Information Security Analyst
Listed on 2026-03-01
-
IT/Tech
Cybersecurity, IT Consultant, Information Security, Security Manager
Requires at least 2x/week onsite in NYC.
Job DescriptionWe are seeking an Information Security Advisor to support a U.S.
-based Security Advisory team within a large financial services organization. This role is focused on hands‑on security advisory, design review, and threat/risk assessment in support of application and infrastructure initiatives. You will partner closely with business lines, application teams, and infrastructure stakeholders to ensure technology initiatives are designed and implemented in alignment with enterprise security standards and U.S. regulatory requirements.
This is a hands‑on advisory role requiring the ability to analyze system designs, understand how applications operate within cloud and on‑prem environments, and recommend appropriate security controls
, including compensating controls when needed.
- Perform security and risk assessments for applications and infrastructure across on‑prem, cloud, hybrid, and SaaS environments
- Conduct and support Threat Risk Assessments and threat modeling activities
- Review security architecture and design artifacts to understand data flows, trust boundaries, and control requirements
- Advise teams on security control selection
, compensating controls, and secure‑by‑design principles - Support cloud initiatives by providing security design and architecture guidance
- Validate implementation of security controls through evidence review and documentation
- Partner with technical and business stakeholders to balance security requirements with business objectives
- 5+ years of hands‑on experience performing information security assessments
- 3+ years conducting Threat Risk Assessments / threat modeling
- Experience reviewing application and infrastructure security designs
- Strong understanding of security controls
, including compensating controls - Experience interpreting vulnerability findings in a risk‑based context
- Knowledge of U.S. regulatory requirements and practices
- Strong written and verbal communication skills
- Cloud security experience (AWS, Azure, or GCP)
- Familiarity with security frameworks (NIST, ISO, CIS, PCI)
- Security certifications (CISSP, CISM, CCSP, CRISC)
- Experience using Service Now
- Health insurance
- Health savings account
- Vision insurance
- Flexible spending accounts
- Life insurance
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).