Information Security Assurance Analyst - Sugar Land or Lubbock

Prosperity Bank

Lubbock (TX)

On-site

USD 90,000 - 130,000

Full time

12 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Prosperity Bank is seeking an Information Security Assurance Analyst to serve as a second line of defense, assessing cybersecurity controls, risk management effectiveness, and regulatory compliance across the bank. The role collaborates with IT, risk management, information security, and business stakeholders to strengthen governance and control oversight.

The ideal candidate has a bachelor's degree in a related field and 3+ years of security and risk experience, with preferred certifications.

Qualifications

  • Education: Bachelor's degree in Cybersecurity, IT, Computer Science or related field.
  • Certifications preferred: CISSP, CRISC, CGRC, CISA, CISM, Security+, CySA+, GPEN, GSEC or equivalent.
  • Experience: Minimum of 3 years in information security, cybersecurity risk management, governance or related discipline.
  • Experience performing risk assessments, control evaluations, and assurance activities.
  • Experience with frameworks like NIST CSF, FFIEC guidance, CIS controls, CRI Profile.

Responsibilities

  • Evaluate cybersecurity controls, architectures, governance, and risk practices for design adequacy and operating effectiveness.
  • Assess risks from technology initiatives, third parties, and emerging tech.
  • Identify risk exposures, recommend mitigations, and monitor remediation activities.
  • Review evidence supporting control implementation and compliance with regulatory requirements.
  • Develop risk observations, findings, and recommendations for leadership and governance committees.
  • Maintain risk assurance metrics and dashboards for cybersecurity risk insight.

Skills

Written communication
Verbal communication
Presentation skills
Risk assessment
Control evaluation
Reporting
Analytical thinking

Education

Bachelor's degree in Cybersecurity, IT, or CS
Relevant professional certifications (CISSP, CRISC, CISA, CISM, Security+)

Job description

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.

Information Security Assurance Analyst - Sugar Land or Lubbock

Full Time Security Analyst LUBBOCK ANNEX, Lubbock, TX, US

2 days ago Requisition ID: 10971

Prosperity Bank is an Equal Opportunity Employer.

POSITION PURPOSE

The Information Security Assurance Analyst serves as an independent second line of defense resource responsible for assessing cybersecurity controls, evaluating risk management effectiveness, performing assurance activities, and monitoring compliance with cybersecurity policies, standards, regulatory requirements, and industry frameworks. The role conducts cybersecurity risk and control assessments, evaluates control design and effectiveness, monitors remediation of identified issues, and provides objective analysis, reporting, and recommendations to support risk-informed decision-making. The position collaborates with Information Technology, Enterprise Risk Management, Information Security, and business stakeholders to strengthen cybersecurity governance, risk management, and control oversight across the Bank.

ESSENTIAL FUNCTIONS AND BASIC DUTIES
  • Evaluate cybersecurity controls, technology architectures, control designs, governance processes, and risk management practices to assess design adequacy, operating effectiveness, risk mitigation, alignment with the Bank's risk appetite, and opportunities for control and risk management improvement.
  • Assess cybersecurity risks associated with technology initiatives, third parties, significant changes, and emerging technologies.
  • Identify and prioritize cybersecurity risk exposures, recommend risk mitigation strategies, and monitor and validate remediation activities and corrective actions.
  • Review and evaluate evidence supporting cybersecurity control implementation and effectiveness to determine compliance with regulatory, policy, and framework requirements.
  • Review the adequacy of corrective action plans and validate closure of cybersecurity findings, issues, and risk treatment activities.
  • Partner with cross-functional teams to assess compliance with cybersecurity standards and evaluate the effectiveness of security controls supporting business processes, technology solutions, and third-party services.
  • Collaborate across operational, third-party, and data governance risk domains to evaluate risk management practices and support risk assurance activities.
  • Strengthen cybersecurity governance by providing independent, risk-based assessments and recommendations to improve control effectiveness and risk management practices.
  • Monitor emerging threats, attack vectors, and vulnerabilities to evaluate potential impacts to the Bank and identify areas requiring additional risk oversight or control improvements.
  • Develop assurance reports, risk observations, findings, and recommendations for Information Security leadership and governance committees.
  • Develop, maintain, and report risk assurance metrics and dashboards that provide meaningful insight into cybersecurity risk, control effectiveness, and remediation activities.
  • Serve as a cybersecurity assurance subject matter expert during regulatory examinations, audits, and independent assessments.
  • Maintain effective communication with internal and external stakeholders to ensure timely and accurate cybersecurity risk awareness.
  • Participate in security meetings and contribute to the development of risk assurance policies and procedures.

