Third Party Information Security Analyst at SUMITOMO MITSUI TRUST BANK, LIMITED | NY, US | Rezi

Third Party Information Security Analyst at SUMITOMO MITSUI TRUST BANK, LIMITED

Third Party Information Security Analyst

SUMITOMO MITSUI TRUST BANK, LIMITED · NY, US

1 weeks ago

Third Party Information Security Analyst

SUMITOMO MITSUI TRUST BANK, LIMITED · NY, US

8 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

The Third Party Information Security Analyst supports the Bank’s Third Party Risk Management function by assessing and monitoring information security risks associated with third parties. This role assists with vendor due diligence, security reviews, and ongoing monitoring to ensure third-party relationships align with the organization’s security requirements.

Responsibilities

  • Conduct initial and continuous information security risk assessments of third (Nth) parties.
  • Review third party provided security documentation including SOC reports, ISO 27001 certifications, security questionnaires, and Business Continuity and Disaster Recovery documentation.
  • Document assessment findings and risk ratings in the Bank’s TPRM platform and maintain an up-to-date tracking sheet.
  • Coordinate with relevant Teams for vendor onboarding and offboarding activities, focusing on information security risks.
  • Perform on-going monitoring of information security-related incidents involving third-parties and coordinate with stakeholders.
  • Participate in internal audits and external examinations related to third party risk management.
  • Assist in maintaining information security-related TPRM policies and procedures.
  • Performs other duties and responsibilities as assigned by management.

Requirements

  • 3+ Years of experience with risk assessment methodologies and techniques as well as Third Party Risk Management Lifecycle.
  • Prior experience with financial industry structure and concepts is a plus.
  • Prior experience working on a Third Party Risk Management (TPRM) platform, such as Prevalent.
  • Prior experience working with and assessing information security-related documentation such as SOC 2 reports, ISO 27001 certification, etc.
  • Strong knowledge of information security and risk management frameworks, including NIST Cybersecurity Framework, ISO/IEC 27001, and the Cyber Risk Institute Profile.
  • Strong Microsoft Office skills.
  • Strong verbal and written communication skills.
  • Strong analytical skills.
  • Self-motivated with good time management skills.

Skills

  • Risk assessment methodologies
  • Third Party Risk Management Lifecycle
  • TPRM platform experience (e.g., Prevalent)
  • Information security documentation review (SOC 2, ISO 27001)
  • NIST Cybersecurity Framework
  • ISO/IEC 27001
  • Cyber Risk Institute Profile
  • Microsoft Office
  • Verbal communication
  • Written communication
  • Analytical skills
  • Time management

Location

  • New York City

Work Type

  • Hybrid

Experience Level

  • Officer level

Benefits

  • Paid Time Off
  • Medical
  • HSA
  • Vision
  • Dental
  • FSA
  • 401(K)
  • Profit Sharing
  • Legal Plan
  • Cancer Indemnity Plan
  • Disability Insurance
  • Life Insurance
  • Employee Assistance Program
  • Commuter Benefits
  • Business Travel Accident
  • Paid Volunteer Day
  • Paid Memberships
  • Paid Seminars
  • Tuition Assistance

About the Company

  • SUMITOMO MITSUI TRUST BANK, LIMITED was established through the merger of The Sumitomo Trust and Banking Co., Ltd with Chuo Mitsui Trust and Banking, Ltd. on April 1, 2012.
  • One of the largest asset managers in Asia and number one among Japanese financial institutions by AUM, with approximately $850 billion USD in AUM.
  • The Bank provides an assortment of financial solutions and manages a broad spectrum of financial products across its global branches.
  • The Americas Division (“AD”) was established to perform corporate functions and supervise U.S. entities.
  • The Global Banking Unit (“GBU”), Americas Division and Global Markets Unit (“GMU”), Americas Division perform business functions.
  • Information Risk Governance (“IRG”) provides oversight to information and cyber security risk by maintaining and improving a branch-wide framework aligned with Head Office and regulatory requirements.
  • IRG addresses Confidentiality, Integrity, and Availability for information assets.
  • IRG establishes appropriate policies, procedures, measurement, and monitoring processes to proactively assess and evaluate cyber security and information security risks.
  • IRG is directly involved in all information and cyber security related projects, matters and issues.
  • Sumi Trust embraces flexible ways of working when the business and role permits.
  • Sumi Trust provides employees with a hybrid working model.
  • Sumi Trust has a diverse and inclusive environment along with its global presence.
  • Sumi Trust believes that efficient teams need truth, loyalty, and a strong sense of purpose to balance risk and their targets.
  • Sumi Trust makes sustainable business decisions to improve society and the world.
  • Sumi Trust believes that each person brings a unique value that drives the business through their creativity and passion.

Equal Opportunity

  • We are an equal employment opportunity employer.
  • All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, national origin, disability status, protected veteran status or any other characteristic protected by law.
  • SuMi Trust provides reasonable accommodations for employees and applicants with disabilities consistent with applicable law.