Senior Cybersecurity Risk Analyst (in-office)

Dime Community Bank

Hauppauge (NY)

On-site

USD 85,000 - 105,000

Full time

12 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Dime Community Bank in Hauppauge, NY is seeking a Senior Cybersecurity Risk Analyst to support the CISO in developing and maintaining the information security program and risk framework. This role collaborates with risk, IT and audit teams to assess controls, monitor risks, and ensure compliance with FFIEC, GLBA, NYS DFS, and other standards.

The position offers a challenging, collaborative environment with opportunities to influence security posture across the bank's lines of business and

Qualifications

  • Bachelor’s degree and minimum three years’ related experience and/or training; or equivalent combination of education and experience.
  • Knowledge of banking operations and bank policy and procedure development.
  • Knowledge of financial services regulatory requirements (FFIEC, GLBA, NYSDFS), and industry standards (NIST, ISO 27001/2).
  • CISSP or CISM (or comparable certification) preferred.
  • Experience administering GRC software.
  • Experience with Security Awareness Training and Testing Platforms.
  • Exposure to enterprise security tools (SIEM, vulnerability scanners, firewalls, identity governance and administration).
  • Demonstrated understanding of technological trends and developments in information security, risk management, and business continuity.
  • Demonstrated experience in the administration and management of the information security function, including FFIEC and DFS regulations and audits.
  • High regard for quality and risk management practices.
  • Excellent oral and written communication skills.
  • Ability to work outside of normal business hours on occasion.

Responsibilities

  • Plan, coordinate and develop recommendations for all aspects of information security policies and procedures.
  • Ensure compliance with information security policies across procedures and use; engage vendors and systems professionals to advance security goals.
  • Develop and maintain policies, standards, processes, and procedures to assess, monitor, report, elevate and remediate information security risks.
  • Ensure risk assessments are performed and controls tested; report results of the annual information security risk assessment.
  • Maintain the information security risk register and resolve compliance variances.
  • Develop and deliver activities to influence information security culture and staff awareness.
  • Present program status to Senior Management and the Board; coordinate audits and examinations.
  • Monitor regulatory environment to prepare for new laws, guidance, and frameworks.

Skills

Risk management
Information security
Regulatory knowledge
Communication skills
Security awareness training
Executive reporting

Education

Bachelor’s degree

Tools

GRC software
SIEM
Vulnerability scanners
Firewalls
Identity governance
Microsoft Office

Job description

Summary

Dime Community Bank is currently hiring for a Senior Cybersecurity Risk Analyst (“SCRA”) at its Headquarters in Hauppauge, Long Island. The SCRA is primarily responsible for assisting the Chief Information Security Officer (“CISO”) in the development, maintenance and monitoring of Dime’s Cybersecurity and Information Security Programs, which are designed to protect the confidentiality, integrity, and availability of Dime’s information systems. In fulfilling this responsibility, the SCRA will serve as a technical expert on information security policy and will be responsible for managing Dime’s Information Security Program. The SCRA will also work with Dime’s CISO and Chief Risk Officer (“CRO”) to develop, implement and maintain an effective cybersecurity risk framework.



Salary commensurate with experience, ranging from $85,000 to $105,000 annually. The exact compensation may vary based on relevant experience, skills, education, training, licensure and certifications, and location.



Dime does not provide relocation assistance or visa sponsorship (now or in the future).



Responsibilities


Overall, the CRA’s job is to work with Dime’s IT, Internal Audit, and Risk Management Departments and various business lines to plan, coordinate and develop recommendations for all aspects of information security policies and procedures in order to:




  • Ensure that the procedures and rules of use for information systems comply with Dime’s information security policies. Perform periodic reviews to assure that security policies and procedures are being complied with, as well as develop recommendations for improvements. Work with Dime’s business lines, vendors, and systems professionals to identify solutions to advance the bank’s information security goals.