The above statements describe the general nature and level of work only. They are not an exhaustive list of all required responsibilities, duties, and skills. Other duties may be added, or this job description amended at any time.

SUPERVISORY RESPONSIBILITIES:

This position has no supervisory role.

QUALIFICATIONS

Education/Certification: Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, a related discipline, or the equivalent of combined education and related work experience.

Professional certifications such as CISSP, CRISC, CGRC, CISA, CISM, Security+, CySA+, GPEN, GSEC, or equivalent certifications are preferred.

Experience Required: Minimum of 3 years of experience in information security, cybersecurity risk management, security assurance, governance, risk and compliance (GRC), information technology auditing, security architecture, security engineering, or a related cybersecurity discipline.

Experience performing cybersecurity risk assessments, control evaluations, control effectiveness reviews, assurance activities, compliance assessments, audit support, or related oversight and risk management functions.

Experience applying cybersecurity frameworks and standards, including the Cyber Risk Institute (CRI) Profile, NIST Cybersecurity Framework (CSF), FFIEC guidance, CIS Critical Security Controls, or similar industry frameworks.

Experience evaluating cybersecurity controls, reviewing evidence, assessing remediation activities, and developing risk-based findings, recommendations, or reporting.

Experience supporting internal audits, external audits, regulatory examinations, independent assessments, or assurance reviews in a regulated environment.

Demonstrated ability to successfully execute initiatives in complex and highly regulated environments.

Banking or financial services industry experience preferred.

Required Knowledge: Knowledge of information security governance, risk management, compliance, and assurance principles.

Knowledge of banking cybersecurity regulations, guidance, and frameworks, including FFIEC, GLBA, NIST Cybersecurity Framework (CSF), Cyber Risk Institute (CRI) Profile, and applicable regulatory requirements.

Knowledge of cybersecurity threats, vulnerabilities, attack techniques, technology risks, and risk assessment methodologies.

Knowledge of information security control design, implementation, testing, and effectiveness assessment.

Knowledge of risk-based control assessment techniques, including evidence evaluation, validation, documentation, and assurance review practices.

Knowledge of enterprise technology and security architecture concepts sufficient to assess cybersecurity risks and control effectiveness.

Knowledge of cybersecurity principles and practices, including confidentiality, integrity, availability, defense-in-depth, access control, encryption, and threat mitigation strategies.

Knowledge of system lifecycle management, secure-by-design principles, software security, third-party risk management, and data governance concepts.

Knowledge of cybersecurity risk metrics, quantification methodologies, trend analysis, and governance reporting techniques.

Skills/Abilities: Strong written, verbal, and presentation skills.

Ability to communicate cybersecurity risks and control issues to technical and non-technical audiences.

Ability to assess security controls and determine effectiveness.

Ability to identify cybersecurity risks, evaluate severity and business impact, and recommend practical mitigation strategies.

Ability to evaluate security architectures, designs, and technology implementations from a risk perspective.

Ability to perform security assurance reviews, risk assessments, and control effectiveness evaluations.

Ability to review and evaluate evidence supporting cybersecurity control implementation and effectiveness.

Ability to assess corrective action plans and validate remediation activities associated with cybersecurity findings, issues, and risk treatment plans.

