Summary
VARITE INC is recruiting an Information Security Analyst to support security consulting and risk management in a large enterprise environment. The role focuses on SailPoint role review and maintenance, technology access control reviews, security risk analysis, remediation, security standards, and collaboration with business and technology groups.
Responsibilities
- SailPoint Role review and maintenance and may include participating in technology access controls reviews of platform resources
- Identifying security risks, analyzing complex security issues, performing remediation efforts, creation/ownership of new security standards, providing security requirements and decisions
- Provides corporate security consulting support to concurrent projects
- Acts as an owner for assigned work
- Maintains adequate documentation regarding decisions and work performed
- Escalates problems in a timely manner
- Documents processes, procedures, and best practices
- Anticipates and addresses security needs/issues
- Provides security guidance and makes reliable security decisions with minimal supervision
- Interprets security policy and standards and consults on security variance requests
- Interprets policy and decisions variance requests
- Translates information security terminology into terms understandable to diverse groups
- Partners and collaborates with KeyCorp business and technology groups to deliver value through security review, assessment and consulting services
- Interfaces with corporate technology and line of business areas
- May interface with internal and external audit partners
- Builds and sustains collaborative relationships with multiple constituencies
- Ability to lead from a non-leadership position and within a cross functional team
Skills
- The ideal candidate for this position has an in-depth knowledge of security and technology, with strong understanding of risk management
- The candidate must be able to make decisions based on prior experience in a large enterprise environment and their solid understanding of the technologies and risks involved
- The candidate will need to have experience with access controls for common resources, such as Windows, Linux, Database such as SQL Server, Oracle, DB2, network appliances and mainframe
- Functional knowledge of both technical and business aspects of security is highly desirable
- Effective communication with lines of business and technology groups critical
- Bachelor degree or equivalent work experience
- Three to five + years of experience including technology-related auditing, consulting, programming, and/or operational banking experience
- Subject matter expert level expertise knowledge of both the business and technical aspects of security and technology
- Strong broad-based technical background (distributed/mainframe, database, web based application development and/or Cloud)
- High level of business acumen, preferably in a regulated/financial industry
- Strong risk-based analysis and decision making skills Ability to make quick fact-based decisions Ability to work outside comfort zone Ability to understand and analyze complex business processes and technologies to make sound recommendations
- Project management and/or project team member experience
- Ability to multitask and manage competing priorities
- Process management, time management and organizational skills
- Excellent interpersonal, customer service and relationship management skills
- Proven ability to effectively handle challenging clients and difficult political situations
- Excellent written and verbal communication skills
- Ability to create and implement new processes and procedures
- Proficient use of Microsoft Office Suite
- IAM experience or background desired
Qualifications
Must Haves
- The ideal candidate for this position has an in-depth knowledge of security and technology, with strong understanding of risk management
- The candidate must be able to make decisions based on prior experience in a large enterprise environment and their solid understanding of the technologies and risks involved
- The candidate will need to have experience with access controls for common resources, such as Windows, Linux, Database such as SQL Server, Oracle, DB2, network appliances and mainframe
- Functional knowledge of both technical and business aspects of security is highly desirable
- Effective communication with lines of business and technology groups critical
- Bachelor degree or equivalent work experience
- Three to five + years of experience including technology-related auditing, consulting, programming, and/or operational banking experience
- Subject matter expert level expertise knowledge of both the business and technical aspects of security and technology
- Strong broad-based technical background (distributed/mainframe, database, web based application development and/or Cloud)
- High level of business acumen, preferably in a regulated/financial industry
- Strong risk-based analysis and decision making skills Ability to make quick fact-based decisions Ability to work outside comfort zone Ability to understand and analyze complex business processes and technologies to make sound recommendations
- Project management and/or project team member experience
- Ability to multitask and manage competing priorities
- Process management, time management and organizational skills
- Excellent interpersonal, customer service and relationship management skills
- Proven ability to effectively handle challenging clients and difficult political situations
- Excellent written and verbal communication skills
- Ability to create and implement new processes and procedures
- Proficient use of Microsoft Office Suite
Nice to Haves
- IAM experience or background desired
Benefits