Information Technology Security Analyst
7 days ago
Philadelphia, PA, United States
THE DIME BANK
Full-time
Free with email or Google
Save this job and keep your search organized
Create a free account to save jobs, create alerts and return to this listing from your dashboard.
Free with email or Google
By continuing, you agree to our Terms & Privacy Policy.
Description
Job Reporting Relationships Supervised by:
Network Services Manager Supervises:
N/A Basic Qualifications Education/Training: Bachelor’s degree in information technology, Cybersecurity, Computer Science, or related field preferred, with strong knowledge of Microsoft Windows desktop and server operating systems. Working knowledge of network architecture, including LAN/WAN, firewalls, VPNs, and cloud environments. Familiarity with cybersecurity frameworks (NIST, ISO 27001, CIS, CRI). Relevant certifications preferred (e.g., Security+, CISSP, CISA, CEH) but not required. Skill(s):
Strong written and verbal communication skills; Knowledge of regulatory requirements (GLBA, FFIEC, PCI-DSS, etc.) preferred; Analytical and problem-solving abilities with attention to detail. Understanding of identity and user access management standards. Ability to assess risk and assist in making recommended mitigation strategies. Ability to work collaboratively with vendors and technical peers and management in a complex technology environment. Proven experience evaluating the data privacy risks of third-party generative AI platforms and establishing secure acceptable-use guardrails for corporate users.
Experience:
Minimum of one (1) year of experience in information security, IT security operations, or related field preferred. General Responsibilities Supports the Bank’s Information Security Program by assisting in the development, implementation, and maintenance of security technology, security controls and processes designed to protect information systems, networks, and data. Ensures compliance with internal policies, regulatory requirements, and industry best practices through monitoring, analysis, reporting, and continuous improvement activities. Essential Duties Assist with the Bank’s Information Security functions by performing the following duties: a. Security Software & Hardware Management: Deploy, configure, maintain, and patch security technologies—including endpoints, firewalls, intrusion detection/prevention systems (IDS/IPS), SIEM platforms, anti-malware/EDR tools, and data encryption solutions. b. Testing and deploying critical security patches across servers, workstations, and network infrastructure to eliminate vulnerabilities without disrupting bank operations. c. Reviewing alerts from the SIEM, firewall, and email security gateways (e.g., phishing filters) to distinguish between false positives and real threats. d. Managing email security, authentication protocols (DKIM, SPF, DMARC) and spam/phishing filters to prevent fraud and business email compromise (BEC). e. Manage Microsoft 365 Tenant, and email security gateway, data loss prevention and security controls. f. Before turning on internal AI search tools, you must audit and clean up Active Directory and SharePoint permissions. (If a user has accidental access to HR or financial folders, the AI will surface that data to them). g. Updating DLP policies with specific rules to detect, alert, and block financial data (SSNs, account numbers, routing numbers) or internal source code from being uploaded to external AI endpoints. h. Securing the network pipelines and APIs that connect the bank’s databases to the AI models, ensuring all data in transit and at rest is strongly encrypted. i. Conduct frequent testing of simulated cyber-attacks to look for vulnerabilities in the computer systems and take care of these before an internal or external cyber-attack. j. Monitoring and configuring system boundaries to prevent attackers from manipulating the AI’s output or extracting sensitive training data via malicious prompts. k. Reviewing the SOC 2 reports and "AI governance policies" of third-party vendors to determine how they train their models, where the bank's data is stored, and if the data is used to train public models. l. Audit internal AI tool usage and configure access controls to prevent the exposure of proprietary company data or customer PII. m. Perform regular vulnerability scans, analyze system logs for anomalies or breach indicators, and participate in threat hunting and incident response activities. n. Install, maintain, and upgrade software safeguards, including firewalls, data encryption programs, and anti-malware. o. Investigate cyberattacks, assess the extent of the damage, and coordinate mitigation and recovery efforts. p. Develop and enforce cybersecurity best practices, develop disaster recovery plans for security systems and services, and ensure compliance with industry’s best practices and privacy laws. q. Make recommendations to managers and senior executives about information security advancements to best protect the company’s systems. r. Conducting and documenting quarterly or annual user access reviews to ensure the "principle of least privilege" is maintained. s. Maintaining standard operating procedures,
Job Reporting Relationships Supervised by:
Network Services Manager Supervises:
N/A Basic Qualifications Education/Training: Bachelor’s degree in information technology, Cybersecurity, Computer Science, or related field preferred, with strong knowledge of Microsoft Windows desktop and server operating systems. Working knowledge of network architecture, including LAN/WAN, firewalls, VPNs, and cloud environments. Familiarity with cybersecurity frameworks (NIST, ISO 27001, CIS, CRI). Relevant certifications preferred (e.g., Security+, CISSP, CISA, CEH) but not required. Skill(s):
Strong written and verbal communication skills; Knowledge of regulatory requirements (GLBA, FFIEC, PCI-DSS, etc.) preferred; Analytical and problem-solving abilities with attention to detail. Understanding of identity and user access management standards. Ability to assess risk and assist in making recommended mitigation strategies. Ability to work collaboratively with vendors and technical peers and management in a complex technology environment. Proven experience evaluating the data privacy risks of third-party generative AI platforms and establishing secure acceptable-use guardrails for corporate users.
