Job Closed

This listing is no longer active.

BMO logo
BMO

At BMO we are driven by a shared Purpose: Boldly Grow the Good in business and life. It calls on us to create lasting, positive change for our customers, our communities and our people. By working together, innovating and pushing boundaries, we transform lives and businesses, and power economic growth around the world. As a member of the BMO team you are valued, respected and heard, and you have more ways to grow and make an impact. We strive to help you make an impact from day one – for yourself and our customers. We’ll support you with the tools and resources you need to reach new milestones, as you help our customers reach theirs. From in-depth training and coaching, to manager support and network-building opportunities, we’ll help you gain valuable experience, and broaden your skillset. To find out more visit us at BMO Careers .

Third Party Cyber Security Incident Response Analyst

Security AnalystSecurity AnalystFull TimeRemoteMid LevelTeam 10,001

Location

United States

Posted

78 days ago

Salary

$88.8K - $165K / year

Seniority

Mid Level

Job Description

Third Party Cyber Security Incident Response Analyst

BMO

Application Deadline: 03/23/2026 Address: VIRTUAL43 - HomeRes - TX Job Family Group: Technology The individual for this role will lead third party incident response and management activities for BMOFG third and fourth-party suppliers. The analyst will provide cybersecurity subject matter expertise to execute on the following: - Executes end to end cyber security processes for monitoring, engaging, tracking, and remediation activities related to third-party and fourth-party incident response - Uses analysis to identify risks, understands the scope of complexity that exists in computing environments, across all layers, and the ways which a security incident may impact that environment. Equipped with the technical skills to determine necessary risk mitigations associated with cyber security incidents and root cause analysis - Reviews technical artifacts to determine if they satisfy remediation requirements, align to industry standard framework requirements, and submit reports with written and detailed analysis surrounding each incident - Builds effective relationships and communication with both internal and external stakeholders. Troubleshoots and problem solves complex issues with internal and external stakeholders, as required - Exercises judgment to identify, diagnose, and solve problems for each unique scenario - Works independently on a range of complex tasks, which may include unique situations - Ensures consistent, high quality practices/work and the achievement of business results in alignment with business/group strategies and with productivity goals - Develops and implements changes to streamline and integrate security processes and systems in the organization - Identifies opportunities to strengthen the information security capability at BMO, such as: sharing expertise to promote technical development, mentoring and educating peers and employees, building communities and professional networks across BMO - Stays abreast of industry technical and business trends through participation in professional associations, practice communities & individual learning - Broader work or accountabilities may be assigned as needed Qualifications: - Typically between 3 - 5 years of relevant experience within cyber security for third-party incident response and third-party risk management. Additionally, a post-secondary degree in Cyber/Information Security, Computer Science, Engineering, Information Systems, or a related field of study or an equivalent combination of education and experience - Experience with third-party incident response, reviewing vulnerability management and penetration test reports, familiarity with OWASP, and ability to identify both risks and root causes - Experience with conducting cybersecurity assessments on third-party suppliers using common industry frameworks, including NIST Cyber Security Framework (CSF), NIST 800-53, ISO 27001 and 27002, Payment Card Industry (PCI) Data Security Standard (DSS), CIS Top 18/20, or OWASP - Strong analytical experience, the candidate must be able to independently review technical artifacts to determine if they satisfy industry standard framework requirements and submit reports with their written and detailed analysis, including passing quality assurance processes - Strong ability to interact and communicate both written and verbally with people at all levels, both technical and non-technical, in a dynamic environment where interactions vary from written to verbal communications. Additionally, must work well independently with the ability to produce deliverables on a daily basis - Preference for candidates with at least one certification in a related field, with strong preference for Information Security certifications from a well-recognized institution (e.g. (ISC)2, ISACA, SANS) - Experience with tools such as BitSight, Nessus, SecurityScorecard, Black Kite, Risk Recon, Recorded Future, Threat Connect, Flashpoint, RSA Archer, or Shodan - Strong proficiency in Microsoft Excel, Word, and Outlook and closely tracking of tasks with frequent status updates - Excellent written and verbal communication skills for reporting and presenting reviews to senior leaders - in-depth - Understanding of multiple information security platforms and able to solve complex issues - Technical and system-level expertise in one or more information security solutions and/or extensive background in security or IT design and engineering. - Knowledge of information security design and engineering concepts, practices, and technology obtained through formal training and work experience - In-depth - Knowledge of the technical/business environment and the corporate processes and procedures - In-depth - Technical proficiency gained through education and/or business experience - Collaboration & team skills - In-depth - Analytical and problem solving skills - In-depth - Influence skills - In-depth - Data driven decision making - In-depth Salary: $88,800.00 - $165,600.00 Pay Type: Salaried The above represents BMO Financial Group’s pay range and type. Salaries will vary based on factors such as location, skills, experience, education, and qualifications for the role, and may include a commission structure. Salaries for part-time roles will be pro-rated based on number of hours regularly worked. For commission roles, the salary listed above represents BMO Financial Group’s expected target for the first year in this position. BMO Financial Group’s total compensation package will vary based on the pay type of the position and may include performance-based incentives, discretionary bonuses, as well as other perks and rewards. BMO also offers health insurance, tuition reimbursement, accident and life insurance, and retirement savings plans. To view more details of our benefits, please visit: https://jobs.bmo.com/global/en/Total-Rewards About Us At BMO we are driven by a shared Purpose: Boldly Grow the Good in business and life. It calls on us to create lasting, positive change for our customers, our communities and our people. By working together, innovating and pushing boundaries, we transform lives and businesses, and power economic growth around the world. As a member of the BMO team you are valued, respected and heard, and you have more ways to grow and make an impact. We strive to help you make an impact from day one – for yourself and our customers. We’ll support you with the tools and resources you need to reach new milestones, as you help our customers reach theirs. From in-depth training and coaching, to manager support and network-building opportunities, we’ll help you gain valuable experience, and broaden your skillset. To find out more visit us at http://jobs.bmo.com/us/en BMO is proud to be an equal employment opportunity employer. We evaluate applicants without regard to race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or any other legally protected characteristics. We also consider applicants with criminal histories, consistent with applicable federal, state and local law. BMO is committed to working with and providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please send an e-mail to BMOCareers.Support@bmo.com and let us know the nature of your request and your contact information. Note to Recruiters: BMO does not accept unsolicited resumes from any source other than directly from a candidate. Any unsolicited resumes sent to BMO, directly or indirectly, will be considered BMO property. BMO will not pay a fee for any placement resulting from the receipt of an unsolicited resume. A recruiting agency must first have a valid, written and fully executed agency agreement contract for service to submit resumes.