  • Coordinate and assist in the development and maintenance of policies, standards, processes, and procedures to assess, monitor, report, elevate and remediate information security risks and related compliance issues.

  • Ensure that appropriate risk assessments are performed and that existing controls are periodically tested for effectiveness. Use metrics to measure, monitor and report on the effectiveness and efficiency of information security controls and compliance with information security policies. Conduct and report results of the annual information security risk assessment.

  • Maintain the information security risk register and ensure that compliance issues and other variances are resolved in a timely manner.

  • Ensure the development and delivery of activities and programs that can positively influence Dime’s information security culture and the related behavior of its staff, including information security education and awareness.

  • Present program status and updates on major deliverables to Senior Management and the Board of Directors. Engage and influence all areas of Dime to ensure that initiatives and activities are aligned with the information security program. Periodically conduct training and awareness campaigns with new and existing staff.

  • Act as Information Security’s primary point of contact with respect to internal and external audits and examinations, and coordinate efforts to gather and supply evidence to auditors and examiners.

  • Monitor the evolving regulatory environment to ensure that Dime identifies and prepares for new and changing laws, guidance, and frameworks.



Qualifications



  • Bachelor’s degree and minimum three years’ related experience and/or training; or equivalent combination of education and experience.

  • Knowledge of banking operations and bank policy and procedure development.

  • Knowledge of financial services regulatory requirements (FFIEC, GLBA, NYSDFS), and industry standards (NIST, ISO 27001/2).

  • CISSP or CISM (or comparable certification) preferred.

  • Experience administering GRC software.

  • Experience with Security Awareness Training and Testing Platforms.

  • Exposure to enterprise security tools preferred (i.e., SIEM, vulnerability scanners, firewalls, identity governance and administration).

  • Demonstrated understanding of technological trends and developments in the areas of information security, risk management, and business continuity.




  • Demonstrated experience in the administration and management of the information security function, including FFIEC and DFS regulations and audits.




  • High regard for quality and risk management practices.

  • Excellent oral and written communication skills.

  • Ability to work outside of normal business hours on occasion.

  • Superior knowledge of Microsoft Office products.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Risk Analyst (in-office)
Senior Cybersecurity Risk Analyst (in-office)

BNB Bank • Hauppauge (NY)

On-site
USD 85,000 - 105,000
Senior Cybersecurity Risk Analyst (in-office)
Senior Cybersecurity Risk Analyst (in-office)

Dime Commercial Bank • Hauppauge (NY)

On-site
USD 85,000 - 105,000
Network Security Engineer
Network Security Engineer

Dime Commercial Bank • Hauppauge (NY)

On-site
USD 100,000 - 115,000
Network Security Engineer
Network Security Engineer

BNB Bank • Hauppauge (NY)

On-site
USD 100,000 - 115,000
Senior Cybersecurity Risk Analyst — In-Office Banking
Senior Cybersecurity Risk Analyst — In-Office Banking

Dime Commercial Bank • Hauppauge (NY)

On-site
USD 85,000 - 105,000
Senior Cyber Risk & Compliance Strategist
Senior Cyber Risk & Compliance Strategist

Dime Community Bank • Hauppauge (NY)

On-site
USD 85,000 - 105,000
Network Security Engineer (in-office)
Network Security Engineer (in-office)

Dime Community Bank • Hauppauge (NY)

On-site
USD 100,000 - 115,000
Senior Cybersecurity Risk Analyst — In-Office Banking
Senior Cybersecurity Risk Analyst — In-Office Banking

BNB Bank • Hauppauge (NY)

On-site
USD 85,000 - 105,000
Senior Enhanced Due Diligence (EDD) Analyst (in-office)
Senior Enhanced Due Diligence (EDD) Analyst (in-office)

Dime Commercial Bank • Hauppauge (NY)

On-site
USD 73,000 - 83,000
Network Security Administrator I (in-office)
Network Security Administrator I (in-office)

Dime Community Bank • Hauppauge (NY)

On-site
USD 70,000 - 80,000