Experience:
Minimum of one (1) year of experience in information security, IT security operations, or related field preferred. General Responsibilities Supports the Bank’s Information Security Program by assisting in the development, implementation, and maintenance of security technology, security controls and processes designed to protect information systems, networks, and data. Ensures compliance with internal policies, regulatory requirements, and industry best practices through monitoring, analysis, reporting, and continuous improvement activities. Essential Duties Assist with the Bank’s Information Security functions by performing the following duties: a. Security Software & Hardware Management: Deploy, configure, maintain, and patch security technologies—including endpoints, firewalls, intrusion detection/prevention systems (IDS/IPS), SIEM platforms, anti-malware/EDR tools, and data encryption solutions. b. Testing and deploying critical security patches across servers, workstations, and network infrastructure to eliminate vulnerabilities without disrupting bank operations. c. Reviewing alerts from the SIEM, firewall, and email security gateways (e.g., phishing filters) to distinguish between false positives and real threats. d. Managing email security, authentication protocols (DKIM, SPF, DMARC) and spam/phishing filters to prevent fraud and business email compromise (BEC). e. Manage Microsoft 365 Tenant, and email security gateway, data loss prevention and security controls. f. Before turning on internal AI search tools, you must audit and clean up Active Directory and SharePoint permissions. (If a user has accidental access to HR or financial folders, the AI will surface that data to them). g. Updating DLP policies with specific rules to detect, alert, and block financial data (SSNs, account numbers, routing numbers) or internal source code from being uploaded to external AI endpoints. h. Securing the network pipelines and APIs that connect the bank’s databases to the AI models, ensuring all data in transit and at rest is strongly encrypted. i. Conduct frequent testing of simulated cyber-attacks to look for vulnerabilities in the computer systems and take care of these before an internal or external cyber-attack. j. Monitoring and configuring system boundaries to prevent attackers from manipulating the AI’s output or extracting sensitive training data via malicious prompts. k. Reviewing the SOC 2 reports and "AI governance policies" of third-party vendors to determine how they train their models, where the bank's data is stored, and if the data is used to train public models. l. Audit internal AI tool usage and configure access controls to prevent the exposure of proprietary company data or customer PII. m. Perform regular vulnerability scans, analyze system logs for anomalies or breach indicators, and participate in threat hunting and incident response activities. n. Install, maintain, and upgrade software safeguards, including firewalls, data encryption programs, and anti-malware. o. Investigate cyberattacks, assess the extent of the damage, and coordinate mitigation and recovery efforts. p. Develop and enforce cybersecurity best practices, develop disaster recovery plans for security systems and services, and ensure compliance with industry’s best practices and privacy laws. q. Make recommendations to managers and senior executives about information security advancements to best protect the company’s systems. r. Conducting and documenting quarterly or annual user access reviews to ensure the "principle of least privilege" is maintained. s. Maintaining standard operating procedures,