Job Requirements

  • Typically between 3 - 5 years of relevant experience within cyber security for third-party incident response and third-party risk management.
  • A post-secondary degree in Cyber/Information Security, Computer Science, Engineering, Information Systems, or a related field of study or an equivalent combination of education and experience.
  • Experience with third-party incident response, reviewing vulnerability management and penetration test reports, familiarity with OWASP, and ability to identify both risks and root causes.
  • Experience with conducting cybersecurity assessments on third-party suppliers using common industry frameworks, including NIST Cyber Security Framework (CSF), NIST 800-53, ISO 27001 and 27002, Payment Card Industry (PCI) Data Security Standard (DSS), CIS Top 18/20, or OWASP.
  • Strong analytical experience, able to independently review technical artifacts to determine if they satisfy industry standard framework requirements and submit reports with their written and detailed analysis.
  • Strong ability to interact and communicate both written and verbally with people at all levels, both technical and non-technical.
  • Preference for candidates with at least one certification in a related field, with strong preference for Information Security certifications from a well-recognized institution (e.g. (ISC)2, ISACA, SANS).
  • Experience with tools such as BitSight, Nessus, SecurityScorecard, Black Kite, Risk Recon, Recorded Future, Threat Connect, Flashpoint, RSA Archer, or Shodan.
  • Strong proficiency in Microsoft Excel, Word, and Outlook and closely tracking of tasks with frequent status updates.
  • Excellent written and verbal communication skills for reporting and presenting reviews to senior leaders.
  • Understanding of multiple information security platforms and able to solve complex issues.
  • Technical and system-level expertise in one or more information security solutions and/or extensive background in security or IT design and engineering.
  • Knowledge of information security design and engineering concepts, practices, and technology obtained through formal training and work experience.
  • Knowledge of the technical/business environment and the corporate processes and procedures.
  • Technical proficiency gained through education and/or business experience.
  • Collaboration & team skills.
  • Analytical and problem solving skills.
  • Influence skills.
  • Data driven decision making.
  • Salary: $88,800.00 - $165,600.00
  • Pay Type: Salaried

Benefits

  • Performance-based incentives.
  • Discretionary bonuses.
  • Health insurance.
  • Tuition reimbursement.
  • Accident and life insurance.
  • Retirement savings plans.

Related Job Pages

More Security Analyst Jobs

Kasa logo

Trust & Safety Specialist

Kasa

Kasa is home when you are away from yours. It's also a great place to work! Visit kasa.com/careers to apply!

Security Analyst78 days ago
Full TimeRemoteTeam 201-500Since 2016H1B Sponsor

Role Description Kasa is looking for a Trust & Safety Specialist who contributes to building assurance within the Kasa community and helps to keep our community members safe. In this role, you will be: - Investigating reported violations of house rules. - Coordinating cross-functional incident response. - Providing resolution to escalated or potentially harmful situations. - Assisting in the prevention and detection of future risks. You will report to the Senior Program Manager of Trust & Safety and provide a consistent, caring, and empathetic response to the community members you will be interacting with directly. Qualifications - 3+ years of experience in a customer-facing Trust & Safety role. - 3+ years of experience conducting investigations and handling urgent and high-priority issues. - Knowledge and experience managing cross-functional incident response efforts. - Expertise in de-escalation techniques and victim advocacy. - Flexible and willing to work off-hours, including weekends and holidays. Requirements - You default to active listening and capture details and responses in a clear, approachable, and actionable way in your written and spoken responses. - You have hundreds of examples of results from your sound judgment, most of which occur through autonomously solving problems with minimal oversight. - Experience working in a fast-paced environment with consistent change. - Experience working in a remote environment. Benefits - Remote Work: Flexibility as a core value, with over three-quarters of the team working remotely. - Competitive Salary: Total compensation at or above market rates plus additional earning opportunities based on the position. - Other Perks: Qualifying full-time roles are eligible for a wi-fi stipend, home office stipend, and more!

Worldwide
Job Closed
Home Depot logo

Cybersecurity Analyst – PII Compliance

Home Depot

Home Depot is a Fortune 500 company and the world's largest specialty retailer of home-improvement products. Founded in 1978 with its first two stores in Atlant

Security Analyst78 days ago

• Protecting what matters most to our associates and consumers by securing our sensitive data and critical assets from current and emerging threats • Perform data gathering, synthesis, and develop solutions; Leverage department standards to achieve results • Partner with teams to identify trends and resolve problems • Evaluate information and provide recommendations based on findings

United States
$80K - $130K / year
Job Closed

Security Analyst - Any Office Location

Baker Donelson

Baker Donelson is a national law firm offering comprehensive legal services to clients, with expertise encompassiong more than 30 practice areas, including lega

