수평: Associate

직업 종류: Contract

Loading ...

작업 내용

Information Security Analyst

On behalf of our client in the Banking Sector, PROCOM is looking for an Information Security Analyst.

Information Security Analyst – Job Description

  • Provide consultation and advice to ECF Delivery partners on a broad range Technology Controls / Information Security programs / policies / standards and incidents for own specialized area.
  • Provide consultation and advice to ECF Delivery partners on non-technical risk assessments/mitigation requirements as it applies to technology currency and as of interest to 2A partners.
  • Conduct 1B challenge against all ECF Epics to ensure technology currency risks are within mitigation plans, perform assessment of risks, definition of required controls, appropriateness of implemented control procedures, vulnerability assessments and any other relevant areas
  • Lead or contribute to completion of risk and control design assessments against applications being upgraded to adhere to the Currency Standards, articulate and document impact of control gaps to the business and the overall Bank, risk mitigation and remediation plans, remediation strategy document as applicable
  • Work comfortably in ambiguity, provide flexibility to deal with changes in a fast paced and new environment, working closely with peers where subject matter expertise is required.
  • Contribute to the completion of technology extended support contracts risk assessments to determine Vendor’s compliance levels against the Currency Security requirements. This may require direct contact with vendors and escalation to reporting manager where necessary.
  • Contribute to the definition, development, and oversight of a global security management strategy and framework
  • Ensure technology, processes, and governance are in place to monitor, detect, prevent, and react to both current and emerging technology / security threats against business
  • Develop on-going Currency Technology Risk reporting, monitoring key trends and defining metrics to regularly measure control effectiveness for own area
  • Work proactively with technology partners / stakeholders and service/platform owners to ensure all currency technology security components are integrated into the banks overall Enterprise Architecture, and any control gaps are addressed.
  • Consult and partner with other 2A Risk and Control partners (i.e., e-Tech ORM) to ensure 2A Challenge is incorporated in support of the 3 Line of Defense framework to oversee and challenge the execution of risk management activities and leading practices/technologies used to keep up with the constantly evolving cyber threat landscape.
  • Provide support and consulting in preparation for Audits and in composing management responses and appropriate remediation activities
  • Participate in computer security incident responses relevant to business (or enterprise wide) and represent respective function and Enterprise position to the business, and business needs to incident response team where necessary.
  • Adhere to internal policies / procedures, technology control standards, and applicable regulatory guidelines
  • Contribute to the review of internal processes and activities and assist in identifying potential opportunities for improvement
  • Adhere to and advise on / oversee / monitor / enforce enterprise frameworks and methodologies that relate to technology controls / information security activities
  • Influence behavior to reduce risk and foster a strong technology risk management culture throughout the enterprise
  • Remain informed of emerging issues, industry trends and/or relevant changes
  • Define / develop / implement / manage standards, policies, procedures, and solutions that mitigate risk and maximize security, availability of service, efficiency and effectiveness
  • Actively manage relationships with other areas of Technology / businesses / corporate and/or control functions and ensure alignment with enterprise and/or regulatory requirements
  • Keep abreast of emerging issues, trends, and evolving regulatory requirements and assess potential impacts to the Bank
  • Assess / identify key issues and escalate to appropriate levels and relevant stakeholders where required
  • Maintain a culture of risk management and control, supported by effective processes and sound infrastructure an in alignment with risk appetite
  • Participate in business specific / cross-functional / enterprise initiatives as a subject matter expert helping to identify risk / provide guidance
  • May develop / provide / contribute to complex reporting, analysis, and assessments at the functional or enterprise level
  • Continuously enhance knowledge / expertise in own area
  • Keep current on emerging trends / developments and grow knowledge of the business, analytical tools and techniques
  • Embrace changes and be flexible with the organization adaptation to NEW and Scaled Agile
  • Prioritize and manage own workload to deliver quality results and meet assigned timelines
  • Support a positive work environment that promotes service to the business, quality, innovation and teamwork and ensure timely communication of issues/ points of interest
  • Identify and recommend opportunities to enhance productivity, effectiveness and operational efficiency
  • Establish effective relationships across multiple business and technology partners, program and project managers
  • Participate in knowledge transfer within the team and business units

Information Security Analyst – Mandatory Skills

  • Expert knowledge of IT security and risk disciplines and practices
  • Advanced knowledge of organization, technology controls / security/ risk issues
  • May participate on complex, comprehensive or large projects and initiatives
  • Acts as a lead expert resource in technology controls / information security for project teams, the business / organization and/or outside vendors
  • Reports to Senior Manager or above
  • University degree
  • Information security certification / accreditation an asset 7+ years of relevant experience
  • Information Security – 7+ years
  • Review data sources – create Security findings using One Green
  • Risk Assessments/ Vulnerability management, Operational Management
  • JIRA
  • Agile

Information Security Analyst - Nice To Have Skills

  • RSA Archer – One Green
  • CISSP
  • Service Now
  • Cloud

Information Security Analyst - Assignment Start Date

ASAP – 6 months to start

Information Security Analyst - Assignment Location

Toronto, ON – Work Remotely
Loading ...
Loading ...

마감 시간: 21-06-2024

무료 후보 신청 클릭

대다

Loading ...
Loading ...

동일한 작업

Loading ...
Loading ...