procedures, measurement, and monitoring processes to proactively assess and evaluate and cyber security and information security risks inherent in the Branch Operations. IRG is directly involved in all information and cyber security related projects, matters and issues.

Your Role Overview:

The Information Security Risk Analyst is responsible for supporting the organization's vulnerability management program and performing assigned information security risk assessments. This role will perform the day-to-day vulnerability management activities, perform risk-based analysis of identified vulnerabilities, coordinate remediation efforts with the IT Department, and help ensure systems are maintained in accordance with the organization's information security standards.

Your Duties and Responsibilities:

  1. Administer and support the organization's system vulnerability management program.
  2. Conduct regular vulnerability scans across servers, endpoints, applications, network infrastructure, and Cloud environments.
  3. Monitor vulnerability scanning coverage and coordinate with the IT Department to identify missing, newly added, or decommissioned IT assets and ensure that the scanning scope remains accurate and up to date.
  4. Review and analyze vulnerability scan results and cross-reference with other sources such as the CISA Known Exploited Vulnerabilities (KEV) catalog to identify high-criticality areas for remediation. Identify potential false-positive findings and review with ITD for validity.
  5. Collaborate with ITD to prioritize system vulnerability remediation and patching based on system risk severity, vulnerability exploitability, asset criticality, and potential business impact.
  6. Track identified vulnerabilities through remediation and/or mitigation, validate remediation through re-scanning or review of appropriate supporting evidence, and generate regular system vulnerability remediation status reports.
  7. Monitor compliance of system vulnerability remediation based on pre-defined risk-based remediation targets. Escalate critical or significant delays of system vulnerability remediation based on pre-defined targets to Management, as necessary.
  8. Create vulnerability management-related reports with risk summaries and recommendations to Management.
  9. Perform risk assessments on proposed new systems to be introduced to the organization.
  10. Perform other duties and responsibilities as assigned by management.


Your Qualifications:

  1. Strong understanding and prior experience working with network components and devices such as Firewalls, IPS, IDS, switches, routers, NDR, and NAC.
  2. Strong understanding and prior experience working with Microsoft Windows-based environments including components such as domain controllers, DHCP, DNS, and Active Directory.
  3. Foundational understanding of Information Security frameworks such as NIST Cybersecurity Framework and SP 800-53 as well as Cyber Risk Institute Profile v2.x
  4. 3+ Years of experience managing System Vulnerability Management tools such as Qualys or Tenable.
  5. 3+ Years of experience with risk assessment methodologies and techniques
  6. Prior experience with financial industry structure and concepts a plus.
  7. Strong verbal and written communication skills.
  8. Strong analytical skills with attention to detail and accuracy.
  9. Self-motivated with good time management skills.


  • The Employee Benefits package includes: Paid Time Off, medical, HSA, vision, dental, FSA, 401(k), profit sharing, legal plan, cancer indemnity plan, disability insurance, life insurance, employee assistance program, commuter benefits, business travel accident, paid volunteer day, paid memberships, paid seminars, and tuition assistance.
  • We offer many socialization opportunities for wellness, financial wellbeing, runs/walks, team building, happy hours, and activities to support the Sustainable Developmental Goals.


Check out our LinkedIn for our employee experience: https://www.linkedin.com/company/smtbny

About Sumitomo Mitsui Banking Corporation

Sumitomo Mitsui Banking Corporation (SMBC) is a Japanese multinational banking and financial services company headquartered in Tokyo, Japan. It is the second-largest bank in Japan by assets and market capitalization. SMBC offers a wide range of financial services, including commercial banking, investment banking, asset management, leasing, and consumer finance. The bank has a global presence, with operations in over 40 countries and regions. SMBC is a member of the Mitsubishi UFJ Financial Group (MUFG), one of the largest financial groups in the world.
Learn more about Sumitomo Mitsui Banking Corporation
Size
101,023 employees
Market Cap
$54.6 billion
Industry
Net Income
$526.9 billion
5 Year Trend
-0.2%
NASDAQ

Similar Jobs

More Jobs at Sumitomo Mitsui Banking Corporation

  • Sumitomo Mitsui Banking Corporation
    Treasury Risk Analyst
    $110K — $130K *
    New York, NY 10025 (New York County)
    Finance & Insurance
    In-Person
  • Sumitomo Mitsui Banking Corporation
    Credit Analyst
    $70K — $95K *
    New York, NY 10025 (New York County)
    Finance & Insurance
    In-Person
  • Sumitomo Mitsui Banking Corporation
    Assistant General Counsel
    $150K — $200K *
    New York, NY 10025 (New York County)
    Legal & Accounting
    In-Person

More Information Technology Jobs

Find similar Information Security Risk Analyst jobs: