Chief Information Security Office-Security Services & Cyber Defense Associate

Bank of China
  • New York, New York
  • $42,000–$90,000 Per Year
  • Full-time
4 days ago

Job Description

Introduction:

Established in 1912, Bank of China is one of the largest banks in the world, with over $3 trillion in assets and a footprint that spans more than 60 countries and regions. Our long-term outlook, institutional weight and global breadth provide our clients with a stable and reliable financial partner, whether in Corporate or Personal Banking or our Trade Services, Commodities, Financial Institutions and Global Markets lines of business.

Overview:

This incumbent will provide Security Services and Cyber Defense functions as required to fulfill the Bank's information security program requirements. This incumbent will provide support to Security Architecture, Security Engineering, Security Operations, Identity & Access Management, Threat Management, Vulnerability Management and Penetration Testing functions.

Responsibilities:

Security Architecture, Security Engineering & Security Operations (45%) 

  • Provide Security Standards and requirements for all in-house and Third-Party applications being built or procured by the Bank
  • Provide support and expertise to IT to find security solutions that meet requirement
  • Manage assigned security monitoring tools for daily security monitoring which includes but not limited to network devices, platforms, databases, applications
  • Design, configure and enhance assigned security tools for effective security event monitoring and escalate accordingly
  • Conduct assigned security tools rule and configuration validation and monitored devices recertification - Identify and escalate security issues and assist in cybersecurity incident investigations
  • Perform regular maintenance of assigned security tools including software upgrades, license updates and fine tuning of rules and configuration 

Threat Management, Vulnerability Management & Penetration Testing (45%) 

  • Conduct threat assessment and modeling as required
  • Conduct vulnerability scans of internal and external network
  • Present results to IT and partner to perform analysis, set criticality levels and assign timelines for remediation
  • Provide oversight of IT remediation, track and report all findings to the Information Security Committee
  • Coordinate penetration testing exercises in collaboration with IT
  • Present results to IT and partner to perform analysis, set criticality levels and assign timelines for remediation
  • Provide oversight of IT remediation, track and report all findings to the Information Security Committee 
Qualifications:
  • Bachelor’s degree in business, Computer Science, Management Information Systems, Engineering, Mathematics, or related field is required.

  • Minimum 1 year of work experience in Information security, cybersecurity, vulnerability management, security architecture, network, security tools and computer systems administration, risk management.

  • Good understanding of regulatory requirements including FFIEC, GLBA, NIST.

  • Knowledge of Information security and cyber security best practices.

  • Knowledge of systems administration such as Windows Server, Active Directory management, Firewall, UNIX system, network architectures, etc.

  • Knowledge of security tools such as SIEM, DLP, XDR, EDR, Web Filter etc.

  • Good understanding of protocol behaviors, validity of identified vulnerabilities.

  • CISSP/CRISC/ or IT related certifications preferred.
Pay Range

Actual salary is commensurate with candidate’s relevant years of experience, skillset, education and other qualifications.

: USD $42,000.00 - USD $90,000.00 /Yr.

Numbers & Facts

LocationNew York, New York
Job TypeFull-time
Salary$42,000–$90,000 Per Year

Skills

  • Best Practicesunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Channel Strategiesunmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Corporate Bankingunmatched
  • Firewallsunmatched
  • Identity Data Managementunmatched
  • Information Technology & Information Systemsunmatched
  • Information/Data Security (InfoSec)unmatched
  • Internet Securityunmatched
  • Management of Information Systems/Technology (MIS)unmatched
  • Mathematicsunmatched
  • Microsoft Active Directoryunmatched
  • Microsoft Windows Serverunmatched
  • Microsoft Windows System Administrationunmatched
  • Network Architecture/Engineeringunmatched
  • Network Securityunmatched
  • Penetration Testingunmatched
  • Problem Solving Skillsunmatched
  • Protective Servicesunmatched
  • Risk Managementunmatched
  • Security Architectureunmatched
  • Security Information and Event Management (SIEM)unmatched
  • Security Monitoringunmatched
  • Security Softwareunmatched
  • Software Licensesunmatched
  • Software Upgradesunmatched
  • Systems Administration/Managementunmatched
  • Systems Engineeringunmatched
  • Threat Modelingunmatched
  • Trading/Stockbrokingunmatched
  • Unix Operating Systemsunmatched
  • Vulnerability Scannersunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder