Western Alliance Bank - Phoenix, AZ

posted 5 months ago

Full-time - Mid Level
Phoenix, AZ
Credit Intermediation and Related Activities

About the position

The Security Risk and Compliance Analyst II-Cyber position at Western Alliance Bank is designed for a detail-oriented information security professional with a focus on assessing third-party security risks. This role is critical within the information security organization, primarily responsible for reviewing and evaluating vendor-submitted questionnaires and supporting documentation to identify potential security risks that may not be controlled. The successful candidate will play a key role in ensuring compliance with various information security legal and regulatory requirements, making this position vital for the bank's overall security posture. In this role, the analyst will conduct comprehensive reviews of vendor materials, which may include SOC reports, certifications, policies, and procedures, to assess compliance with the bank's information security requirements. The analyst will be tasked with identifying and documenting any information security gaps found in vendor documentation and will need to request additional documentation through the vendor management process. Collaboration with cross-functional teams is essential to ensure alignment with regulatory standards and best practices, and the analyst will also be responsible for reporting on vendor security reviews, including volume and status updates. The ideal candidate for this position will possess a strong understanding of information security frameworks and common IT principles, along with experience in evaluating vendor security risks. Analytical skills and attention to detail are crucial, as the role requires interpreting complex information security documentation and applying it to practical scenarios. The candidate should also have proven technical writing and communication skills, enabling them to work independently while also collaborating effectively with others.

Responsibilities

  • Conduct comprehensive reviews of vendor submitted material including SOC reports, certifications, policies, and procedures to assess compliance with WAB's information security requirements.
  • Identify and document information security gaps in vendor documentation and request additional documentation through the vendor management process.
  • Collaborate with cross-functional teams to ensure alignment with regulatory standards and best practices.
  • Report on vendor security reviews, including volume, status, and other relevant metrics.

Requirements

  • Bachelor's degree in information systems or a related field, or relevant experience.
  • Minimum of 3 years of experience conducting vendor security assessments.
  • Practical recent experience with information security frameworks such as ISO 27001/2, NIST CSF, NIST SP 800-53, SIG, etc.
  • Excellent analytical skills with the ability to interpret complex information security documentation and apply them to practical scenarios.
  • Exceptional attention to detail and organizational skills.
  • Proven technical writing and communication skills with the ability to work independently and collaboratively.

Nice-to-haves

  • Industry certifications such as CISA, CRISC, CISM, etc. are preferred but not required.

Benefits

  • 401(k) matching
  • Dental insurance
  • Health insurance
  • Tuition reimbursement
  • Wellness program
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service