Information Technology Security Analyst

Socket.dev

Honesdale (Wayne County)

On-site

USD 90,000 - 130,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

The Bank is seeking an Information Security professional to support its security program at the Honesdale, PA location, focusing on security controls, AI governance, and regulatory compliance.

You will work with vendors and internal teams to audit AI tooling, manage encryption, SOC 2 considerations, and threat detection, with opportunities to enhance skills in a complex technology environment.

Qualifications

  • Strong written and verbal communication skills.
  • Familiar with regulatory requirements (GLBA, FFIEC, PCI-DSS).
  • Experience assessing data privacy risks in third‑party AI platforms and establishing secure guardrails.

Responsibilities

  • Supports the Bank’s Information Security Program by implementing security controls and processes.
  • Monitors and analyzes security alerts to identify threats and security incidents.
  • Review SOC 2 reports and AI governance policies of third‑party vendors for data handling.
  • Audit internal AI tool usage and configure access controls to protect proprietary data.
  • Perform vulnerability scans, analyze logs for anomalies, and participate in threat hunting.
  • Maintain and upgrade security safeguards including firewalls and encryption tools.

Skills

Communication
Regulatory knowledge
Risk assessment
Vendor collaboration
AI governance
Data privacy

Education

Bachelor's degree in IT / Cybersecurity / CS

Job description

Job Reporting Relationships

Supervised by: Network Services Manager

Supervises: N/A

Basic Qualifications
Education/Training:

Bachelor’s degree in information technology, Cybersecurity, Computer Science, or related field preferred, with strong knowledge of Microsoft Windows desktop and server operating systems. Working knowledge of network architecture, including LAN/WAN, firewalls, VPNs, and cloud environments. Familiarity with cybersecurity frameworks (NIST, ISO 27001, CIS, CRI). Relevant certifications preferred (e.g., Security+, CISSP, CISA, CEH) but not required.

Skill(s):

Strong written and verbal communication skills; Knowledge of regulatory requirements (GLBA, FFIEC, PCI-DSS, etc.) preferred; Analytical and problem-solving abilities with attention to detail. Understanding of identity and user access management standards. Ability to assess risk and assist in making recommended mitigation strategies. Ability to work collaboratively with vendors and technical peers and management in a complex technology environment. Proven experience evaluating the data privacy risks of third‑party generative AI platforms and establishing secure acceptable-use guardrails for corporate users.

Experience:

Minimum of one (1) year of experience in information security, IT security operations, or related field preferred.

General Responsibilities

Supports the Bank’s Information Security Program by assisting in the development, implementation, and maintenance of security technology, security controls and processes designed to protect information systems, networks, and data. Ensures compliance with internal policies, regulatory requirements, and industry best practices through monitoring, analysis, reporting, and continuous improvement activities.

Responds to inquiries relating to his/her area of responsibility, or to requests from other Bank personnel, within given time frames and within established policy.

Essential Duties

Assist with the Bank’s Information Security functions by performing the following duties:

  • a. Security Software & Hardware Management: Deploy, configure, maintain, and patch security technologies—including endpoints, firewalls, intrusion detection/prevention systems (IDS/IPS), SIEM platforms, anti‑malware/EDR tools, and data encryption solutions.
  • b. Testing and deploying critical security patches across servers, workstations, and network infrastructure to eliminate vulnerabilities without disrupting bank operations.
  • c. Reviewing alerts from the SIEM, firewall, and email security gateways (e.g., phishing filters) to distinguish between false positives and real threats.
  • d. Managing email security, authentication protocols (DKIM, SPF, DMARC) and spam/phishing filters to prevent fraud and business email compromise (BEC).
  • e. Manage Microsoft 365 Tenant, and email security gateway, data loss prevention and security controls.
  • f. Before turning on internal AI search tools, you must audit and clean up Active Directory and SharePoint permissions. (If a user has accidental access to HR or financial folders, the AI will surface that data to them).
  • g. Updating DLP policies with specific rules to detect, alert, and block financial data (SSNs, account numbers, routing numbers) or internal source code from being uploaded to external AI endpoints.
  • h. Securing the network pipelines and APIs that connect the bank’s databases to the AI models, ensuring all data in transit and at rest is strongly encrypted.
  • i. Conduct frequent testing of simulated cyber‑attacks to look for vulnerabilities in the computer systems and take care of these before an internal or external cyber‑attack.
  • j. Monitoring and configuring system boundaries to prevent attackers from manipulating the AI’s output or extracting sensitive training data via malicious prompts.
  • k. Reviewing the SOC 2 reports and "AI governance policies" of third‑party vendors to determine how they train their models, where the bank's data is stored, and if the data is used to train public models.
  • l. Audit internal AI tool usage and configure access controls to prevent the exposure of proprietary company data or customer PII.
  • m. Perform regular vulnerability scans, analyze system logs for anomalies or breach indicators, and participate in threat hunting and incident response activities.
  • n. Install, maintain, and upgrade software safeguards, including firewalls, data encryption programs, and anti‑malware.
  • o. Investigate cyberattacks, assess the extent of the damage, and coordinate mitigation and recovery efforts.
  • p. Develop and enforce cybersecurity best practices, develop disaster recovery plans for security systems and services, and ensure compliance with industry’s best practices and privacy laws.
  • q. Make recommendations to managers and senior executives about information security advancements to best protect the company’s systems.
  • r. Conducting and documenting quarterly or annual user access reviews to ensure the "principle of least privilege" is maintained.
  • s. Maintaining standard operating procedures, asset lists and other documentation that support the Information Technology and Security program.
  • t. Participating in data collection and presentment during risk assessments and regulatory exams.
  • u. Make recommendations to managers and senior executives about information security advancements to best protect the company’s systems.

