Information security analyst
Lensa is a career site that helps job seekers find great jobs in the US. We are not a staffing firm or agency. Lensa does not hire directly for these jobs, but promotes jobs on LinkedIn on behalf of its direct clients, recruitment ad agencies, and marketing partners. Lensa partners with DirectEmployers to promote this job for Santander US. Clicking "Apply Now" or "Read more" on Lensa redirects you to the job board/employer site. Any information collected there is subject to their terms and privacy notice.
Information Security Analyst Country: United States of America Your Journey Starts Here Santander is a global leader and innovator in the financial services industry. We believe that our employees are our greatest asset. Our focus is on fostering an enriching journey that empowers you to explore diverse career opportunities while nurturing your personal growth. We are committed to creating an environment where continuous learning and development are prioritized, enabling you to thrive both professionally and personally. Here, you will find ample opportunities to connect and collaborate with talented colleagues from around the world, sharing insights and driving innovation together. Join us at Santander, where you are supported by a culture of engagement and a commitment to your success. An exciting journey awaits, if you are interested in exploring the possibilities We Want to Talk to You! The Difference You Make The Sr. Specialist, Information Security develops and implements information security standards and procedures. Provides tactical information security advice and examining the ramifications of new technologies. Ensures that all information systems are functional and secure. Plans, implements, upgrades, or monitors security measures for the protection of computer networks and information. In addition, the incumbent ensures security controls are in place that will safeguard digital files and vital electronic infrastructure. They may respond to computer security breaches and viruses.- Work closely with the New York Information Security and Santander US Identity and Access Services teams, and Business Owners to address any New York related IAM, PAM and Single Sign On (SSO) related issues including related regulatory requirements to mature the information security program.
- The submission, approval, creation, and removal of accounts, entitlements, application roles, and business roles follows documented processes and procedures with clearly defined roles and responsibilities.
- User Active Directory accounts unused for the previous 90 calendar days are reviewed for inactivity and, if confirmed to be inactive, disabled or removed.
- All certified access rights are documented and current. Technology Platform Owners identifies users whose access rights violate the Separation of Duty (“SoD”) rules and are reviewed with managers/supervisors. Any exceptions are documented, risk-assessed, and formally approved within 30 business days of the management review.
- The recertification process is performed as a formal review of information assets to confirm that all granted access rights entitlements remain valid, updated, and in full compliance with the Segregation of Duties (SoD) rules and Principle of Least Privilege.
- All assets are onboarded to the Privileged Access Management System (PAMS) such as CyberArk and a process is defined to periodically review and recertify the accounts including groups they belong to.
- Perform risk assessments and control gap analysis against Information Security Policies and Standards.
- Support coordination for closure of gaps identified with Standard Requirements and Cyber Risk Assessment methodology.
- Analysis, evidence gathering and documenting compliance with Federal Financial Institutions Examination Council (FFIEC) Cybersecurity Assessment Tool (CAT), NYDFS 23 NYCRR 500 cybersecurity or any other regulatory requirements.
- Experience in information security, identity and access management, privileged access management, Single Sign On, Azure Active Directory integration, Cloud Framework, IT audit, or information technology risk management
- Knowledge of risk assessments and compliance of major regulatory initiatives (e.g., SOX, NYDFS)
- Knowledge with cyber security and information security program management and frameworks (e.g., NIST CSF, ISO/IEC 27000, etc.)
- Possess the ability to perform under pressure in a challenging environment.
- A hunger to learn and take on challenging opportunities contributing to the success of information security team.
- Possess a highly developed sense of personal accountability and follow-through with an ability to effectively prioritize multiple tasks and projects.
- Proven ability to work in team environment.
- Must take ownership, demonstrate a sense of urgency, and ensure accuracy and quality.
- Bilingual in Spanish is a plus.
Recommended Jobs
Senior Data Engineer
About the company ResortPass is completely redefining what it means to be a guest at a hotel. By offering day access to luxury hotel experiences, including breathtaking pools, private beaches, d…
Senior Product Manager, International Rapid Response Payment Systems
About GiveDirectly GiveDirectly (GD) aims to reshape international giving – and millions of lives – by providing cash grants directly to the world’s poorest. The Brookings Institution estimates th…
Notary Public Associate
The Center Associate delivers world-class customer service to all retail customers by receiving and processing packages for courier shipment and operating copiers, fax machines, binding equipment, lam…
Mid-Level Leveraged Finance Associate
Description We are seeking a mid-level Leveraged Finance associate with four to five years of experience to join our fast-growing and internationally recognized Leverage…
Assistant Clinical Professor of Physical Education Teacher Education (
Summary ... Assistant Clinical Professor of Physical Education Teacher Education (PETE) Job Title: Assistant Clinical Professor of... ...Education (PETE) Department: School of Education …
Senior Backend Engineer, Care Platform Operations
Ro is a direct-to-patient healthcare company with a mission of helping patients achieve their health goals by delivering the easiest, most effective care possible. Ro is the only company to offer nat…
CNC Grinder
Summary:: Responsible for operating CNC surface grinder(s) with attention to detail and precise flatness and finish tolerances. Responsibilities include fabricating and polishing/deburring parts and …
Senior Designer, Fashion - Women's Swim
What you'll do at Position Summary... As a Senior Designer at Walmart, you will be at the forefront of creating world-class swimwear known for its innovation, design, function, fit, and quality…
Senior Strategic Partnerships Manager
Everlaw is seeking a talented Partnership Manager to manage and grow the company’s partnerships with strategic managed services providers (MSPs) in the legal services and ediscovery industry. Core to…
Commissioning Rotating Specialist
Saipem is a global leader in the engineering and construction of major projects for the energy and infrastructure sectors, both offshore and onshore. Saipem is "One Company" organized into business …