Job Closed
This listing is no longer active.
This job posting is expected to remain active for 31 days from the initial posting date listed above. If it is necessary to extend this deadline, the posting will remain active as appropriate. Job postings may come down early due to business need or a high volume of applicants.
Cyber Security Analyst II - Vulnerability Management
Location
United States
Posted
11 days ago
Salary
0
Seniority
Mid Level
Job Description
Cyber Security Analyst II - Vulnerability Management
First Citizens Bank
Role Description This position supports Information Security and Cyber Threat management programs within the Bank at an advanced level of ability. Key responsibilities include: - Analyzing vulnerability and threat data to provide actionable intelligence for cyber defense efforts. - Evaluating the Bank's networks and systems to identify technical security gaps or deficiencies. - Recommending process improvements and technical solutions to address identified gaps or deficiencies. - Facilitating the defense of the organization's information security and technological architecture through ongoing reporting and escalation of emerging threats. - Providing guidance for less experienced associates in the work group or assisting with special projects. Responsibilities - Security Review: Monitors and evaluates security incidents, system alerts, audit events, and other activity for potential threats against the Bank's networks and systems. Detects anomalies, malware infections, and intrusion attempts. Identifies, recommends, and executes appropriate mitigation tactics for identified threats. May perform system testing or provisioning. - Analysis: Analyzes data from various operating systems, databases, and applications within the Bank. Sources and interprets data to proactively search for threats. - Business Support: Supports the defense of the organization's information security and technological architecture through a number of operational and technical tasks. Ensures all cyber security monitoring systems are online and fully operational as well as ensuring compliance with all security policies and standards. Maintains current knowledge about threat indicators, attack trends, and cyber-intel as well as news and reports from industry sources. Participates in the creation and maintenance of playbooks and incident response procedures. May answer inquiries or facilitate training on security threats for other associates in the work group. - Reporting: Produces reports that document investigation and security incidents as well as the results of analysis. Provides analytics and reporting that facilitates actionable cyber-intelligence within daily operations. Conveys information to the appropriate parties, which includes both internal and external partners. Qualifications - Bachelor's Degree and 4 years of experience in Information Security OR High School Diploma or GED and 8 years of experience in Information Security. - Preferred Qualifications: - 6+ years of experience in Cyber Security and/or Information Technology. - Proficiency in vulnerability scanning and reporting platforms such as Tenable, Qualys VMDR, Rapid7, Wiz, Brinqa, etc. - Experience with IT Service Management tools such as ServiceNow and Jira. Benefits Benefits are an integral part of total rewards and First Citizens Bank is committed to providing a competitive, thoughtfully designed and quality benefits program to meet the needs of our associates. More information can be found at https://jobs.firstcitizens.com/benefits .
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
Security Analyst
LS Retail, an Aptos CompanyWe are a world-leading developer and provider of unified POS and business management software for retail and hospitality
• Respond to and triage alerts relating to phishing attacks, impersonation, scams, and brand abuse (e.g. Sublime, Doppel), escalating credible threats where appropriate. • Coordinate day-to-day operation of the bug bounty program, including communication with researchers, issue tracking, reporting, and internal follow-up. • Conduct user access reviews and review security settings, access configurations, and administrative controls across business systems, SaaS platforms, and internal infrastructure, tracking remediation where required. • Support recurring operational security workflows, including documentation, process tracking, and follow-up.
Information Security Analyst
AltoVitaAward-winning enterprise software layered with a human-centric approach to power the corporate accommodations sector.