Continuously analyze network traffic, activity logs, and system alerts for anomalies, intrusion attempts, and breaches.

Additional Responsibilities
  • a. Execute assigned projects and work with vendors as directed, in oversight and support of the Physical and Information Security infrastructure and solutions.
  • b. Participate in training as required for the Bank to meet regulatory requirements, recommend and assist in training/retraining of employees in their responsibilities for Information Security Programs.
  • c. Remain current on Information Technology and Information security trends and assist in Bank compliance with all federal and state laws. Attain certifications as required for the organization to meet vendor guidelines.
  • d. Complete incident response reporting for security events within the technology infrastructure.
  • e. Adjust to changing priorities as directed by supervisors or senior management.

Abides by the current laws and organizational policies and procedures designed and implemented to promote an environment which is free of harassment and other forms of illegal discriminatory behavior in the workplace

Cooperates with, participates in, and supports the adherence to all internal policies, procedures, and practices in support of risk management and overall safety and soundness and the Bank's compliance with all regulatory requirements; works to ensure that assigned personnel adhere to the same.

Reports pertinent information to the immediate supervisor as requested, or according to an established schedule; compiles information as necessary or as directed and provides data to appropriate Bank personnel to integrate goals and activities.

Ancillary Duties

1. Perform tasks which are supportive in nature of the essential functions of the job, but which may be altered or re‑designed depending upon individual circumstances.

Job Location

Support Center

1055 Texas Palmyra Highway

Honesdale, PA 18431

Various outside locations

Equipment/Machines
  • 1. Automobile with Valid Driver’s License
  • 2. Smartphone
  • 3. Computer Equipment
  • Multi-Function Print Devices
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Technology Security Analyst
Information Technology Security Analyst

The Dime Bank • Honesdale

On-site
USD 70,000 - 110,000
Information Security Analyst
Information Security Analyst

Bank of the Orient • Millbrae (CA)

On-site
USD 110,000 - 140,000
Information Security Application and Compliance Analyst
Information Security Application and Compliance Analyst

Vinson & Elkins • Mesquite (TX)

On-site
USD 95,000 - 125,000
Information Security Application and Compliance Analyst
Information Security Application and Compliance Analyst

Vinson & Elkins • Houston (TX)

On-site
USD 90,000 - 130,000
Information Security Application and Compliance Analyst
Information Security Application and Compliance Analyst

Vinson & Elkins • Dallas (TX)

Hybrid
USD 90,000 - 130,000
Cybersecurity Cybersecurity Threat Analyst I (Hybrid) Sioux Falls, SD
Cybersecurity Cybersecurity Threat Analyst I (Hybrid) Sioux Falls, SD

Bancorp Bank • Sioux Falls (SD), Northern (KY)

Hybrid
USD 55,000 - 85,000
Cybersecurity Threat Analyst I (Hybrid)
Cybersecurity Threat Analyst I (Hybrid)

Bancorp Bank • Sioux Falls (SD)

On-site
USD 65,000 - 85,000
Cybersecurity Threat Analyst I (Hybrid)
Cybersecurity Threat Analyst I (Hybrid)

The Bancorp Bank, N.A. • Sioux Falls (SD)

Hybrid
USD 60,000 - 80,000
Cybersecurity Threat Analyst I (Hybrid)
Cybersecurity Threat Analyst I (Hybrid)

The Bancorp Bank, N.A. • Wilmington (DE)

Hybrid
USD 65,000 - 85,000
Cybersecurity Threat Analyst I (Hybrid)
Cybersecurity Threat Analyst I (Hybrid)

The Bancorp • Wilmington (DE)

Hybrid
USD 65,000 - 90,000