Ability to analyze complex cybersecurity data and identify trends, weaknesses, and emerging risks.

Ability to develop clear, concise, and defensible reports, dashboards, findings, and recommendations.

Ability to interpret cybersecurity laws, regulations, standards, policies, and contractual requirements.

Ability to build effective relationships while maintaining appropriate independence and objective challenge.

PHYSICAL ACTIVITIES AND REQUIREMENTS OF THIS POSITION

Talking: Especially where one must frequently convey detailed or important instructions or ideas accurately, loudly, or quickly.

Average Hearing: Able to hear average or normal conversations and receive ordinary information.

Repetitive Motion: Movements frequently and regularly required using the wrists, hands, and/or fingers.

Average Visual Abilities: Average, ordinary, visual acuity necessary to prepare or inspect documents or products, or operate machinery.

Physical Strength: Sedentary work; sitting most of the time. Exerts up to 10 lbs. of force occasionally. (Almost all office jobs.)

WORKING CONDITIONS

None: No hazardous or significantly unpleasant conditions (such as in a typical office).

MENTAL ACTIVITIES AND REQUIREMENTS OF THIS POSITION

Reasoning Ability: Ability to apply logical or scientific thinking to define problems, collect data establish facts and draw conclusions.

Able to interpret a variety of technical instructions and deal with multiple variables.

Mathematics Ability: Understanding of concepts such as probability, statistics, and basic algebra.

Language Ability: Ability to read periodicals, journals, manuals, dictionaries, thesauruses, and encyclopedias.

Ability to prepare business letters, proposals, summaries, and reports using prescribed format and conforming to all rules of punctuation, grammar, diction, and style.

Ability to conduct training, communicates at panel discussions, and make professional presentations.

Monday - Friday: 8:00AM - 5:00PM
40 hours

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.

Information Security Assurance Analyst - Sugar Land or Lubbock

Full Time Security Analyst LUBBOCK ANNEX, Lubbock, TX, US

2 days ago Requisition ID: 10971

Prosperity Bank is an Equal Opportunity Employer.

POSITION PURPOSE

The Information Security Assurance Analyst serves as an independent second line of defense resource responsible for assessing cybersecurity controls, evaluating risk management effectiveness, performing assurance activities, and monitoring compliance with cybersecurity policies, standards, regulatory requirements, and industry frameworks. The role conducts cybersecurity risk and control assessments, evaluates control design and effectiveness, monitors remediation of identified issues, and provides objective analysis, reporting, and recommendations to support risk-informed decision-making. The position collaborates with Information Technology, Enterprise Risk Management, Information Security, and business stakeholders to strengthen cybersecurity governance, risk management, and control oversight across the Bank.

ESSENTIAL FUNCTIONS AND BASIC DUTIES
  • Evaluate cybersecurity controls, technology architectures, control designs, governance processes, and risk management practices to assess design adequacy, operating effectiveness, risk mitigation, alignment with the Bank's risk appetite, and opportunities for control and risk management improvement.
  • Assess cybersecurity risks associated with technology initiatives, third parties, significant changes, and emerging technologies.
  • Identify and prioritize cybersecurity risk exposures, recommend risk mitigation strategies, and monitor and validate remediation activities and corrective actions.
  • Review and evaluate evidence supporting cybersecurity control implementation and effectiveness to determine compliance with regulatory, policy, and framework requirements.
  • Review the adequacy of corrective action plans and validate closure of cybersecurity findings, issues, and risk treatment activities.
  • Partner with cross-functional teams to assess compliance with cybersecurity standards and evaluate the effectiveness of security controls supporting business processes, technology solutions, and third-party services.
  • Collaborate across operational, third-party, and data governance risk domains to evaluate risk management practices and support risk assurance activities.
  • Strengthen cybersecurity governance by providing independent, risk-based assessments and recommendations to improve control effectiveness and risk management practices.
  • Monitor emerging threats, attack vectors, and vulnerabilities to evaluate potential impacts to the Bank and identify areas requiring additional risk oversight or control improvements.
  • Develop assurance reports, risk observations, findings, and recommendations for Information Security leadership and governance committees.
  • Develop, maintain, and report risk assurance metrics and dashboards that provide meaningful insight into cybersecurity risk, control effectiveness, and remediation activities.
  • Serve as a cybersecurity assurance subject matter expert during regulatory examinations, audits, and independent assessments.
  • Maintain effective communication with internal and external stakeholders to ensure timely and accurate cybersecurity risk awareness.
  • Participate in security meetings and contribute to the development of risk assurance policies and procedures.

