If you are a current FIB employee, please apply through the Career Worklet in the Employee Portal.
This position may be located at any of First Interstate Bank's offices in Idaho, Iowa, Missouri, Montana, Nebraska, Oregon, South Dakota, or Wyoming.
Benefits
- Generous Paid Time Off (PTO) in addition to paid federal holidays
- Student debt employer repayment program
- 401(k) retirement plan with a 6% match
SUMMARY
The IT Risk Analyst II is responsible for measuring and identifying technical risks within First Interstate Bank's (FIB) infrastructure and third‑party solutions. This position also performs testing to validate systems and application security configurations continue to meet industry and FIB architecture and security standards, establishes and leverages risk metrics and dashboards to continuously assess and report on technical risk, and provides guidance on IT security architecture and configurations based on the risks and controls evaluated.
ESSENTIAL DUTIES AND RESPONSIBILITIES
- Leverages technical knowledge to assist in developing and enhancing cyber and information security policies, procedures, and standards.
- Works with Enterprise Architecture to assist in developing and enhancing the information security architecture standards and IT security technology roadmaps.
- Researches and evaluates proposed new technologies and platforms to ensure the appropriate technical security controls are specified in the requirements and are in alignment with the security reference architecture and security controls framework.
- Provides security consulting on projects to ensure solutions are designed in accordance with security architecture and that security configurations are properly implemented.
- Performs technical security assessments against FIB’s existing infrastructure and products to ensure compliance with security architecture, policies, standards, procedures, and industry best practices.
- Monitors and matures the risk‑based IT security metrics, scorecards, and dashboards to track cybersecurity performance and trends across the organization.
- Assists the business in identifying root causes and develops mitigation for deficiencies.
- Works with various groups during product upgrades or new product design to ensure security best practices are implemented.
- Performs technical reviews of third‑party cyber and information risk.
- Researches emerging technologies in support of security enhancement and development efforts.
QUALIFICATIONS
- Knowledge of concepts and principles in information security functional areas such as cloud security, firewalls and security mediation services, identity and access management, industry standard security frameworks, security controls, and compliance frameworks.
- Strong oral, written, and interpersonal communication skills.
- Strong communication skills with all levels of the business and the ability to leverage knowledge of the appropriate approach and degree of detail for each.
- Remain up to date with emerging threats, best practices, and relevant frameworks, guidance, and legislation.
- Capable of managing varied assignments and working independently.
- Ability to define problems, collect data, establish facts, and draw valid conclusions.
- Ability to interpret an extensive variety of technical instructions in mathematical or diagram form and deal with several abstract and concrete variables.
- Experience with methods used in performing risk analyses and assessments and measuring cybersecurity compliance.
- Experience maintaining and updating documentation necessary for supporting security environments, including policies, standards, patterns, and reference architectures.
- Experience in working with compliance and regulatory program requirements.
EDUCATION AND/OR EXPERIENCE
- Bachelor's Degree in a related field (required).
- 4-6 years experience in IT security audit, architecture, engineer, risk monitoring, and/or equivalent combination of education and experience (required).
LICENSES AND CERTIFICATIONS
- Preferred: CISSP – Certified Information Systems Security Professional
- Preferred: CISA – Certified Information Systems Auditor
- Preferred: CEH – Certified Ethical Hacker
- Preferred: CCSP – Certified Cloud Security Professional
- Preferred: GSEC – GIAC Security Essentials Certification
- Preferred: GISP – GIAC Information Security Professional
PHYSICAL DEMANDS AND WORKING ENVIRONMENT
Dexterity of hands/fingers to operate computer keyboard and mouse; frequently lifting occasionally up to 50 lbs; sitting frequently; standing occasionally; noise level moderate. Typical work hours M–F, 8‑5. Regular and predictable attendance required.
EQUAL OPPORTUNITY EMPLOYER
First Interstate Bank is an equal opportunity employer committed to a diverse workforce and a barrier‑free employment process. Employment is based solely on an individual's merit and qualifications directly related to the position. We do not discriminate on the basis of race, color, religion, national origin, ancestry, pregnancy status, sex, age, marital status, disability, medical condition or any other characteristics protected by law. We make all reasonable accommodations to meet the obligations set forth under the Americans with Disabilities Act (ADA) and state disability laws.
All applicants must pass pre‑employment screenings including a background check. First Interstate Bank participates in E‑Verify, which requires new employees to verify their identity and employment eligibility.