Information Security Risk Analyst
Sumitomo Mitsui Trust Bank ‚Ä¢ New York, NY ‚Ä¢ Full Time ‚Ä¢ $90,000–$125,000 / year
Posted on Sat, Aug 22, 2026
This role is located in New York City and will require a hybrid work schedule of at least 2 days in office per week.
This role is for Officer level candidates.
About the Bank:
Sumitomo Mitsui Trust Bank, Limited was established through the merger of The Sumitomo Trust and Banking Co., Ltd with Chuo Mitsui Trust and Banking, Ltd. on April 1, 2012. We are one of the largest asset managers in Asia and number one among Japanese financial institutions by AUM, with approximately $850 Billion USD in AUM. The Bank provides an assortment of financial solutions and manages a broad spectrum of financial products across its global branches.
Department Overview:
The Americas Division (“AD”) was established in the Sumitomo Mitsui Trust Bank, Limited, New York Branch) (“SMTBNY”) to perform corporate functions and supervise U.S. entities. Established under the AD are the “Global Banking Unit (“GBU”), Americas Division” and “Global Markets Unit (“GMU”), Americas Division” which performs business functions. Information Risk Governance (“IRG”) provides oversight to information and cyber security risk by maintaining and improving branch wide framework that is in-line with the Head Office and regulatory requirements and addresses Confidentiality, Integrity, and Availability for information assets. IRG establishes appropriate policies, procedures, measurement, and monitoring processes to proactively assess and evaluate and cyber security and information security risks inherent in the Branch Operations. IRG is directly involved in all information and cyber security related projects, matters and issues.
Your Role Overview:
The Information Security Risk Analyst is responsible for supporting the organization’s vulnerability management program and performing assigned information security risk assessments. This role will perform the day-to-day vulnerability management activities, perform risk-based analysis of identified vulnerabilities, coordinate remediation efforts with the IT Department, and help ensure systems are maintained in accordance with the organization’s information security standards.
Your Duties and Responsibilities:
- Administer and support the organization’s system vulnerability management program.
- Conduct regular vulnerability scans across servers, endpoints, applications, network infrastructure, and Cloud environments.
- Monitor vulnerability scanning coverage and coordinate with the IT Department to identify missing, newly added, or decommissioned IT assets and ensure that the scanning scope remains accurate and up to date.
- Review and analyze vulnerability scan results and cross-reference with other sources such as the CISA Known Exploited Vulnerabilities (KEV) catalog to identify high-criticality areas for remediation. Identify potential false-positive findings and review with ITD for validity.
- Collaborate with ITD to prioritize system vulnerability remediation and patching based on system risk severity, vulnerability exploitability, asset criticality, and potential business impact.
- Track identified vulnerabilities through remediation and/or mitigation, validate remediation through re-scanning or review of appropriate supporting evidence, and generate regular system vulnerability remediation status reports.
- Monitor compliance of system vulnerability remediation based on pre-defined risk-based remediation targets. Escalate critical or significant delays of system vulnerability remediation based on pre-defined targets to Management, as necessary.
- Create vulnerability management-related reports with risk summaries and recommendations to Management.
- Perform risk assessments on proposed new systems to be introduced to the organization.
- Perform other duties and responsibilities as assigned by management.
Your Qualifications:
- Strong understanding and prior experience working with network components and devices such as Firewalls, IPS, IDS, switches, routers, NDR, and NAC.
- Strong understanding and prior experience working with Microsoft Windows-based environments including components such as domain controllers, DHCP, DNS, and Active Directory.
- Foundational understanding of Information Security frameworks such as NIST Cybersecurity Framework and SP 800-53 as well as Cyber Risk Institute Profile v2.x
- 3+ Years of experience managing System Vulnerability Management tools such as Qualys or Tenable.
- 3+ Years of experience with risk assessment methodologies and techniques
- Prior experience with financial industry structure and concepts a plus.
- Strong verbal and written communication skills.
- Strong analytical skills with attention to detail and accuracy.
- Self-motivated with good time management skills.
Why you should join SuMi Trust:
SuMi Trust embraces flexible ways of working when the business and role permits. We provide employees with a hybrid working model, allowing for in-office work and work from home. Our diverse and inclusive environment along with our global presence enables us to collaborate and communicate to meet our business needs. We believe that efficient teams need truth, loyalty, and a strong sense of purpose to balance risk and their targets. We make sustainable business decisions to improve our society and the world. We believe that each person brings a unique value that drives the business though their creativity and passion.
The Employee Benefits package includes: Paid Time Off, medical, HSA, vision, dental, FSA, 401(k), profit sharing, legal plan, cancer indemnity plan, disability insurance, life insurance, employee assistance program, commuter benefits, business travel accident, paid volunteer day, paid memberships, paid seminars, and tuition assistance.
We offer many socialization opportunities for wellness, financial wellbeing, runs/walks, team building, happy hours, and activities to support the Sustainable Developmental Goals.