The above statements describe the general nature and level of work only. They are not an exhaustive list of all required responsibilities, duties, and skills. Other duties may be added, or this job description amended at any time.

SUPERVISORY RESPONSIBILITIES:

This position has no supervisory role.

QUALIFICATIONS

Education/Certification: Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, a related discipline, or the equivalent of combined education and related work experience.

Professional certifications such as CISSP, CRISC, CGRC, CISA, CISM, Security+, CySA+, GPEN, GSEC, or equivalent certifications are preferred.

Experience Required: Minimum of 3 years of experience in information security, cybersecurity risk management, security assurance, governance, risk and compliance (GRC), information technology auditing, security architecture, security engineering, or a related cybersecurity discipline.

Experience performing cybersecurity risk assessments, control evaluations, control effectiveness reviews, assurance activities, compliance assessments, audit support, or related oversight and risk management functions.

Experience applying cybersecurity frameworks and standards, including the Cyber Risk Institute (CRI) Profile, NIST Cybersecurity Framework (CSF), FFIEC guidance, CIS Critical Security Controls, or similar industry frameworks.

Experience evaluating cybersecurity controls, reviewing evidence, assessing remediation activities, and developing risk-based findings, recommendations, or reporting.

Experience supporting internal audits, external audits, regulatory examinations, independent assessments, or assurance reviews in a regulated environment.

Demonstrated ability to successfully execute initiatives in complex and highly regulated environments.

Banking or financial services industry experience preferred.

Required Knowledge: Knowledge of information security governance, risk management, compliance, and assurance principles.

Knowledge of banking cybersecurity regulations, guidance, and frameworks, including FFIEC, GLBA, NIST Cybersecurity Framework (CSF), Cyber Risk Institute (CRI) Profile, and applicable regulatory requirements.

Knowledge of cybersecurity threats, vulnerabilities, attack techniques, technology risks, and risk assessment methodologies.

Knowledge of information security control design, implementation, testing, and effectiveness assessment.

Knowledge of risk-based control assessment techniques, including evidence evaluation, validation, documentation, and assurance review practices.

Knowledge of enterprise technology and security architecture concepts sufficient to assess cybersecurity risks and control effectiveness.

Knowledge of cybersecurity principles and practices, including confidentiality, integrity, availability, defense-in-depth, access control, encryption, and threat mitigation strategies.

Knowledge of system lifecycle management, secure-by-design principles, software security, third-party risk management, and data governance concepts.

Knowledge of cybersecurity risk metrics, quantification methodologies, trend analysis, and governance reporting techniques.

Skills/Abilities: Strong written, verbal, and presentation skills.

Ability to communicate cybersecurity risks and control issues to technical and non-technical audiences.

Ability to assess security controls and determine effectiveness.

Ability to identify cybersecurity risks, evaluate severity and business impact, and recommend practical mitigation strategies.

Ability to evaluate security architectures, designs, and technology implementations from a risk perspective.

Ability to perform security assurance reviews, risk assessments, and control effectiveness evaluations.

Ability to review and evaluate evidence supporting cybersecurity control implementation and effectiveness.

Ability to assess corrective action plans and validate remediation activities associated with cybersecurity findings, issues, and risk treatment plans.

Ability to analyze complex cybersecurity data and identify trends, weaknesses, and emerging risks.