Security Analyst78 days ago

Baker, Donelson, Bearman, Caldwell, & Berkowitz, PC has an immediate opening for a Security Analyst in any office location within the Firm’s footprint. Remote work will also be considered. The Security Analyst will be responsible for architecting, operating, maintaining, monitoring, and improving the Information Security program. This position must be well versed in understanding the IT landscape including security, infrastructure, network, endpoint, server, emerging technology standards and trends and will be involved in strategy, design and engineering to contribute to the development and operation of secure solutions. Essential Responsibilities include: Threat Detection, Monitoring and Incident Response - Monitor and analyze alerts and events generated by various systems to identify potential security incidents. - Conduct thorough investigations into security alerts and incidents to determine the root cause and extent of impact. - Develop and maintain incident response procedures, including escalation paths and communication protocols, to ensure timely and effective response to security incidents. - Participate in on-call or incident escalation rotations as needed. Physical Security - Support the coordination and implementation of physical security standards in all Baker offices. - Support the coordination of physical security components for new site buildouts. - Support the coordination of repairs and maintenance for physical security systems and devices. - Support the evaluation and recommendation of locations for physical security controls. - Support minor troubleshooting and resolution of physical security hardware issues. - Support the administration and maintenance of the physical access control system Vulnerability, Risk and Compliance - Partner with IT, DevOps, and application teams to remediate vulnerabilities and improve security posture. - Maintain documentation for audits, regulatory requirements, and leadership reporting. Cross-functional Collaboration - Communicate risks, recommendations, and security considerations to technical and non-technical stakeholders. Documentation, Governance and Continuous Improvement - Contribute to development and maintenance of Information Security Policies, Standards, Procedures and Guidelines. - Contribute to the overall strategy of the Information Security Program. - Evaluate and implement security solutions, leveraging industry best practices, to address identified gaps and enhance the overall security posture. - Stay up-to-date on the latest security technologies, tools, and best practices to enhance the security posture of the organization Qualifications: - Possess familiarity or working knowledge of protection solutions and technologies including: - Endpoint Security Solutions - Cloud Technologies - Host-based Firewall and IDS/IPS - Data Loss Prevention (DLP) - Threat Intelligence - Threat Hunting - Incident Response - Zero-Trust Architecture Concepts - Strong analytical skills - Ability to communicate security-related concepts to a broad range of technical and non-technical staff both verbally and in writing. - Ability to manage multiple tasks simultaneously and meet established deadlines. - Ability to collaborate with all IT teams on security-related incidents, tasks and projects - Ability to work productively while remote and communicate effectively in a virtual team environment. - Ability to stay current with new technology. - Extensive knowledge of Windows end user workstation and server operating systems and administration. - Working knowledge of MacOS end user operating systems. - Experience utilizing security best-practices for endpoint protection solutions. - Prefer knowledge of asset discovery, packaging, patch management and software distribution. - Moderate travel to Baker offices is required - 2+ years Information Security or relevant IT experience. - A Bachelor’s degree in Information Security, Computer Science, Information Systems, or another related field is preferred. - Security or other technical certifications are preferred but not required. Career development plan to include certifications upon hire. - Extensive experience will be considered for a senior-level analyst role. The salary range for this position is $80,000 to $100,000. Must provide minimum authorization to work in the United States. Resumes only accepted for job posted. Thank you for submitting your resume. After our hiring committee has had a chance to review all candidates for this position, we will reach out to only those that will be moving on to the next step in our recruiting process. We appreciate your interest in the position and will contact you if further action is necessary

United States
$80K - $100K / year
Job Closed
Emory Healthcare logo

Info Sec Healthcare Data Privacy and Audit Analyst

Emory Healthcare

Emory Healthcare is the largest healthcare system in the state of Georgia and the only academic healthcare provider in greater metropolitan Atlanta, Georgia. Th