Check out our LinkedIn for our employee experience: https://www.linkedin.com/company/smtbny
We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, national origin, disability status, protected veteran status or any other characteristic protected by law. SuMi Trust provides reasonable accommodations for employees and applicants with disabilities consistent with applicable law. If you need a reasonable accommodation during the application
More live risk_analyst roles
- Senior Risk Analyst — Burlington, New Jersey, United States
- Manager, Credit Risk Analyst at Charles Schwab Corporation — Westlake, TX, United States
- Information Security Risk Analyst (SOC) at SUMITOMO MITSUI TRUST BANK — New York, New York, United States
- Risk Analyst at Hancock Whitney Bank — Gulfport, Mississippi, United States
- Financial Crimes Risk Analyst at Origin Bank — Longview, Texas, United States
- Senior Business Risk Analyst at Crisis24 (Remote)
- Senior IT Compliance and Risk Analyst at NextEra Energy (Remote)
- Information Security Risk Analyst at Sumitomo Mitsui Trust Bank — New York, New York, United States
- Risk Analyst at DHRM — Richmond, Virginia, United States
- Senior Product Financial Risk Analyst at SWBC — San Antonio, Texas, US
- Risk Analyst at Graham Capital Management — Norwalk, Connecticut, United States
- Risk Analyst at Fiserv — Omaha, Nebraska, United States
- Senior Third Party Risk Analyst at ICW Group — San Diego, California, United States
- Senior Risk Analyst - Finance Oversight at M&T Bank — Buffalo, New York, US
- Securities Finance Front Office Market Risk Analyst, Vice President at State Street — Boston, MA, United States
- Market Risk Analyst at TD Bank (Remote)
- Foreign Investment Risk Analyst at Amentum — Washington, United States
- Business Risk Analyst Sr at Fidelity International — Mississauga, Canada
- Campus - Risk Analyst Program Intern at Fannie Mae (Remote)
- Risk Analyst (Claims Adjuster) at Fresno Regional Workforce Development Board (Remote)
- Operational Risk Analyst, Senior at Old National Bank — Lake Elmo, Minnesota, United States
- Core Treasury Sr. Risk Analyst at KeyBank — Cleveland, Ohio, United States
- Senior Technology Risk Analyst at Flagstar Bank — Troy, MI, United States
- Credit Risk Analyst at Washington Trust — Providence, Rhode Island, United States
- Senior Risk Analyst at Primient — Schaumburg, IL, United States
- Senior Technology Risk Analyst at Sungrow USA Corporation (Remote)
- Market Risk Analyst at Tenaska — Omaha, Nebraska, United States
- Fraud Risk Analyst at U.S. Bank — Minneapolis, Minnesota, United States
- Credit Risk Analyst at Federal Home Loan Bank of Des Moines — Des Moines, Iowa, United States
- Risk Analyst - Portfolio Forecasting at GM Financial — Fort Worth, TX, United States
- Junior Risk Analyst – Enterprise Risk Management at CACI — Colorado Springs, Colorado, United States
- AVP, Credit Risk Analyst (Capital Markets) at Cantor Fitzgerald — New York, United States
- Risk Analyst II, Portfolio Analytics at GM Financial — Fort Worth, Texas, United States
- Market Risk Analyst at Royal Bank of Canada — New York, NY, US
- Senior Risk Analyst at Polymarket — New York, New York, United States
- Risk Analyst at Bridge Specialty Group (Remote)
- AVP, Prime Brokerage Risk Analyst at Cantor Fitzgerald — New York, New York, United States
- Senior Associate - Data Risk Analyst at New York Life Insurance — New York, United States
- Corporate Insurance/Risk Analyst at Avery Dennison — Mentor, Ohio, United States
- Insurance and Risk Analyst at Acrisure — Dallas, Texas, US
- Credit Risk Analyst at Columbia Bank — Tigard, Oregon, United States
- Senior Catastrophe Risk Analyst at Tokio Marine HCC — Duluth, Georgia, United States
- Sr. Risk Analyst, Credit Risk Management at Merrick Bank — South Jordan, Utah, United States
- Senior Corporate Risk Analyst at Alliant Insurance Services (Remote)
- Principal Technology Risk Analyst at Fidelity — Westlake, Texas, United States
- Insurance Risk Analyst at Marsh McLennan (Remote)
- Senior Risk Analyst at TC Energy — Calgary, Alberta, Canada
- Cyber Risk Analyst at City of New York — New York City, New York, United States
- Enterprise Risk Analyst - AI Risk at Boeing Employees' Credit Union (Remote)
- Risk Analyst (Credit Risk) at goeasy — Mississauga, Ontario, Canada
- Risk Analyst at Vast Bank — Tulsa, OK, US
- Treasury Risk Analyst at SUMITOMO MITSUI TRUST BANK — New York, New York, United States