Cyber Security Specialist

3 weeks ago


New York, New York, United States Sumitomo Mitsui Financial Group, Inc. Full time

Job Summary

The Security Testing Engineer will be responsible for executing within our Cyber Resilience Exercise program designed to increase cyber resilience capabilities and preparedness across various businesses, group companies, and functions of the bank. This role will support partnerships for exercises such as cyber scenario exercising and cyber incident management.

Key Responsibilities

  • Analyze IT infrastructure, systems, and applications for susceptibility to various security exploits and threats. Recommend best practices to mitigate vulnerabilities and partner with IT colleagues to implement fixes.
  • Create reports based on findings, identify remediation steps, and disseminate them to stakeholders.
  • Perform in-depth analysis and testing on new systems, vendor connections, applications, and implemented vulnerability patches.
  • Manage and update testing and validation infrastructure, vendors, and practices. Maintain documentation for testing practices and validation policy.
  • Support the development of security policy and practices to provide a holistic and proactive posture against vulnerabilities and exploits.
  • Partner in and understand the impacts and plans associated with resilience of cyber threats and risks.
  • Works with business/function/entity to increase awareness of Cyber Resilience. Provides input to IT, cybersecurity, and operational resiliency risk trainings bank wide.
  • Partner with IT infrastructure and development teams to identify systems and applications for potential exploits and conduct testing and validation of code to ensure it conforms to security standards.
  • Understands changes related to regulatory, new product/initiative, processes, controls, events, issues, etc., in the IT, data management, and cybersecurity domains that may impact the operational risk profile of the bank.
  • Provides reporting to Information Security and business senior management.
  • Engage with end-user security training team to develop curriculum and focus training on the most impactful practices and policies and update according to trending threats and exploits.
  • Work with business units to understand their current processes and advise on adjustments that could be made to improve overall security. Analyze requests for exceptions where needed and suggest appropriate structuring to balance both security and operational efficiency.

Requirements

  • Demonstrate an advanced understanding of cyber security concepts with knowledge of vulnerabilities and how they function, security and defensive posturing best practices, and threat assessment and remediation techniques.
  • Should either hold or be working towards professional certification in cyber security penetration testing.
  • Display knowledge of tools and frameworks used to conduct penetration testing, application code validation, and systems to enable real-time threat monitoring.
  • Possess knowledge of common network and data exchange protocols, hardware operating systems, and security infrastructure.
  • Show communication skills needed to effectively convey security policies and rational to business units.
  • Exhibit ability to coordinate the efforts of multiple teams and stakeholders during penetration tests, implementing vulnerability patches, and in response to security incidents.
  • 1-3 years of direct work experience within the financial services industry with focus on DAST, SAST, IAST, Network or Web Application Penetration.
  • Working knowledge of technology and cyber risk management process and controls, industry practices, and frameworks (e.g., NIST, ISO).
  • Detail oriented, with proven ability to question the status quo and apply resilience activities to enhance capabilities, as appropriate.
  • Strong organizational skills, with proven ability to successfully manage multiple, concurrent priorities.
  • Ability to communicate and work effectively in a matrixed environment and across various organizational levels, where flexibility, collaboration, and adaptability are important at all levels.
  • Foundational knowledge of banking laws and regulations (FFIEC, NYDFS, BCBS, FCA, PRA, BoE, etc.).
  • Maintain a technical cyber threat mindset to understand underlying risks and weaknesses to properly assist in mitigating and enhancement activities.
  • Desire to continually deliver a quality and meaningful work product in a timely and efficient manner.
  • BA/BS in Computer Engineering, Computer Science, Information Systems, Cyber Security, Business Administration, or demonstrated relevant industry background and/or military experience.
  • CISSP, CCRP (Certified Cyber Resilience Professional), CEH (Certified Ethical Hacker), GIAC, or other Cyber Incident Response or Penetration Testing certifications preferred.

About Sumitomo Mitsui Financial Group, Inc.