Security Analyst78 days ago

Overview At Emory Healthcare we fuel your professional journey with better benefits, valuable resources, ongoing mentorship and leadership programs for all types of jobs, and a supportive environment that enables you to reach new heights in your career and be what you want to be. We provide: · Comprehensive health benefits that start day 1 · Student Loan Repayment Assistance & Reimbursement Programs · Family-focused benefits · Wellness incentives Ongoing mentorship, development, leadership programs...and more Work Location: Remote position with exception of 2x/annually participate in Cyber Awareness Month onsite road show meetings. Will only consider applicants from the following states: Alabama, Arkansas, Florida, Georgia, Illinois, Louisiana, Michigan, New Hampshire, North Carolina, Ohio, Pennsylvania, South Carolina, Tennessee, Texas, Virginia and Wisconsin Description The Info Sec Healthcare Data Privacy and Audit Analyst is responsible for a wide range of Healthcare specific audit/compliance related workflows. Specific areas of audits range from data privacy of Epic medical records, litigations, reactive auditing, clinical workflows specific to the healthcare industry, and ediscovery areas such as badge access in OR's, and/or paging access. We are seeking specific Info Sec Audit/Compliance experience in the healthcare industry as such for this role. - Conducts proactive and reactive audits. - Clearly document assessments, variances, findings, and remediation plans in Archer. - Maintain a current knowledge of applicable federal and state privacy laws and accreditation standards, and monitor advancements in information privacy and security technologies to ensure adaptation and compliance. - Conduct information security research in keeping abreast of latest security issues and keeps abreast of testing tools, techniques, and process improvements in support of security event detection and analysis. - Use/s the Emory Healthcare values to govern decisions, actions and behaviors. Performs other duties as assigned. PREFERRED QUALIFICATIONS: - Healthcare industry experience in an IT Audit/Compliance job function. MINIMUM QUALIFICATIONS: - Bachelor's degree (B.A. / B.S.) or equivalent from an accredited college or university required, with 3-5 years of experience in IT/IS. - 3-5 years of experience with information security risk analysis, security risk configuration development, or information security audit. Demonstrated understanding of common healthcare technology implementation architectures, common cloud security configurations, identity management solutions and, technologies and application of risk analysis. - Demonstrable natural aptitude with object relationship and cause/effect. - Demonstrable familiarity with HIPAA, GDPR, HITECH, and other appropriate information security and information privacy regulatory requirements for healthcare entities a plus. - In depth knowledge of NIST 800-53, ISO 27K, GDPR, PCI-DSS is desirable. - Any of the following certifications is a plus: ITIL, any of the following Information Security Certifications: CISSP, HCISSP, CISM, CISA, CIPP, CIPM, CIPT, CPHIMS, PCIP, GSEC, GCIH, GCFE, GCFA, CEH, GPEN, and PM - A combination of education and analogous experience may be substituted for some requirements. - Skills/Abilities/Competencies: Possess strong interpersonal skills to effectively communicate with cross functional teams including staff at all levels of the organization. - Outstanding time management and organizational skills required. - An ability to work under the required guidelines and deliver on business/project requirements. - Ability to work with both team members and staff in a professional manner. - Comfortable working in a dynamic environment with multiple work streams, goals, and objectives. Possess ability to recommend to ISPO leadership team to prioritize project related tasks. - Excellent vocabulary, written and verbal communication and effective interpersonal skills is critical. - Understanding of Windows, Unix/Linux operating systems, security administration, virtualization, and TCP/IP networking concepts. - Ability to work independently with minimal supervision. - Ability to successfully negotiate and collaborate with others of different skill sets, backgrounds and levels within and external to the organization. - Strong problem solving and negotiation skills. - Ability to effectively conduct meetings, both formal and informal. - Requires minimal direction from leadership and possesses the ability to learn quickly. Additional Details Emory is an equal opportunity employer, and qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status or other characteristics protected by state or federal law. Emory Healthcare is committed to providing reasonable accommodations to qualified individuals with disabilities upon request. Please contact Emory Healthcare’s Human Resources at careers@emoryhealthcare.org. Please note that one week's advance notice is preferred.

United States
Job Closed