Security Specialist

PNC BankPittsburgh, PA
5hOnsite

About The Position

At PNC, our people are our greatest differentiator and competitive advantage in the markets we serve. We are all united in delivering the best experience for our customers. We work together each day to foster an inclusive workplace culture where all of our employees feel respected, valued and have an opportunity to contribute to the company’s success. Security Specialist within PNC's CYBER POLICY AND DEFENSE organization. PNC is an in-office company that fosters a supportive culture where employees can thrive and achieve balance. We encourage candidates to connect with their recruiter and hiring manager to understand workplace expectations and ensure the role aligns with their goals. PNC is an in-office company that fosters a supportive culture where employees can thrive and achieve balance. We encourage candidates to connect with their recruiter and hiring manager to understand workplace expectations and ensure the role aligns with their goals. PNC will not provide sponsorship for employment visas or participate in STEM OPT for this position. Job Description Provides technical evaluation and analysis in a specific Security area. Supports activities, process, and tools needed to improve overall security posture of the organization. Primary responsibilities do not include Architect or Engineering responsibilities. Applies security concepts, reviews information, executes defined tasks, analyzes requirements, reviews logs, and creates documentation. Performs investigation and data loss prevention, data manipulation, and coordination of activities. Performs actions to address or mitigate risks and vulnerabilities. Reviews and defines controls. Advises on more complex security procedures and products for clients, security administrators and network operations. Participates in enforcement of control security risks and threats; potential of one more controls subject to manager discretion. Shares knowledge with staff. Conducts security assessments and other information security routines consistently. Investigates and recommends corrective actions for data security related to established guidelines. Develops policies and procedures to standardize security functions and eliminate potential vulnerabilities and threats. Oversees that business needs are being met during development. PNC Employees take pride in our reputation and to continue building upon that we expect our employees to be: Customer Focused - Knowledgeable of the values and practices that align customer needs and satisfaction as primary considerations in all business decisions and able to leverage that information in creating customized customer solutions. Managing Risk - Assessing and effectively managing all of the risks associated with their business objectives and activities to ensure they adhere to and support PNC's Enterprise Risk Management Framework.

Requirements

  • Risk management
  • Controls
  • Remediation
  • GLBA regulatory compliance
  • FFIEC
  • Familiarity with NIST
  • Experience in risk management, policy/governance, IT controls, or cybersecurity, within CIAM/IAM or directly related identity domains.
  • Demonstrated experience writing policies/standards/procedures and mapping them to controls and evidence.
  • Experience with CIAM concepts: authentication flows, MFA factors, federation (OIDC/OAuth2, SAML), identity proofing, session security, risk-based auth.
  • Working knowledge of risk frameworks and governance approaches: e.g., NIST 800-53/63, ISO 27001/27002, FFIEC expectations; three lines of defense model; issue/exception management.
  • Strong written communication skills: policy drafting, risk narratives, control design, audit responses.
  • Analytical skills: define KRIs/KCIs/KPIs, interpret trends, and present data-driven recommendations.
  • Successful candidates must demonstrate appropriate knowledge, skills, and abilities for a role.
  • Roles at this level typically require a university / college degree, with 5+ years of industry-relevant experience.
  • Specific certifications are often required.
  • In lieu of a degree, a comparable combination of education, job specific certification(s), and experience (including military service) may be considered.

Nice To Haves

  • Jira/Confluence for workflow, documentation, and control libraries.
  • Experience with GRC tools (e.g., Archer, ServiceNow GRC, MetricStream) and evidence management.
  • Certifications: CIPM, CISA, CRISC, CISM, CGEIT, CISSP, CCSP, or vendor CIAM certs.

Responsibilities

  • Provides technical evaluation and analysis in a specific Security area.
  • Supports activities, process, and tools needed to improve overall security posture of the organization.
  • Applies security concepts, reviews information, executes defined tasks, analyzes requirements, reviews logs, and creates documentation.
  • Performs investigation and data loss prevention, data manipulation, and coordination of activities.
  • Performs actions to address or mitigate risks and vulnerabilities.
  • Reviews and defines controls.
  • Advises on more complex security procedures and products for clients, security administrators and network operations.
  • Participates in enforcement of control security risks and threats; potential of one more controls subject to manager discretion.
  • Shares knowledge with staff.
  • Conducts security assessments and other information security routines consistently.
  • Investigates and recommends corrective actions for data security related to established guidelines.
  • Develops policies and procedures to standardize security functions and eliminate potential vulnerabilities and threats.
  • Oversees that business needs are being met during development.

Benefits

  • PNC offers a comprehensive range of benefits to help meet your needs now and in the future.
  • Depending on your eligibility, options for full-time employees include: medical/prescription drug coverage (with a Health Savings Account feature), dental and vision options; employee and spouse/child life insurance; short and long-term disability protection; 401(k) with PNC match, pension and stock purchase plans; dependent care reimbursement account; back-up child/elder care; adoption, surrogacy, and doula reimbursement; educational assistance, including select programs fully paid; a robust wellness program with financial incentives.
  • In addition, PNC generally provides the following paid time off, depending on your eligibility: maternity and/or parental leave; up to 11 paid holidays each year; 9 occasional absence days each year, unless otherwise required by law; between 15 to 25 vacation days each year, depending on career level; and years of service.
  • To learn more about these and other programs, including benefits for full time and part-time employees, visit pncthrive.com .
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service