Data Security/ Compliance

Senior Information Security Specialist

Reports to CISO in Chicago with a global team of 5, this role works for a technology solution provider with all the top tier banks and other financial services firms globally as clients. As a consequence, the company must adhere to the various standards for Information Security to meet the demands of each of their global tier one banking customers. This results in a really interesting and challenging environment for an IT security professional and the team currently are top of their game. This is the first appointment for Ireland so will work with a broader team here reporting to the USA.  The Senior Information Security Analyst is responsible for understanding and providing appropriate surveillance for the critical cyber threats out there and participate in the development and implementation of security policies and procedures. In the role you will leverage Network Monitoring, Logging and Security Incident Event Management (SIEM) systems to produce alerts, audit data and reporting to detect suspicious activity and will analyse the threat data to help determine what response is appropriate as well as implementing and improving technology and procedures related to vulnerability management, device hardening and cybersecurity incident response.

  • Monitoring, investigation and reporting of security incidents. Member and support of the Information Security Response Team
  • Coordinate and perform internal as well as external penetration tests, application as well as network vulnerability assessment scans, and security risk assessment reviews.
  • Ability to develop and analyse processes. Identify as well as detail information risk, governance and compliance concepts and principles. Monitor, evaluate, and advise on information security issues related to systems, data, network, and workflow to ensure security controls are appropriate and operating as intended.
  • Work with a set of guidelines to help identify critical event data for additional analysis and escalation as appropriate
  • Assist in the development and document security architecture and plans, including strategic, tactical, and project plans
  • Conduct security research in keeping abreast of latest security issues.
  • Always observes all organizational procedures from a security risk perspective.
  • Liaise with internal team members and external vendors in a professional manner while performing professional services, and/or security assessment activities.
  • Assist with the design and implementation of disaster recovery and business continuity plans, procedures, audits, and enhancements
  • Assist in defining security requirements for information technology projects.
  • Investigate and document suspicious activity and reported security
  • More than 5 years’ experience in information security (network, application and systems) or related technology experience,
  • Experience delivering InfoSec services to Banking and financial services industry with knowledge of SOC2, NIST, CIS and other standards / Frameworks pertaining to banking and financial services
  • Strong knowledge of technology and security controls related to the detection, analysis, containment, eradication, and recovery from cyber security incidents.
  • Working knowledge of application & infrastructure security solutions (Firewalls, Intrusion Detection\Prevention Systems, Network Security, Password Management, Data Encryption, Vulnerability Scanners, SIEM Systems, and Access Control)
  • Working knowledge of information security concepts, standards, and best practices.
  • Knowledge of Windows and Linux systems, Active Directory Architecture, EDR, data governance, vulnerability management, SIEM systems, and Information Security compliance and standards.
  • Strong verbal and written communication skills with experience in documentation and familiarization of Standard Operating and other formal procedures
  • Server and Network Device Security Hardening (routers, switches, firewalls, virtual environments are a plus)
  • CISSP, CRISC, Certified Ethical Hacker (CEH) certification a plus.
  • Technical writing experience with management level reports