Job offer
Information Security Specialist
The Information Security Specialist is responsible for performing technical tasks and monitoring activities in the area of information security to ensure compliance with bank policies and standards. The position holder works on developing and improving security projects and monitors the IT security infrastructure to identify and mitigate risks.
Job description
Under general supervision, the Information Security Specialist performs technical tasks and monitoring activities in the area of information security, in accordance with the bank’s policies. He provides status reports to senior management, works on the development and improvement of security projects with some supervision/guidance, and monitors and controls the IT security infrastructure for the business units to identify, mitigate, and control risks by ensuring compliance with agreed-upon rules and standards.Tasks and responsibilities
- Carry out IT security activities to ensure that customers receive a high-quality, cost-effective service that meets the agreed-upon business plans and standards.
- In-depth knowledge of security tools such as log aggregators, firewalls, proxies, DLP, and others.
- Monitoring and controlling infrastructure data by implementing agreed-upon rules and standards within the business unit to effectively mitigate and control data security risks.
- Ensure that appropriate audits, risk/vulnerability analyses, and penetration tests are conducted on a regular basis to identify potential security risks/vulnerabilities, malware, and security breaches, and to find solutions when necessary.
- Technical expertise in IT architecture, web applications, and networks.
- Participate in the review of the design, development, and specifications of new or revised processes, systems, information, documentation, and supporting materials in order to compile reports that present the results and ensure that customer requirements are fully understood and met.
- Support the timely and accurate delivery of security projects and initiatives to ensure that they meet specifications and stay within budget.
- Responsibility for understanding and complying with all bank policies, procedures, and standards, as well as all applicable legal requirements, that pertain to his work.
- Monitoring of user activities related to application and system security, such as expired passwords, administrative/power-user activities, inactive user accounts, and other elements consistent with the bank's security management policies.
- Perform routine security management tasks and/or maintenance for all systems and banking applications to ensure that policies and/or standards are not violated, and report any deficiencies to management.
- Reporting cases where users do not comply with the bank's policies and ensuring that the issues are resolved in a timely manner.
- Contribute to the implementation of new and innovative processes or technologies that advance the information security program.
- Stay up to date on current and emerging technical developments in the field of information security, including relevant federal and state laws as well as accreditation requirements.
- Maintaining the confidentiality of corporate information, including specified security measures and controls.
- Effective collaboration with IT, Audit, Internal Control, the headquarters, and other groups as needed.
Job details