Jobs
>
New York City

    Senior Specialist, Technical Risk Assessment - New York, United States - Marsh McLennan

    Default job background
    Regular
    Description

    The Senior Specialist Technical Risk Assessment role's main purpose is to provide an in-depth analysis of the security risk affecting an information system being evaluated by MMC, as a component of MMC technology onboarding process.
    A technical risk assessment (TRA) function, as the main purpose of the Sr. technical risk analyst role, provides in-depth security risk evaluation on information systems such as software applications, cloud services, potential merger/ acquisition targets, and wide deployment / elevated privilege software tools. These security risk-based evaluations
    will outline adherence to information security policy, standards, and controls; and will include enumerations of risks
    and recommendations for actions or mitigations to reduce risk.
    What can you expect?The most relevant responsibility is the identification of security concerns and the assessment of technical risks
    in information systems ─under evaluation─ such as, software products, cloud services, applications, DBs, and technology implementations.
    To perform this main responsibility, the Senior Technical Risk Analysts:

    • Engage with the service requesting team to understand the purpose of the information systems ─under evaluation─ and its requirements for deployment. Review the solution capability, deployment plans and solution architecture to ensure alignment to Global Information Security requirements.

    • Work with technology teams, technology product owners, architects, application owners, security leaders, and business teams (stakeholders) to identify the information systems' security capabilities, security gaps, configuration requirements and technical security implementation recommendations.

    • Perform a technical risk evaluation of the information systems, including in-depth technical security aspects, such as the identification, authentication, and authorization of users, roles, and programs connecting to the information system under evaluation. Encryption mechanisms of MMC information assets in transit, at rest. Network security. Auditing, monitoring, and logging capabilities. System resiliency. Assessing the deployment of approved code and images . Suitability of patching practices and updates. With the goal of determining adherence to MMC Global Information Security requirements.

    • Produce risk reports and documentation to enable information system's stakeholders to understand outcomes of analysis, including technical security implementation recommendations, references to appropriate policies and standards and gaps in the solution capability.

    The Sr. TRA analyst will report directly to the TRA manager, as part of the Information Security IT / Cyber Risk Management organization within Global Information Security.
    We will count on you:

    • Engage with service requesting teams to understand the purpose of the information system ─under
      evaluation─ and requirements for deployment. Review the system's security capabilities, understand the
      architectural components and deployment plans and against applicable security standards and controls to
      ensure alignment to Global Information Security requirements.

    • Participate in larger technology reviews with multiple workstreams and project stakeholders, ensuring the
      timeliness and quality of the information security review.

    • Produce reports and documentation to enable security and technology team members to understand
      outcomes of security analysis, including references to appropriate policies and standards and gaps in the
      solution capability.

    • Ensuring a timely completion of TRA service requests; assess various projects simultaneously by managing
      the expectation of multiple stakeholders with competing priorities.

    • Collaborate with other Technical Risk Assessment team and technology implementation teams within
      MMC in the creation and improvement of security implementation guidelines and standards, ensuring
      alignment to policy.

    • