Chief Information Security Office-Security Services & Cyber Defense Associate

New York, NY, US • Posted 21 hours ago • Updated 8 hours ago
Full Time
On-site
USD 42,000.00 per year
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Microsoft Outlook
  • Banking
  • Commodities
  • Finance
  • Identity Management
  • Security Engineering
  • Security Operations
  • Database
  • Management
  • Threat Analysis
  • Modeling
  • Penetration Testing
  • Collaboration
  • Reporting
  • Computer Science
  • Management Information Systems
  • Mathematics
  • Vulnerability Management
  • Security Architecture
  • Network Security
  • Risk Management
  • FFIEC
  • Gramm-Leach-Bliley Act
  • Information Security
  • Cyber Security
  • System Administration
  • Microsoft Operating Systems
  • Microsoft Windows Server
  • Active Directory
  • Firewall
  • Unix
  • Network
  • SIEM
  • DLP
  • CISSP
  • ISACA

Summary

Introduction

Established in 1912, Bank of China is one of the largest banks in the world, with over $3 trillion in assets and a footprint that spans more than 60 countries and regions. Our long-term outlook, institutional weight and global breadth provide our clients with a stable and reliable financial partner, whether in Corporate or Personal Banking or our Trade Services, Commodities, Financial Institutions and Global Markets lines of business.

Overview

This incumbent will provide Security Services and Cyber Defense functions as required to fulfill the Bank's information security program requirements. This incumbent will provide support to Security Architecture, Security Engineering, Security Operations, Identity & Access Management, Threat Management, Vulnerability Management and Penetration Testing functions.

Responsibilities

Security Architecture, Security Engineering & Security Operations (45%)
  • Provide Security Standards and requirements for all in-house and Third-Party applications being built or procured by the Bank
  • Provide support and expertise to IT to find security solutions that meet requirement
  • Manage assigned security monitoring tools for daily security monitoring which includes but not limited to network devices, platforms, databases, applications
  • Design, configure and enhance assigned security tools for effective security event monitoring and escalate accordingly
  • Conduct assigned security tools rule and configuration validation and monitored devices recertification - Identify and escalate security issues and assist in cybersecurity incident investigations
  • Perform regular maintenance of assigned security tools including software upgrades, license updates and fine tuning of rules and configuration

Threat Management, Vulnerability Management & Penetration Testing (45%)
  • Conduct threat assessment and modeling as required
  • Conduct vulnerability scans of internal and external network
  • Present results to IT and partner to perform analysis, set criticality levels and assign timelines for remediation
  • Provide oversight of IT remediation, track and report all findings to the Information Security Committee
  • Coordinate penetration testing exercises in collaboration with IT
  • Present results to IT and partner to perform analysis, set criticality levels and assign timelines for remediation
  • Provide oversight of IT remediation, track and report all findings to the Information Security Committee

Qualifications

  • Bachelor's degree in business, Computer Science, Management Information Systems, Engineering, Mathematics, or related field is required.
  • Minimum 1 year of work experience in Information security, cybersecurity, vulnerability management, security architecture, network, security tools and computer systems administration, risk management.
  • Good understanding of regulatory requirements including FFIEC, GLBA, NIST.
  • Knowledge of Information security and cyber security best practices.
  • Knowledge of systems administration such as Windows Server, Active Directory management, Firewall, UNIX system, network architectures, etc.
  • Knowledge of security tools such as SIEM, DLP, XDR, EDR, Web Filter etc.
  • Good understanding of protocol behaviors, validity of identified vulnerabilities.
  • CISSP/CRISC/ or IT related certifications preferred.

Pay Range

Actual salary is commensurate with candidate's relevant years of experience, skillset, education and other qualifications.


USD $42,000.00 - USD $90,000.00 /Yr.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 80184657
  • Position Id: 548491813a72ee2363948f638f4f512f
  • Posted 21 hours ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

New York, New York

7d ago

Full-time

USD 300,000.00 - 360,000.00 per year

New York, New York

Today

Full-time

USD 78,000.00 - 124,750.00 per year

Secaucus, New Jersey

Today

Full-time

USD 160,000.00 - 170,000.00 per year

Remote

Today

Full-time

USD 96,500.00 - 207,500.00 per year

Search all similar jobs