Sumitomo Mitsui Banking Corporation

Third Party Information Security Analyst

Finance & Insurance
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3+ years of experience in risk assessment and Third Party Risk Management (TPRM) lifecycle.
  • Familiarity with financial industry structures and concepts is advantageous.
  • Experience using TPRM platforms like Prevalent is preferred.
  • Proficient in analyzing information security documentation such as SOC 2 and ISO 27001 reports.
  • In-depth understanding of NIST Cybersecurity Framework, ISO/IEC 27001, and Cyber Risk Institute profiles.
  • Strong skills in Microsoft Office suite, particularly for documentation and reporting.
  • Excellent verbal and written communication skills.

Responsibilities

  • Conduct initial and continuous information security risk assessments of third parties.
  • Review security documentation from third parties, including SOC reports and ISO 27001 certifications.
  • Document findings and maintain tracking sheets in the TPRM platform.
  • Coordinate with teams for vendor onboarding and offboarding focused on information security risks.
  • Monitor information security incidents involving third parties and assess potential impacts.
  • Participate in internal audits and external examinations related to third party risk management.
  • Assist in maintaining TPRM policies and procedures.

Benefits

  • Paid Time Off, medical, HSA, vision, dental, FSA, and 401(k).
  • Profit sharing, legal plan, cancer indemnity plan, disability insurance, and life insurance.
  • Employee assistance program and commuter benefits.
  • Paid volunteer day, memberships, seminars, and tuition assistance.
  • Opportunities for wellness socialization, financial wellbeing, and team-building activities.
Full Job Description
This role is located in New York City and will require a hybrid work schedule of at least 2 days in office per week.

This role is for Officer level candidates.

Department Overview:

The Americas Division ("AD") was established in the Sumitomo Mitsui Trust Bank, Limited, New York Branch) ("SMTBNY") to perform corporate functions and supervise U.S. entities. Established under the AD are the "Global Banking Unit ("GBU"), Americas Division" and "Global Markets Unit ("GMU"), Americas Division" which performs business functions. Information Risk Governance ("IRG") provides oversight to information and cyber security risk by maintaining and improving branch wide framework that is in-line with the Head Office and regulatory requirements and addresses Confidentiality, Integrity, and Availability for information assets. IRG establishes appropriate policies, procedures, measurement, and monitoring processes to proactively assess and evaluate and cyber security and information security risks inherent in the Branch Operations. IRG is directly involved in all information and cyber security related projects, matters and issues.

Your Role Overview:

The Third Party Information Security Analyst supports the Bank's Third Party Risk Management function by focusing on assessing and monitoring information security risks associated with 3rd, 4th, Nth parties. This role assists with vendor due diligence, security reviews, information security risk assessments, and ongoing monitoring activities to ensure these third party relationships align with the organization's security requirements.

Your Duties and Responsibilities:

  1. Conduct initial and continuous information security risk assessments of third (Nth) parties.
  2. Review third party provided security documentation including SOC reports, ISO 27001 certifications, security questionnaires, and Business Continuity and Disaster Recovery documentation.
  3. Document assessment findings and risk ratings in the Bank's TPRM platform and maintain an up-to-date tracking sheet that provides management with clear visibility into the status, due date, and completion of each assessment and related follow-up actions.
  4. For vendor due-diligence, with a focus on information security risks, coordinate with relevant Teams (Administration, Legal, etc.) for vendor onboarding and offboarding activities
  5. Perform on-going monitoring of information security-related incidents involving third-parties and coordinate with relevant stakeholders to facilitate requests for necessary information from the relevant third-parties and support the assessment of potential impact to the Bank.
  6. Participate in internal audits and external examinations related to the information security risk domains of third party risk management
  7. Assist in maintaining information security-related TPRM policies and procedures.
  8. Performs other duties and responsibilities as assigned by management.


Your Qualifications:

  1. 3+ Years of experience with risk assessment methodologies and techniques as well as Third Party Risk Management Lifecycle.
  2. Prior experience with financial industry structure and concepts a plus.
  3. Prior experience working on a Third Party Risk Management (TPRM) platform, such as Prevalent.
  4. Prior experience working with and assessing information security-related documentation such as SOC 2 reports, ISO 27001 certification, etc.
  5. Strong knowledge of information security and risk management frameworks, including NIST Cybersecurity Framework, ISO/IEC 27001, and the Cyber Risk Institute Profile.
  6. Strong Microsoft Office skills
  7. Strong verbal and written communication skills.
  8. Strong analytical skills
  9. Self-motivated with good time management skills.


  • The Employee Benefits package includes: Paid Time Off, medical, HSA, vision, dental, FSA, 401(k), profit sharing, legal plan, cancer indemnity plan, disability insurance, life insurance, employee assistance program, commuter benefits, business travel accident, paid volunteer day, paid memberships, paid seminars, and tuition assistance.
  • We offer many socialization opportunities for wellness, financial wellbeing, runs/walks, team building, happy hours, and activities to support the Sustainable Developmental Goals.


Check out our LinkedIn for our employee experience: https://www.linkedin.com/company/smtbny

About Sumitomo Mitsui Banking Corporation

Sumitomo Mitsui Banking Corporation (SMBC) is a Japanese multinational banking and financial services company headquartered in Tokyo, Japan. It is the second-largest bank in Japan by assets and market capitalization. SMBC offers a wide range of financial services, including commercial banking, investment banking, asset management, leasing, and consumer finance. The bank has a global presence, with operations in over 40 countries and regions. SMBC is a member of the Mitsubishi UFJ Financial Group (MUFG), one of the largest financial groups in the world.
Learn more about Sumitomo Mitsui Banking Corporation
Size
101,023 employees
Market Cap
$54.6 billion
Industry
Net Income
$526.9 billion
5 Year Trend
-0.2%
NASDAQ

Similar Jobs

More Jobs at Sumitomo Mitsui Banking Corporation

More Finance & Insurance Jobs

Find similar Third Party Information Security Analyst jobs: