Information
Security Senior Manager for a
contract assignment with one of our premier
financial services clients in lower Manhattan, NYC. Hybrid schedule 2x weekly onsite.
Reporting to the Senior Manager of Security Advisory (US Advisory), the Information Security Advisor provides guidance to business lines to ensure design, development and implementation of complex projects and initiatives are in accordance with the Bank's Information Security Standards and in compliance with industry regulations. In this role, you will be supporting various business lines while assisting them in making informed decisions to protect information assets deployed in various environments.
Responsibilities :
Provide strategic guidance and technical expertise to business lines, IT support functions, and IS&C Control functions to include security within early stages of the design of Bank s technological solutions.
Providing the following functions to Scotiabank's Initiatives:
Conducting Threat Risk Assessments and performing security advisory work on specific applications and infrastructure associated with Scotiabank's US subsidiaries and other Initiatives ensuring that controls are adequate, meet Bank standards, and enable business objectives.
Conducting Risk Management activities.
Provide Quality Assurance on Threat Risk Assessments and Threat Modelling as required for Cloud initiatives. Provide design and technical expertise on security solutions and recommend best practices.
Collaborate with cross-functional teams to design and implement robust security architectures for various systems, applications, and networks.
Evaluate existing security solutions and propose enhancements or new designs to address emerging threats and business requirements.
Ensure alignment with industry best practices, compliance standards, and organizational security policies.
Identify security weaknesses, vulnerabilities, and gaps in existing systems and recommend remediation strategies.
Provide support on how to apply the Bank's portfolio of standards to the technology footprint of Scotiabank's subsidiaries.
Provide oversight over the specific line of business security posture, ensuring that all tools available to detect and remediate security risks have been applied.
Conduct industry reviews and benchmarking exercises to ensure our controls are aligned with our peers, emerging threats, and available mitigation strategies.
Working directly with technical leads from assigned Lines of Businesses supporting their initiatives from an Information Security perspective.
Providing relationship management function primarily to US subsidiaries from an Information Security perspective.
Required Skills:
- 5+ years of hands-on technical working experience in performing security assessments on various platforms, network infrastructure and complex applications.
- 3+ years of Experience with Threat Risk Assessments of applications hosted on premise, cloud, hybrid cloud and SaaS.
- 2+ years of experience in security solution architecture, software development, and/or hands-on experience with implementations to various environments, knowledge of application security controls, including compensating controls and cloud-based security solutions
- 3+ experience reviewing and interpreting vulnerability reporting, server hardening requirements, and validating presence of controls through evidence
- Strong understanding of US regulatory regulations and practices
- You are a strong communicator and capable of creating clear documentation and communicating ideas to others
- You possess advanced communication (verbal/written/presentation) skills in English.
Preferred Skills:
- Prior experience using ServiceNow platform
- Basic knowledge of cloud technologies and cloud security (Google Cloud Platform or Azure or AWS
- Security engineering, security architecture, and/or security risk based certifications (CISSP, CISM, CCSP, CRISC)
- Familiar with industry standards and frameworks e.g., NIST 800-53, ISO 27001, ISO27002, ISO 27017, ISO27018, PCI DSS, CIS.
SGA is a technology and resource solutions provider driven to stand out. We are a women-owned business. Our mission: to solve big IT problems with a more personal, boutique approach. Each year, we match consultants like you to more than 1,000 engagements. When we say let's work better together, we mean it. You'll join a diverse team built on these core values: customer service, employee development, and quality and integrity in everything we do. Be yourself, love what you do and find your passion at work. Please find us at .
SGA is an Equal Opportunity Employer and does not discriminate on the basis of Race, Color, Sex, Sexual Orientation, Gender Identity, Religion, National Origin, Disability, Veteran Status, Age, Marital Status, Pregnancy, Genetic Information, or Other Legally Protected Status. We are committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, and our services, programs, and activities. Please visit our company to request an accommodation or assistance regarding our policy.
#LI-NI1