Title: IT Business Analyst
Location: New York, NY
Type: HYBRID
Client: SMBC
Pay: $75/Hour on W2
Duration: Contract
Position Summary
Enterprise Information Protection (EIP) organization is seeking an experienced IT Business Analyst contractor to support strategic Encryption and Post-Quantum Cryptography (PQC) initiatives. This role will provide project-based analysis, documentation, stakeholder coordination, and reporting support for enterprise cryptographic inventory, encryption modernization, and PQC readiness programs. The consultant will work across Security Engineering, Security Architecture, Infrastructure, Application Development, Risk, and Technology teams to facilitate requirements gathering, dependency tracking, and program execution. Activities align with EIP's focus on cryptographic inventory management and PQC readiness.
Scope of Work
Gather, analyze, and document business and technical requirements for encryption and PQC-related initiatives.
Coordinate workshops and meetings with technology and cybersecurity stakeholders.
Support enterprise cryptographic inventory and dependency identification efforts.
Document current-state and future-state processes, workflows, data flows, and control requirements.
Create and maintain project documentation, requirements traceability, RAID logs, and executive reporting.
Support vendor assessments, proof-of-concepts, and tool evaluations as needed.
Required Experience
7+ years of Business Analyst experience supporting technology or cybersecurity initiatives.
Strong requirements gathering and documentation skills.
Experience supporting enterprise-scale technology projects.
Financial services experience.
Cybersecurity, data protection, encryption, PKI, or key management experience.
Exposure to CRI & NIST cybersecurity standards.
Knowledge of cryptographic controls, certificate management, or crypto-agility concepts.
Familiarity with Post-Quantum Cryptography (PQC) initiatives and emerging regulatory expectations.
Lead enterprise cryptographic inventory and discovery efforts across applications, databases, cloud platforms, middleware, file systems, certificates, and key management systems.
Analyze and document cryptographic dependencies including:
TLS/SSL certificates
PKI infrastructure
HSM deployments
Key management solutions
Database encryption
File and disk encryption
Tokenization and data masking solutions
Support identification of legacy cryptographic algorithms and protocols including RSA, ECC, SHA-1, SHA-2, TLS versions, and certificate dependencies in preparation for PQC transition activities.
Partner with engineering teams to develop crypto-agility requirements and transition roadmaps.
Facilitate collection of encryption requirements for data at rest, data in transit, and data in use across enterprise environments.
Document cryptographic controls supporting:
Data Loss Prevention (DLP)
Database Security
Cloud Security
Identity & Access Management
Application Security
Third-Party Risk Management
Support evaluation and implementation planning for CRI & NIST Post-Quantum Cryptography standards and migration approaches.
Develop process flows and inventory models for cryptographic assets, certificates, keys, algorithms, and associated business owners.
Build reporting and dashboards tracking:
Cryptographic asset coverage
PQC readiness status
Encryption control maturity
High-risk cryptographic findings
Remediation milestones
Preferred Technical Experience
Knowledge of enterprise encryption technologies including AES-256, RSA, ECC, TLS, SSH, PGP, KMIP, and certificate lifecycle management.
Experience working with:
PKI platforms
Certificate Authorities
Hardware Security Modules (HSMs)
Key Management Systems (KMS)
Secrets Management platforms
Familiarity with cloud encryption technologies across AWS, Azure, and GCP.
Understanding of database encryption, transparent data encryption (TDE), column-level encryption, and tokenization.
Experience supporting cryptographic inventory or certificate inventory initiatives.
Familiarity with cryptographic scanning and discovery tools.
Understanding of NIST PQC algorithms (ML-KEM, ML-DSA, FN-DSA) and enterprise crypto-agility concepts.
Experience supporting regulatory requirements including NYDFS, FFIEC, PCI-DSS, and global banking security standards..
#CybersecurityBusinessAnalyst #CyberSecurity #CybersecurityJobs #BusinessAnalyst #ITBusinessAnalyst #SecurityBusinessAnalyst #CybersecurityAnalyst #InformationSecurity #InformationSecurityJobs #Encryption #Cryptography #PostQuantumCryptography #PQC #CryptoAgility #CryptographicInventory #PKI #PublicKeyInfrastructure #CertificateManagement #CertificateLifecycleManagement #HSM #HardwareSecurityModule #KMS #KeyManagement #SecretsManagement #TLS #SSL #RSA #ECC #AES256 #NIST #NISTPQC #MLKEM #MLDSA #FNSA #CloudSecurity #AWS #Azure #GCP #DatabaseSecurity #ApplicationSecurity #IAM #DLP #DataProtection #FinancialServices #BankingTechnology #CyberRisk #SecurityArchitecture #SecurityEngineering #NYDFS #FFIEC #PCIDSS #TechJobs #CybersecurityCareers #NYCJobs #NewYorkJobs
| Location | New York City, NY |
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.
Free resume templatesImprove your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.
Free resume builder