Information Security Analyst
Indexed description
Great benefits include: on-site fitness facility at Red Bank and Toms River headquarter offices, employee perks & discount programs, tuition assistance, incentive compensation program, professional development opportunities, and more! Apply today to #BecomeOceanFirst and make an impact in the local community!
Primary Purpose
In conjunction with the Information Security Operations Manager, develop, implement, and manage an enterprise wide information security framework to establish IT systems defenses against security vulnerability/ breaches.
Assist in the creation and maintenance of information security procedures designed for business and technology
units to establish and maintain a compliant, risk-focused information security platform. Partner with business and
functional units to create and maintain the bank's Business Continuity, Disaster Recovery Plans, and Incident
Response Plan. Implement appropriate monitoring and testing to ensure adherence to the bank's information
security protocols across the organization.
Essential Duties And Responsibilities
- Provide timely detection, identification, and alerting of possible attacks, anomalous activities, and misuse activities.
Database Security, Firewalls, Cloud Proxy, Network Access Control and Network Segmentation to identify security
risks.
- Ensure appropriate systems and controls exist to protect the confidentiality, integrity and availability of data residing
data repositories.
- Execute the deployment, integration and initial configuration of all new and enhanced information security solutions
security procedures.
- Maintain information security documentation including procedures, processes and guidelines to ensure the
- Coordinate and document incident reviews to ensure appropriate controls are implemented to prevent or mitigate
- Work with IT to maintain the bank's Business Continuity and Disaster Recovery Plans, identify potential information
- Maintain ongoing communications with IT peers to ensure enterprise-wide understanding of information security
- Support the information security activities of the bank's external network sources.
- Maintain current knowledge and understanding of the IT security industry including awareness of new or revised
the IT threat landscape for banking and financial services industry.
- Help deliver enterprise-wide security awareness training for all employees to ensure consistently high levels of
- Active participant in Incident Response Plan tabletop exercises.
- Create/Maintain vulnerability scans and then analyze data and integrate into reporting and dashboard creation.
- Update security software tools to maintain current versions.
- Review and recommend security policies, controls and cyber incident response planning.
- Contribute to automation workflows and integration of Artificial Intelligence (AI) and agentic capabilities to increase
- Approve and oversee identity and access management (IAM) policies and system access control.
- Ensure continued compliance with laws and applicable regulations.
- Schedule and participate in periodic security assessments.
- Choose and recommend security products as necessary.
- Coordinate electronic discovery and digital forensic investigations.
- Ensure an inventory of technology assets, classified by sensitivity and criticality is properly maintained.
- Review relevant logs for security events
- Solid understanding of network and system intrusion and detection methods; examples of related technologies
(SIEM), Security Orchestration, Automation, and Response (SOAR), Firewalls, Intrusion Detection
Systems/Intrusion Prevention Systems (IDS/IPS), security testing tactics techniques and procedures.
- Experienced with Zero Trust Networking principles and supporting technology
- Experienced with Exposure Management and the components that comprise the capability (e.g., vulnerability
- Experience with introducing practical AI and automation into a Security environment desired
- Understanding of information security frameworks, such as MITRE (ATT&CK, ATLAS, D3FEND), Cyber Kill Chain,
- Industry recognized Infosec certifications such as CompTIA Security+, CEH: Certified Ethical Hacker, GSEC: SANS
Security Manager, strongly desired.
- Proven ability to successfully partner with internal clients and vendors to align strategy with deliverables, identify
- Strong service management and service delivery orientation.
- Strong written, oral, and interpersonal communication skills.
- Ability to present ideas in user-friendly language to a variety of constituent audiences.
- Proven ability to work within a changing environment and lead the implementation of change.
- Ability to assess the impact or potential impact of change management initiatives of various sizes and degrees of
- Ability to effectively prioritize and execute tasks in a high-pressure environment.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search