Sumitomo Mitsui Financial Group, Inc. is a top-tier global financial group. Headquartered in Tokyo and with a 400-year history, SMBC Group offers a diverse range of financial services, including banking, leasing, securities, credit cards, and consumer finance. The Group has more than 130 offices and 80,000 employees worldwide in nearly 40 countries. Sumitomo Mitsui Financial Group, Inc. (SMFG) is the holding company of SMBC Group, which is one of the three largest banking groups in Japan. SMFG's shares trade on the Tokyo, Nagoya, and New York (NYSE: SMFG) stock exchanges.

Equal Employment Opportunity

SMBC is an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, national origin, disability status, protected veteran status or any other characteristic protected by law.



  • New York, New York, United States CYOS Solutions Full time

    Cyber Security SpecialistCYOS Solutions is seeking a highly skilled Cyber Security Specialist to join our team. As a Cyber Security Specialist, you will be responsible for identifying, testing, and assessing security controls in line with the Australian Government PSPF, ISM, and agency policies and guidelines.Key Responsibilities:Identify and assess security...


  • New York, New York, United States City of New York Full time

    Cyber Project Specialist Job DescriptionThe City of New York's Bureau of Information Technology is seeking a Cyber Project Specialist to join their team. As a key member of the IT team, you will be responsible for reviewing and assessing business requirements for IT security needs and best practices.You will attend project meetings to assess security needs...


  • New York, New York, United States Diverse Lynx Full time

    Job Title: Cyber Security SpecialistJob Summary:We are seeking a highly skilled Cyber Security Specialist to join our team at Diverse Lynx LLC. As a Cyber Security Specialist, you will be responsible for analyzing and implementing PAM solutions to meet customer requirements.Key Responsibilities:* Assess the client's current PAM practices in line with...


  • New York, New York, United States CyberTec Full time

    Cyber Security SpecialistAt CyberTec, we are seeking a highly skilled Cyber Security Specialist to join our team. The ideal candidate will have a strong background in IT security and experience with Next Generation 9-1-1 emergency call systems.Key Responsibilities:Design and implement secure systems for the City's Next Generation 9-1-1 program.Evaluate...


  • New York, New York, United States CyberTec Full time

    Job SummaryCyberTec is seeking a highly skilled Cyber Security Specialist to join our team. The ideal candidate will have expertise in network integrity security systems and a strong background in system administration.The successful candidate will be responsible for developing and implementing network integrity security systems, maintaining information on...


  • New York, New York, United States Syntricate Technologies Full time

    Cyber Security RoleAt Syntricate Technologies, we are seeking a skilled Cyber Security Specialist to join our team. The ideal candidate will have a strong background in risk management, access control, and cryptography.Key Responsibilities:Ensure vendor security architecture and design meets firm policies, external guidelines, and regulatory...


  • New York, New York, United States GDIT Full time

    Job Description:Cyber Security SpecialistThe Cyber Security Specialist will be responsible for implementing and maintaining the Risk Management Framework (RMF) program for the MTC network enclaves. This includes preparing and maintaining accreditation documentation and artifacts in accordance with RMF policy for US Army and/or DoD programs on behalf of the...


  • New York, New York, United States United Software Group, Inc. Full time

    Cyber Security SpecialistJob Title: Cyber Security SpecialistJob Location: RemoteJoining Mode: Long termAbout the Role:As a Cyber Security Specialist at United Software Group, Inc., you will be responsible for providing expert-level support for CyberArk's toolsets, security concepts, and security product support. You will work closely with the team to ensure...


  • New York, New York, United States Sumitomo Mitsui Financial Group, Inc. Full time

    Job SummaryWe are seeking a highly skilled Cyber Security Specialist to join our team at Sumitomo Mitsui Financial Group, Inc. The ideal candidate will have a strong background in security testing and a passion for staying up-to-date with the latest threats and technologies.Key ResponsibilitiesAnalyze IT infrastructure, systems, and applications for...


