SonicJobs Logo
Left arrow iconBack to search

Principal-Information Security Officer

National Bank of Kuwait
Posted 4 months ago, valid for 20 days
Location

New York, NY 10008, US

Salary

$120,000 per year

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • The role involves supporting the NY Head of Information Security in enhancing the branch's information and cyber security posture.
  • Candidates should have a Bachelor's degree in Information Technology, Cybersecurity, or a related field, along with 5-7 years of experience in information security or IT risk.
  • Key responsibilities include assisting with regulatory compliance assessments, security operations, and maintaining documentation for audits and management reporting.
  • The position also requires basic knowledge of information security principles and a willingness to learn about regulatory and compliance requirements.
  • The salary for this role is competitive and commensurate with experience.

Job Purpose:

Support the NY Head of Information Security in maintaining the branch’s information and cyber security posture. Assist in implementing and maintaining information security policies, procedures, and controls. Participate in security assessments, monitoring activities, reporting, and compliance tracking. Develop foundational expertise in regulatory, technical, and governance aspects of information security under mentorship.


Responsibilities:

  • Assist in the identification and assessment of local regulatory and compliance requirementsĀ related to Information and Cyber Security, including OCC and CIMA expectations, and support timely communication to the Group ISO.
  • Support periodic access reviews, risk assessments, and compliance tracking

activities.

  • Maintain documentation and evidence to support internal audits, regulatory exams, and management reporting.
  • Assist in tracking remediation actions for identified gaps and issues.

Security Assessments & Vulnerability Management

  • Support security assessment activities, including:
    • Vulnerability scanning
    • Application security reviews
    • Infrastructure and configuration reviews
    • Third-party/vendor security assessments
  • Track assessment results, remediation plans, and exceptions using designated tools (e.g., Remedy or equivalent).
  • Assist in maintaining the Vulnerability Assessment DashboardĀ and exception tracking.

Security Operations & Monitoring

  • Coordinate with the outsourced Security Operations Center (SOC/MSSP)Ā for:
    • Log review follow-ups
    • Alert tracking
    • Incident documentationĀ 
  • Assist in monitoring security alerts and escalating issues in accordance with defined procedures.
  • Support maintenance of incident records and post-incident documentation.


Policy, Standards & Awareness

  • Assist in reviewing and updating information security policies, procedures, and guidelines under the direction of the NY ISO.
  • Help ensure NY policies, standards and procedures align with Group ISO policies, standards, procedures and evolving cybersecurity risks.
  • Support the planning and delivery of information security awareness and training programsĀ for employees, contractors, and third parties.


Asset & Technology Support

  • Maintain accurate IT asset inventoriesĀ required for security assessments.
  • Support evaluation of new technologies and vendors, including documentation and Proof-of-Concept activities.
  • Assist in tracking the effectiveness of patch management and system hardeningĀ activities.


Metrics, Reporting & Administration

  • Collect data for security metrics, KRIs, and KPIsĀ as defined by management.
  • Prepare draft reports and presentations for internal stakeholders and management review.
  • Maintain organized records of security initiatives, assessments, and control testing results.


Qualifications and Experience:

  • Bachelor’s degree in Information Technology, Cybersecurity, Information Systems, or related field.
  • 5–7 years of experience in information security, IT risk, audit, or IT operations (financial services preferred).
  • Entry-level or working toward professional certifications such as:
    • Security+
    • CISA (Associate)
    • ISO 27001 Foundation
    • CISSP (Associate)

Skills Essential:

  • Strong written and verbal communication skills.
  • Ability to follow structured processes and document results accurately.
  • Basic understanding of:
  • Information security principles
  • Risk management concepts
  • Vulnerability management
  • Willingness to learn regulatory and compliance requirements.
  • Ability to manage multiple tasks with supervision.



Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.