Salary Range: $160,000.00 To $200,000.00 Annually This role is located in New York City and will require a hybrid work schedule of at least 2 days in office per week. This role is for Vice President level candidates. About the Bank: Sumitomo Mitsui Trust Bank, Limited was established through the merger of The Sumitomo Trust and Banking Co., Ltd with Chuo Mitsui Trust and Banking, Ltd. on April 1, 2012. We are one of the largest asset managers in Asia and number one among Japanese financial institutions by AUM, with approximately $850 Billion USD in AUM. The Bank provides an assortment of financial solutions and manages a broad spectrum of financial products across its global branches. Department Overview: The Americas Division (“AD”) was established in the Sumitomo Mitsui Trust Bank, Limited, New York Branch) (“SMTBNY”) to perform corporate functions and supervise U.S. entities. Established under the AD are the “Global Banking Unit (“GBU”), Americas Division” and “Global Markets Unit (“GMU”), Americas Division” which performs business functions. Information Risk Governance (“IRG”) provides oversight to information and cyber security risk by maintaining and improving branch wide framework that is in-line with the Head Office and regulatory requirements and addresses Confidentiality, Integrity, and Availability for information assets. IRG establishes appropriate policies, procedures, measurement, and monitoring processes to proactively assess and evaluate cyber security and information security risks inherent in the Branch Operations. IRG is directly involved in all information and cyber security related projects, matters, and issues. Your Role Overview: The Information Security Officer (ISO) serves as the Chief Information Security Officer’s principle operational delegate. The ISO is responsible for leading the day-to-day governance, administration, and continuous improvement of the Americas Division’s Information Security and Cybersecurity program. Working under the direction of the CISO, the ISO translates the Americas Division’s information security strategy, risk appetite, regulatory obligations, and enterprise requirements into an effective operating program. Your Duties and Responsibilities: Administer and continuously improve the Americas Division information security and cybersecurity program, including policies, standards, procedures, control requirements, and evidence repositories. Translate CISO direction, enterprise security requirements, Americas Division risk appetite, and regulatory expectations into actionable objectives, work plans, control requirements, and measurable deliverables. Maintain Americas Division information security policies and procedures lifecycle, including periodic review, stakeholder coordination, approval tracking, publication, and exception management. Assist the CISO to coordinate with Head Office and US regional affiliate information security teams to ensure that the US-level Information Security risk framework is appropriately adhered to and evidenced. Coordinate with security operations, IT, Legal, Compliance, BCP, Head Office, and other relevant stakeholders during cybersecurity incidents, as part of the Incident Response Team. Monitor relevant changes in laws, regulations, supervisory expectations, industry practices, and emerging threats and recommend updates to the Americas Division cybersecurity and information security program. Oversee and challenge the information security risk assessments as performed by the Risk Management Section of IRG. This includes risk assessments for new products, material technology changes, Cloud/SaaS services, third party engagements, Artificial Intelligence use cases, and other material business initiatives. Oversee the effectiveness of key cybersecurity controls, including identity and access management, privileged access, vulnerability management, systems patching, endpoint protection, logging and monitoring, data encryption, secure configuration based on best practices, secure development lifecycle, backup and recovery, as well as data protection. Coordinate risk-based control testing and evidence collection, identify control deficiencies, validate remediation, and escalate material or overdue issues to the CISO and appropriate Senior Management. Administer the information security exception process, including documentation of business justification, compensating controls, expiration dates, ownership, risk ratings, and required approvals. Ensure that material residual risk decision and risk acceptances are escalated to the CISO and/or other authorized risk acceptance authorities in accordance to policy. Coordinate the Americas Division’s operational readiness for applicable cybersecurity and information security regulatory obligations. Prepare and maintain documentation, risk assessments, testing records, policy evidence, incident records, third party evidence, and other artifacts needed to support regulatory examinations, internal/external audits, and management reviews. Track regulatory and audit findings, drive remediation governance, validate closure evidence, and escalate overdue or high-risk findings. Produce timely, accurate, and actionable cybersecurity management information for the CISO, including key risk indicators, control metrics, significant incidents, vulnerabilities, exceptions, audit issues, third-party risks, training results, and remediation status. Support the CISO in preparing periodic and annual cybersecurity program reports for Senior Management, governing bodies, and other stakeholders. Assist the CISO with the management of all matters related to Information Security and Information Risk Management, including providing guidance to other IRG Department members. Performs other duties and responsibilities as assigned by management. Your Qualifications: Certification in Information Security (ISC 2 CISSP or ISACA CISM) required. 8+ years of Information Security related experience, IT Audit experience, preferred. Strong knowledge of Information Security principles, terminologies, and technologies required. Strong knowledge of Information Risk Management framework and principles required. Ability to analyze and design information security policy, procedures, and activities required. Detailed Knowledge and expertise in Technology Risk Assessments and Risk Analysis required. Excellent written and verbal communication skills, required. Strong skills and prior experience with Microsoft Office (PowerPoint, Excel, and Word) required. Strong project management and people management skills required. Prior experience developing Risk Management and Oversight Frameworks for Systems Automation, AI, and other novel technologies. Prior experience in the Financial Services Industry preferred, especially in a FBO with exposure to NYDFS and FRBNY regulations. Why you should join SuMi Trust: SuMi Trust embraces flexible ways of working when the business and role permits. We provide employees with a hybrid working model, allowing for in-office work and work from home. Our diverse and inclusive environment along with our global presence enables us to collaborate and communicate to meet our business needs. We believe that efficient teams need truth, loyalty, and a strong sense of purpose to balance risk and their targets. We make sustainable business decisions to improve our society and the world. We believe that each person brings a unique value that drives the business though their creativity and passion. The Employee Benefits package includes: Paid Time Off, medical, HSA, vision, dental, FSA, 401(k), profit sharing, legal plan, cancer indemnity plan, disability insurance, life insurance, employee assistance program, commuter benefits, business travel accident, paid volunteer day, paid memberships, paid seminars, and tuition assistance. We offer many socialization opportunities for wellness, financial wellbeing, runs/walks, team building, happy hours, and activities to support the Sustainable Developmental Goals. Check out our LinkedIn for our employee experience: https://www.linkedin.com/company/smtbny We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, national origin, disability status, protected veteran status or any other characteristic protected by law. SuMi Trust provides reasonable accommodations for employees and applicants with disabilities consistent with applicable law. If you need a reasonable accommodation during the application
Information Technology Manager/Information Security Officer - Career Centers
Action for Boston Community Development
Chief Information Security Officer
The Federal Savings Bank
Information System Security Officer (ISSO)
MBL Technologies Inc
Information System Security Officer, Lead
Hubcareers Docusign
Information System Security Officer - DoD Secret Clearance
Cdw
Information Security Officer
Medvidi