Source description
About the role
As a Cyber Security Analyst, you will be responsible for the security aspects of a portfolio of banking service platforms and applications. Your key responsibilities will include: - Implementing/contributing compliance projects to the functional and technical team. - Assisting functional and technical teams throughout major evolutions on platforms and applications, requiring understanding of architecture, functionalities, and security policies. - Ensuring compliance of applications with global audit and regulatory programs such as ECB Audit, NIST, GDPR Compliance, NYDFS & SECAIA. - Improving and maintaining the security level of applications and platforms in compliance with regulatory requirements and SG group security criteria. - Collaborating with application and technical teams to deploy, troubleshoot, and maintain required security solutions. - Preparing reports on BAU, key programs, and maintaining effective communication with project stakeholders. - Planning, organizing, and ensuring follow-up actions and action plans independently. - Conducting Application Security Assessment (ASA), security control assessment, and providing security recommendations. - Performing risk reviews, working on derogation/ad-hoc request validations, and maintaining risk acceptance documents as per group guidelines. - Driving Secure by design throughout SDLC of the applications. - Demonstrating and training teams on Secure by design and latest security technologies. Qualifications required for this role include: - 3 to 6 years of experience in IT security with knowledge in information security. - Understanding of architecture issues to develop security policies and recommendations. - Knowledge of SDLC, hands-on experience in Security Environments and activities. - Familiarity with Application Security, Vulnerability Management, Cloud Security, and Thread modeling. - Awareness of digital technologies, functional domain, and business processes. - Ability to identify and propose process improvements, prepare documentation, and consolidate on process/technical subjects related to Security. - Understanding of Cloud and network Security, IAM, Data encryption, SIEM. - Knowledge of regulatory programs such as GDPR, NYDFS, SCHREMS, DORA etc. - Exposure to languages and technologies like JAVA, API, ASP.Net, Spark, Python, react.js. - Familiarity with security tools like Qualys, Nessus, Nmap, Burp suite, SonarQube, netspaker, OWSAP. - Strong work ethics, adaptability, interpersonal skills, and problem-solving capabilities. In addition to the above responsibilities and qualifications, Socit Gnrale values employee engagement in positive impact initiatives and commitment to ESG principles in all activities and policies. Joining Socit Gnrale will provide you with the opportunity to contribute to a stimulating and caring environment while developing and strengthening your expertise. As a Cyber Security Analyst, you will be responsible for the security aspects of a portfolio of banking service platforms and applications. Your key responsibilities will include: - Implementing/contributing compliance projects to the functional and technical team. - Assisting functional and technical teams throughout major evolutions on platforms and applications, requiring understanding of architecture, functionalities, and security policies. - Ensuring compliance of applications with global audit and regulatory programs such as ECB Audit, NIST, GDPR Compliance, NYDFS & SECAIA. - Improving and maintaining the security level of applications and platforms in compliance with regulatory requirements and SG group security criteria. - Collaborating with application and technical teams to deploy, troubleshoot, and maintain required security solutions. - Preparing reports on BAU, key programs, and maintaining effective communication with project stakeholders. - Planning, organizing, and ensuring follow-up actions and action plans independently. - Conducting Application Security Assessment (ASA), security control assessment, and providing security recommendations. - Performing risk reviews, working on derogation/ad-hoc request validations, and maintaining risk acceptance documents as per group guidelines. - Driving Secure by design throughout SDLC of the applications. - Demonstrating and training teams on Secure by design and latest security technologies. Qualifications required for this role include: - 3 to 6 years of experience in IT security with knowledge in information security. - Understanding of architecture issues to develop security policies and recommendations. - Knowledge of SDLC, hands-on experience in Security Environments and activities. - Familiarity with Application Security, Vulnerability Management, Cloud Security, and Thread modeling. - Awareness of digital technologies, functional domain, and business processes. - Ability to identify and propose process improvements, prepare documentation, and consolidate on process/technical subjects r
More at Societe Generale