  • New York, New York, United States Dionach Full time

    Job DescriptionWe are seeking a highly skilled Cyber Security Specialist to join our team at Dionach. As a Penetration Tester, you will be responsible for identifying and exploiting vulnerabilities in our clients' systems.Key Responsibilities:Conduct penetration testing and vulnerability assessmentsDevelop and implement secure coding practicesCollaborate...


  • New York, New York, United States RightTalents LLC Full time

    Cyber Security Threat Intelligence SpecialistAt RightTalents LLC, we are seeking a highly skilled Cyber Security Threat Intelligence Specialist to join our team. The ideal candidate will have at least 8 years of experience in Cyber Threat Intelligence initiatives, including enhancing prevention, detection, response and recovery efforts through various...


  • New York, New York, United States Della Infotech Full time

    Job Title:Cyber Security SpecialistJob Summary:Della Infotech is seeking a highly skilled Cyber Security Specialist to join our team. The ideal candidate will have a strong background in IT security and experience in designing and implementing secure systems.Key Responsibilities:Ensure security policies such as CJIS are in compliance throughout the design...


  • New York, New York, United States City of New York Full time

    Cyber Security Analyst Job DescriptionThe City of New York is seeking a highly skilled Cyber Security Analyst to join its team. As a Cyber Security Analyst, you will be responsible for configuring, deploying, and monitoring virus software and other vulnerability management tools to protect the agency's network and data.You will work closely with the...


  • New York, New York, United States United Software Group, Inc. Full time

    Cyber Security SpecialistAt United Software Group, Inc., we are seeking a highly skilled Cyber Security Specialist to join our team. The ideal candidate will have a strong background in Identity Access Management (IAM) and experience with CyberArk's toolsets.Key Responsibilities:Provide expert-level support for IAM solutions, including CyberArk's...


  • New York, New York, United States Kansas State University Full time

    About This Role:The Cyber Security Infrastructure Specialist will support the Infrastructure Security team by implementing and managing day-to-day cyber security protection and detection technologies at Kansas State University.The position is key in enhancing security measures, optimizing costs, improving performance, and ensuring end-user satisfaction...


  • New York, New York, United States Consolidated Edison Company of New York, Inc. Full time

    Job SummaryThe Sr. System Cyber Analyst is responsible for protecting our organization's computer systems and networks from cyber threats, ensuring the security of our data and digital assets.This role requires a strong understanding of industry standard policy, processes, and procedures covering incident, problem, and change management.The ideal candidate...


  • New York, New York, United States Consolidated Edison Company of New York Full time

    Job SummaryThe Senior System Cyber Analyst is responsible for protecting our organization's computer systems and networks from cyber threats, ensuring the security of our data and digital assets.This role involves designing, installing, and monitoring IT computing infrastructure, as well as providing timely response and troubleshooting alerts generated by...


  • New York, New York, United States Consolidated Edison Inc Full time

    Job DescriptionThe Sr. System Cyber Analyst is responsible for protecting our organization's computer systems and networks from cyber threats, ensuring the security of our data and digital assets.The Sr. Analyst will design, install, monitor IT computing infrastructure, provide timely response and troubleshoot alerts generated by various security tools.The...


  • New York, New York, United States CyberTec Full time

    Job Title: Cyber Security SpecialistCyberTec is seeking a highly skilled Cyber Security Specialist to join our team. As a key member of our security team, you will be responsible for implementing and operating network security telemetry collection systems in multi-cloud and on-prem environments.Responsibilities:Lead the implementation of cybersecurity...


  • New York, New York, United States Saxon Global Full time

    Job DescriptionWe are seeking a highly skilled Cyber Security Specialist to join our team at Saxon Global. As a key member of our security team, you will be responsible for evaluating and implementing new technologies, analyzing infrastructure and software designs and implementations, and identifying and resolving potential issues to help enhance and secure...