Information Security Risk Analyst

SUMITOMO MITSUI TRUST BANK, LIMITEDNew York, NY
$90,000 - $125,000Hybrid

About The Position

The Information Security Risk Analyst is responsible for supporting the organization’s vulnerability management program and performing assigned information security risk assessments. This role will perform the day-to-day vulnerability management activities, perform risk-based analysis of identified vulnerabilities, coordinate remediation efforts with the IT Department, and help ensure systems are maintained in accordance with the organization’s information security standards.

Requirements

  • Strong understanding and prior experience working with network components and devices such as Firewalls, IPS, IDS, switches, routers, NDR, and NAC.
  • Strong understanding and prior experience working with Microsoft Windows-based environments including components such as domain controllers, DHCP, DNS, and Active Directory.
  • Foundational understanding of Information Security frameworks such as NIST Cybersecurity Framework and SP 800-53 as well as Cyber Risk Institute Profile v2.x
  • 3+ Years of experience managing System Vulnerability Management tools such as Qualys or Tenable.
  • 3+ Years of experience with risk assessment methodologies and techniques
  • Strong verbal and written communication skills.
  • Strong analytical skills with attention to detail and accuracy.
  • Self-motivated with good time management skills.

Nice To Haves

  • Prior experience with financial industry structure and concepts a plus.

Responsibilities

  • Administer and support the organization’s system vulnerability management program.
  • Conduct regular vulnerability scans across servers, endpoints, applications, network infrastructure, and Cloud environments.
  • Monitor vulnerability scanning coverage and coordinate with the IT Department to identify missing, newly added, or decommissioned IT assets and ensure that the scanning scope remains accurate and up to date.
  • Review and analyze vulnerability scan results and cross-reference with other sources such as the CISA Known Exploited Vulnerabilities (KEV) catalog to identify high-criticality areas for remediation. Identify potential false-positive findings and review with ITD for validity.
  • Collaborate with ITD to prioritize system vulnerability remediation and patching based on system risk severity, vulnerability exploitability, asset criticality, and potential business impact.
  • Track identified vulnerabilities through remediation and/or mitigation, validate remediation through re-scanning or review of appropriate supporting evidence, and generate regular system vulnerability remediation status reports.
  • Monitor compliance of system vulnerability remediation based on pre-defined risk-based remediation targets. Escalate critical or significant delays of system vulnerability remediation based on pre-defined targets to Management, as necessary.
  • Create vulnerability management-related reports with risk summaries and recommendations to Management.
  • Perform risk assessments on proposed new systems to be introduced to the organization.
  • Perform other duties and responsibilities as assigned by management.

Benefits

  • PAID TIME OFF
  • MEDICAL
  • HSA
  • VISION
  • DENTAL
  • FSA
  • 401(K)
  • PROFIT SHARING
  • LEGAL PLAN
  • CANCER INDEMNITY PLAN
  • DISABILITY INSURANCE
  • LIFE INSURANCE
  • EMPLOYEE ASSISTANCE PROGRAM
  • COMMUTER BENEFITS
  • BUSINESS TRAVEL ACCIDENT
  • PAID VOLUNTEER DAY
  • PAID MEMBERSHIPS
  • PAID SEMINARS
  • TUITION ASSISTANCE
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service