Enable job alerts via email!

Chief Information Security Office-Security Services & Cyber Defense Associate

Bocusa

New York (NY)

On-site

USD 42,000 - 90,000

Full time

30+ days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a Security Services and Cyber Defense professional to enhance its information security program. This role involves providing critical support across Security Architecture, Engineering, and Operations, ensuring robust protection against cyber threats. You will be responsible for managing security tools, conducting vulnerability assessments, and collaborating with IT to implement effective security solutions. Join a dynamic team dedicated to safeguarding sensitive information while navigating regulatory requirements and best practices in cybersecurity. This is an exciting opportunity to make a significant impact in a leading financial institution.

Qualifications

  • 3+ years in Information Security and Cybersecurity roles.
  • Knowledge of security tools and systems administration.

Responsibilities

  • Provide security standards for applications and manage security monitoring tools.
  • Conduct vulnerability scans and manage remediation efforts.

Skills

Information Security
Cybersecurity
Vulnerability Management
Security Architecture
Network Security
Risk Management
Systems Administration
Regulatory Compliance

Education

Bachelor’s degree in Business, Computer Science, or related field

Tools

SIEM
DLP
XDR
EDR
Web Filter

Job description

Introduction

Established in 1912, Bank of China is one of the largest banks in the world, with over $3 trillion in assets and a footprint that spans more than 60 countries and regions. Our long-term outlook, institutional weight and global breadth provide our clients with a stable and reliable financial partner, whether in Corporate or Personal Banking or our Trade Services, Commodities, Financial Institutions and Global Markets lines of business.

Overview

This incumbent will provide Security Services and Cyber Defense functions as required to fulfill the Bank's information security program requirements. This incumbent will provide support to Security Architecture, Security Engineering, Security Operations, Identity & Access Management, Threat Management, Vulnerability Management and Penetration Testing functions.

Responsibilities

Security Architecture, Security Engineering & Security Operations

  • Provide Security Standards and requirements for all in-house and Third-Party applications being built or procured by the Bank
  • Provide support and expertise to IT to find security solutions that meet requirement
  • Manage assigned security monitoring tools for daily security monitoring which includes but not limited to: network devices, platforms, databases, applications
  • Design, configure and enhance assigned security tools for effective security event monitoring and escalate accordingly
  • Conduct assigned security tools rule and configuration validation and monitored devices recertification
  • Identify and escalate security issues and assist in cybersecurity incident investigations
  • Perform regular maintenance of assigned security tools including software upgrades, license updates and fine tuning of rules and configuration

Threat Management, Vulnerability Management & Penetration Testing

  • Conduct threat assessment and modeling as required
  • Conduct vulnerability scans of internal and external network
  • Present results to IT and partner to perform analysis, set criticality levels and assign timelines for remediation
  • Provide oversight of IT remediation, track and report all findings to the Information Security Committee
  • Coordinate penetration testing exercises in collaboration with IT
  • Present results to IT and partner to perform analysis, set criticality levels and assign timelines for remediation
  • Provide oversight of IT remediation, track and report all findings to the Information Security Committee

Identity & Access Management

Conduct User Recertification & Access Reviews throughout all BOC applications on a periodic basis

Qualifications
  • Bachelor’s degree in Business, Computer Science, Management Information Systems, Engineering, Mathematics, or related field is required
  • Minimum 3 years of work experience in Information security, cybersecurity, vulnerability management, security architecture, network, security tools and computer systems administration
  • Minimum 2 years of experience in risk management
  • Good understanding of regulatory requirements including FFIEC, GLBA, NIST

  • Knowledge of Information security and cyber security best practices

  • Knowledge of systems administration such as Windows Server, Active Directory management, Firewall, UNIX system, network architectures, etc.

  • Knowledge of security tools such as SIEM, DLP, XDR, EDR, Web Filter etc.

  • CISSP/CRISC/ or IT related certifications preferred

Pay Range

Actual salary is commensurate with candidate’s relevant years of experience, skillset, education and other qualifications.

USD $42,000.00 - USD $90,000.00 /Yr.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.