Role Description The Information Security Analyst will support the day-to-day operation of AltoVita’s information security and privacy activities, ensuring compliance and fostering a culture of security awareness. Key Responsibilities - Security and Privacy Operations - Support the maintenance of security, privacy, and compliance documentation. - Assist with tracking security and privacy actions, control improvements, and remediation activities. - Help maintain registers such as risks, issues, actions, policies, vendors, assets, data processing activities, and control evidence. - Coordinate updates between internal teams to ensure agreed actions are progressed. - Support the preparation of security and privacy reports, summaries, and updates for internal stakeholders. - Help ensure security and privacy activities are documented, repeatable, and easy to evidence. - Escalate risks, issues, or delays to the CISO or relevant business owner. - Compliance and Audit Support - Assist with internal and external compliance activities, including ISO 27001, SOC 2, GDPR, and client assurance requirements. - Support evidence gathering for audits, assessments, and control reviews. - Help maintain audit trackers, evidence folders, and compliance records. - Coordinate with internal teams to obtain required documentation and control evidence. - Support follow-up actions from audits, assessments, or client reviews. - Assist with the maintenance of policies, procedures, and standards. - Help ensure compliance activities are well organized and delivered within agreed timelines. - Support the CISO and relevant control owners with audit preparation and remediation tracking. - Policy and Documentation Support - Help maintain clear, practical, and accessible security and privacy documentation. - Support the review and update of information security and privacy policies. - Assist with the creation of standards, procedures, guidance notes, and user-facing materials. - Help ensure documents are version controlled, approved, and communicated appropriately. - Maintain policy review schedules and track required updates. - Draft practical guidance for employees on security and privacy topics. - Support the communication of policy changes across the business. - Help ensure documentation is accurate, consistent, and aligned to business processes. - Security Awareness and Culture - Support the delivery of security and privacy awareness activities across AltoVita. - Carry out security and privacy training administration and ensure 100% completion rates across the business. - Support the development of awareness content, reminders, newsletters, FAQs, and guidance. - Help coordinate phishing simulations and follow-up communications. - Track training completion and awareness participation. - Support campaigns that promote secure behaviors and good privacy practices. - Help make security and privacy feel practical, accessible, and enabling. - Escalate recurring behavioral or process issues to the CISO or relevant business owner. - Privacy Support - Support AltoVita’s privacy activities under the direction of the relevant privacy, legal, or security lead. - Assist with the maintenance of privacy records, including data processing registers and related documentation. - Support the tracking of privacy actions, assessments, and improvement activities. - Help gather information for privacy reviews, data mapping, or data protection impact assessments. - Support internal teams with practical privacy guidance, escalating complex matters where needed. - Assist with record keeping for data subject requests, incidents, or privacy inquiries. - Help ensure privacy documentation remains organized, accurate, and accessible. - Client Assurance and Security Questionnaires - Support the completion of client security and privacy questionnaires, RFP responses, and due diligence requests. - Assist with the preparation of responses to client security and privacy questions. - Maintain a library of approved answers, evidence, and supporting materials. - Coordinate with internal subject matter experts to obtain accurate information. - Ensure responses are consistent with AltoVita’s current controls, policies, and practices. - Help translate technical or compliance information into clear, client-friendly language. - Track open client assurance requests and support timely completion. - Escalate complex, high-risk, or contractual questions to the CISO, Legal, or relevant business owner. - Supplier and Third-Party Support - Support supplier security and privacy processes under the direction of the CISO or relevant business owner. - Assist with supplier due diligence questionnaires and evidence collection. - Help maintain supplier records, risk ratings, and review schedules. - Track supplier security or privacy actions. - Support periodic reviews of key suppliers. - Help ensure supplier documentation is complete and up to date. - Escalate potential supplier risks or concerns to the appropriate owner. - Incident and Risk Support - Support security, privacy, and operational risk processes by helping with coordination, documentation, and follow-up. - Support the logging and tracking of security or privacy incidents. - Help gather relevant information during incident reviews. - Maintain incident notes, timelines, and action trackers. - Support post-incident follow-up and lessons learned activities. - Assist with risk register updates and remediation tracking. - Escalate suspected incidents or risks promptly to the CISO or relevant lead. - Support the documentation of controls, gaps, and agreed improvements. - IT and Access Control Support - Assist with security-related IT and access control activities where required. - Day-to-day execution of access controls. - Support access review processes by gathering user access information. - Help track joiner, mover, and leaver control activities. - Support evidence collection for account provisioning, deprovisioning, and access approvals. - Assist with documentation of access control processes. - Help monitor completion of agreed access management actions. - Oversight and support on internal reviews of security tooling usage, adoption, and documentation. - Escalate access control issues or gaps to IT, system owners, or the CISO. Qualifications - Experience in information security, privacy, compliance, IT, risk, audit, operations, or a related field. - Working knowledge of information security and privacy principles. - Awareness of GDPR, ISO 27001, SOC 2, or similar frameworks. - Strong written and verbal communication skills. - Ability to write clear guidance, summaries, and user-facing content. - Strong organizational skills and attention to detail. - Confidence working with stakeholders across different business functions. - Practical problem-solving approach. Requirements - Ability to maintain trackers, registers, documentation, and evidence records. - Ability to manage multiple tasks and deadlines. - Comfortable using collaboration tools, document repositories, and workflow trackers. Benefits - Opportunity to work in a fast-paced, innovative environment. - Fully remote work with a diverse team from 26 countries. - Support for professional development and training. What Success Looks Like - First 90 Days - Built strong working relationships with the CISO and key internal teams. - Understood AltoVita’s core security, privacy, and compliance activities. - Reviewed existing policies, registers, trackers, and evidence repositories. - Supported current audit, compliance, or client assurance activities. - Helped organize key documentation and improve visibility of open actions. - Identified areas where tracking, evidence, or documentation can be improved. - Started supporting awareness, access review, or supplier assurance activities. - First 6 Months - Helped improve the structure and consistency of security and privacy documentation. - Supported audit and compliance evidence collection in a timely and organized way. - Maintained clear action trackers for control improvements and remediation activities. - Helped improve security and privacy awareness materials. - Supported client assurance responses with accurate and reusable content. - Assisted with supplier due diligence and access review activities. - Improved the quality and availability of evidence for security and privacy controls. - Become a trusted support point for internal security and privacy coordination. - First 12 Months - Helped AltoVita operate a more structured, scalable, and measurable security and privacy function. - Success will be demonstrated through better organized security and privacy records. - Improved evidence readiness for audits and client assurance. - Clearer policy and procedure documentation. - More consistent tracking of risks, actions, and remediation activities. - Improved support for privacy records and data protection activities. - Stronger internal awareness of security and privacy responsibilities. - Faster and more consistent support for client security questionnaires. - Better visibility of supplier assurance and access review activities. - A more mature, well-documented, and business-friendly security and privacy operating model.
