Security Assurance Analyst III

Credit One Bank

Las Vegas (NV)

On-site

USD 85,000 - 120,000

Full time

9 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Credit One Bank in Las Vegas is seeking an Assurance Analyst to perform second-line testing of information security controls within the 3-Lines of Defense framework. You will assess, document, and report on control effectiveness and drive automation of existing controls.

Ideal candidates have 3+ years in IT/security, knowledge of EDR and IAM, and strong communication skills for assessments and test reports. Collaboration with IT and risk teams is essential.

Qualifications

  • Bachelor's degree in IT/InfoSec or related field.
  • 3+ years IT or IS security experience.
  • Knowledge of security controls and technologies (EDR, logs, IAM).
  • Strong written/verbal communication suitable for reports.

Responsibilities

  • Test IT controls per KPI/KRI.
  • Verify confidentiality, integrity, availability of data and tech.
  • Contribute to risk assessments and control self-assessments.
  • Coordinate with IT leaders and risk personnel on risk/vulnerability assessments.
  • Automate testing and design additional control tests.
  • Support threat intelligence and security operations as needed.

Skills

Security testing
EDR
Log management
IAM
Automation
Python
Threat intelligence
NIST 800-53

Education

Bachelors in IT / InfoSec / IS

Tools

AttackIQ
Verodin

Job description

Description

Position Summary

The position is responsible for conducting second-line testing in accordance with the 3-Lines of Defense operating model and a layered defense-in-depth information security (IS) architecture. As part of the Information Security Program Assurance team, the assurance analyst is ultimately concerned with ensuring risk and controls are effectively managed.

In that capacity, the incumbent is responsible for testing, analyzing, measuring, and documenting the overall effectiveness of information security and cybersecurity controls in accordance with established policies, procedures, and the Information Security Program in general. This position is primarily responsible for conducting security controls testing, monitoring, and reporting. In addition, the position will work towards automating existing controls as needed.

Essential Job Functions
  • Collaborate with Information Technology (IT) to execute comprehensive IT control testing using established Key Performance Indicators (KPI) and Key Risk Indicators (KRI)
  • Verify the confidentiality, integrity, and availability of data and technology through assessments and control frameworks
  • Contribute to periodic information security and cybersecurity risk assessments, information security controls self-assessments, control tests, and reviews to ensure control effectiveness
  • Coordinate with IT leaders, IT managers, IT individual contributors, and appropriate risk personnel on periodic risk and vulnerability assessments. Identity control gaps and opportunities for control enhancement and control enrichment
  • Coordinate with Information Security Operations and IT as needed to prepare control metrics (operational and functional), and to enhance control coverage and effectiveness
  • Participate in identifying and implementing tools, technologies, processes, and procedures to enhance the information security and cybersecurity controls testing, and monitoring programs
  • Exhibit a strong understanding of Information Security Operations, Architecture and dependent disciplines including Systems and Processes, Change Management, Databases, Business Continuity and Applications Controls
  • Automate control testing where possible
  • Design additional control tests
  • Function as an additional resource for threat intelligence, as needed
  • Perform other duties as assigned
Position Requirements
  • Bachelor’s Degree in Information Technology, Information Security, Information Assurance, Management of Information Systems, or similar discipline
  • 3+ years of Information Technology (IT) experience or Information Security (IS) experience. Hands on experience is critical.
  • Knowledge of information security controls and technology, particularly endpoint detection and response (EDR), log management, and identity and access management
  • Possess excellent written and verbal communication skills and be capable of interacting with all levels of management, with specific concentration on writing assessments and test reports
  • Ability to manage priorities and work independently
  • Exceptional analytical and problem-solving skillsWorks autonomously with minimal direction; motivated and self-driven
  • Develop and foster working relationships
  • Strong planning, organization, and documentation skills
  • Strong attention to detail
Preferred
  • Coding and/or scripting knowledge/experience. Knowledge of Python and/or APIs is a plus. Experience automating repetitive tasks is a strong plus
  • Experience with multiple security controls
  • Experience with Information Security controls testing platforms (AttackIQ, Verodin, etc.)
  • Compliance background/knowledge with Federal compliance and examination requirements, preferably in Financial Services
  • Knowledge of Payment Card Industry Data Security Standards (PCI-DSS)
  • Familiar with basic auditing principles
  • Security certification a strong plus (Security +, CISA, GSEC, etc.)
  • Knowledge of NIST 800-53 and 800-37 Rev 2
  • Knowledge in cloud security
  • Knowledge in Application Security and the Software Development Life Cycle (SDLC)
  • Threat Intel Platform (TIP) experience
  • MITRE ATT&CK Framework experience
  • Open Source Intelligence (OSINT) experience

Credit One Bank, N.A. is a data-driven financial services company based in Las Vegas. Founded in 1984, Credit One Bank offers a spectrum of credit card products for people in all stages of financial life. Credit One Bank is an equal opportunity employer committed to diversity and inclusion and does not discriminate against any employee or applicant for employment because of age, race, religion, color, disability, sex, sexual orientation, or national origin. Reasonable accommodations can be made for those who require them, including access to job applications and workplace accommodations. Employment at Credit One Bank is based on mutual consent (also known as at-will). This means that employees and the Bank may terminate the employment relationship at any time, with or without cause and with or without notice. Credit One Bank does not accept unsolicited resumes from agencies and is not responsible for related fees.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Technology Risk Analyst – Monitoring and Testing
Senior Technology Risk Analyst – Monitoring and Testing

Citizens Bank • Johnston (RI)

Hybrid
USD 90,000 - 120,000
Senior Technology Risk Analyst - Monitoring and Testing
Senior Technology Risk Analyst - Monitoring and Testing

Citizens Bank • United States

Hybrid
USD 90,000 - 120,000
Senior Technology Risk Analyst – Monitoring and Testing
Senior Technology Risk Analyst – Monitoring and Testing

Citizens • Johnston (RI)

Hybrid
USD 80,000 - 120,000
Career growth opportunities
Collaborative work environment
Sr. Technology Controls Testing Analyst
Sr. Technology Controls Testing Analyst

BankUnited • Miami (FL)

Hybrid
USD 110,000 - 160,000
Sr. Technology Controls Testing Analyst (Hybrid-Miami Lakes)
Sr. Technology Controls Testing Analyst (Hybrid-Miami Lakes)

BankUnited • Town of Florida (NY)

On-site
USD 90,000 - 150,000
Testing Analyst
Testing Analyst

INSPYR Solutions • Merrifield (VA)

Hybrid
USD 65,000 - 95,000
Manager, Cyber Security (Third Party Risk)
Manager, Cyber Security (Third Party Risk)

Capital One National Association • McLean (VA)

On-site
USD 197,000 - 225,000
Information Security Analyst
Information Security Analyst

TowneBank • Suffolk (VA)

On-site
USD 55,000 - 65,000
Cybersecurity Threat Analyst I (Hybrid)
Cybersecurity Threat Analyst I (Hybrid)

The Bancorp Bank, N.A. • Sioux Falls (SD)

Hybrid
USD 60,000 - 80,000
Manager, Cyber Security (Third Party Risk)
Manager, Cyber Security (Third Party Risk)

Capital One • Richmond (VA)

On-site
USD 179,000 - 205,000