Ability to develop clear, concise, and defensible reports, dashboards, findings, and recommendations.

Ability to interpret cybersecurity laws, regulations, standards, policies, and contractual requirements.

Ability to build effective relationships while maintaining appropriate independence and objective challenge.

PHYSICAL ACTIVITIES AND REQUIREMENTS OF THIS POSITION

Talking: Especially where one must frequently convey detailed or important instructions or ideas accurately, loudly, or quickly.

Average Hearing: Able to hear average or normal conversations and receive ordinary information.

Repetitive Motion: Movements frequently and regularly required using the wrists, hands, and/or fingers.

Average Visual Abilities: Average, ordinary, visual acuity necessary to prepare or inspect documents or products, or operate machinery.

Physical Strength: Sedentary work; sitting most of the time. Exerts up to 10 lbs. of force occasionally. (Almost all office jobs.)

WORKING CONDITIONS

None: No hazardous or significantly unpleasant conditions (such as in a typical office).

MENTAL ACTIVITIES AND REQUIREMENTS OF THIS POSITION

Reasoning Ability: Ability to apply logical or scientific thinking to define problems, collect data establish facts and draw conclusions.

Able to interpret a variety of technical instructions and deal with multiple variables.

Mathematics Ability: Understanding of concepts such as probability, statistics, and basic algebra.

Language Ability: Ability to read periodicals, journals, manuals, dictionaries, thesauruses, and encyclopedias.

Ability to prepare business letters, proposals, summaries, and reports using prescribed format and conforming to all rules of punctuation, grammar, diction, and style.

Ability to conduct training, communicates at panel discussions, and make professional presentations.

Monday - Friday: 8:00AM - 5:00PM
40 hours

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Assurance Analyst - Sugar Land or Lubbock
Information Security Assurance Analyst - Sugar Land or Lubbock

Prosperity Bank and Trust Co • Lubbock (TX)

On-site
USD 90,000 - 125,000
Information Security Assurance Analyst - Sugar Land or Lubbock
Information Security Assurance Analyst - Sugar Land or Lubbock

Prosperity Bank • Sugar Land (TX)

On-site
USD 90,000 - 120,000
Credit Monitoring Analyst - Houston/Lubbock/DFW/South Texas
Credit Monitoring Analyst - Houston/Lubbock/DFW/South Texas

Prosperity Bank • Sugar Land (TX)

On-site
USD 65,000 - 90,000
FT Systems Administrator - Austin, Houston, & San Antonio
FT Systems Administrator - Austin, Houston, & San Antonio

Prosperity Bank and Trust Co • Austin (TX), Northern (KY)

Hybrid
USD 95,000 - 135,000
FT Systems Administrator - Austin, Houston, & San Antonio
FT Systems Administrator - Austin, Houston, & San Antonio

Prosperity Bank • Austin (TX), Northern (KY)

Hybrid
USD 65,000 - 90,000
Floater (Full Time) - SB Katy, Westgreen
Floater (Full Time) - SB Katy, Westgreen

Prosperity Bank • Katy (TX)

Hybrid
USD 35,000 - 48,000
Personal Banker (Full Time) - Orange
Personal Banker (Full Time) - Orange

Prosperity Bank • Town of Texas (WI), Northern (KY)

Hybrid
USD 38,000 - 52,000
Personal Banker (Full Time) - SB Kirby
Personal Banker (Full Time) - SB Kirby

Prosperity Bank and Trust Co • Houston (TX), Northern (KY)

Hybrid
USD 35,000 - 55,000
SBA Junior Credit Analyst - Rock Prairie
SBA Junior Credit Analyst - Rock Prairie

Prosperity Bank and Trust Co • College Station (TX)

On-site
USD 52,000 - 70,000
Personal Banker (Full Time) - SB Kirby
Personal Banker (Full Time) - SB Kirby

Prosperity Bank • Houston (TX), Northern (KY)

On-site
USD 42,000 - 56,000