IT Security Analyst
GP StrategiesGP Strategies Corporation is one of the world's leading talent transformation providers. By delivering award-winning learning and development solutions, we help organizations transform through their people and achieve meaningful change. GP Strategies has delivered our innovative consulting, learning services, and talent technology solutions to over 6,000 organizations globally. From our global experience working across thousands of projects and initiatives over the past 55 years, we've learned that relationships, business, work, innovation, strategy, and transformation are all about people. And, to put it simply, GP Strategies is about our people - an extensive global network of learning experts. With more than 4000 employees in over 30 countries, diversity at GP Strategies is second nature! Beyond our locations, our culture focuses on performance and revolves around respect, fairness, and working collaboratively to achieve our goals. We support our People, no matter who they are or where they are from, because we all have valuable and unique perspectives and approaches. That's how great ideas are born, which enable us to work smarter. GP Strategies is committed and proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth and related conditions, sexual orientation, and gender identity), national origin, age, veteran status, disability, or any other federally protected class.
Role Description Monitor, investigate, and respond to security events to protect the organisation’s endpoints, identities, and cloud environments. Proactively reduce risk through vulnerability management, security patch coordination, and cloud posture auditing, while contributing to continuous improvement through automation, reporting, and support for audit and vendor assurance activities. Key Accountabilities - Manage and respond to security alerts and escalations to ensure timely identification and mitigation of potential threats. - Conduct regular vulnerability scanning and remediation using Tenable.io to identify and help mitigate risks within existing systems. - Assist with security patching and updates for Windows, macOS, and Linux systems using Microsoft Intune and Quest KACE SMA to maintain system hygiene. - Help maintain a strong CSPM framework by auditing AWS and Azure environments against CIS Benchmarks and established security policies. - Monitor and manage the Microsoft Defender suite to detect and investigate threats across endpoints, identities, and cloud workloads. - Develop and maintain automated security playbooks and workflows to increase the efficiency of incident response and repetitive security tasks. - Execute periodic phishing simulations to evaluate employee awareness and identify high-risk user groups. - Support internal and external audits and participate in vendor onboarding by providing technical evidence and helping ensure security requirements are met. Candidate Profile - Alert triage and incident response capability, including investigation using logs and telemetry. - Practical vulnerability management and patch coordination across Windows, macOS, and Linux environments. - Working knowledge of cloud security posture management across AWS and Azure, including assessment against CIS Benchmarks. - Continuous improvement mindset with interest in automating playbooks/workflows and strengthening controls over time.
Cyber Security Analyst
Sigma Software GroupWe support enterprises, product houses, and startups with custom software solutions development and IT consulting.
• Investigate advanced and persistent attacks using data analysis and data science tools • Analyze customers' web traffic to detect unidentified threats and reduce false positives using Elasticsearch and BigQuery • Research, design, and continuously enhance detection mechanisms to stay ahead of evolving threats • Provide real-time technical support to global customers, delivering professional and timely incident responses • Produce clear, insightful incident reports • Collaborate cross-functionally with R&D and Research teams to optimize the company's detection and mitigation capabilities • Design, plan, and implement internal automation projects to improve team efficiency • Work in a shift-based schedule, including weekends



