Cyber Security Risk Expert
Your field of responsibility
You will be responsible for threats, cyberattacks and risk scenarios modelling (identification, assessment, monitoring) and appropriate security controls determination together with development of cyber security testing functionality on one of the most sophisticated data analytics platforms. As a Cyber Security Advisor to senior management of the bank you will be engaged in project team who drives innovative ideas in the area of cyber security including the opportunity to evaluate and develop new cyber security methodologies and initiatives. You will be involved in discussions with both IT and Business clients resulting in appropriate actions which improve overall security level of the bank.
Your future colleagues
We work in the international team of information security experts within the Credit Suisse CISO organization and collaborate with other both IT and business teams to analyze the exposure associated with cyber risk. We are exposed to senior management with significant potential to grow and play a key role in improving bank’s cyber risk exposure. We are a department which values Diversity and Inclusion (D&I) and is committed to realizing the firm’s D&I ambition which is an integral part of our global cultural values.
Your new employer
We are looking for somebody who has a keen interest in cyber security and is able to see the wider context of things by understanding cyber security risk management principles in particular presents:
- Familiarity with threat intelligence area including cyber-attacks, risk scenarios and threat vectors analysis together with assessment of key controls against them.
- Knowledge of cyber security trends and types of attacks (including kill chain process and its stages).
- 5+ years of information security/IT audit/GRC experience.
- Detailed understanding of infrastructure components, technology risk and related controls.
- Outstanding communication and presentation skills and ability to draw actionable conclusions. Results-oriented individual with excellent problem solving skills.
Nice to have:
- Cyber security certification e.g. CISSP, CISA, CISM, CRISC, CEH, OSCP, CompTIA Security+ or similar is a plus.
- MITRE ATT&CK® Framework knowledge.
- Experience in and knowledge of industry standards (e.g. ISO 27001, COBIT, NIST, ITIL).
- Understands the value of diversity in the workplace and is dedicated to fostering an inclusive culture in all aspects of working life so that people from all backgrounds receive equal treatment, realize their full potential and can bring their full, authentic selves to work.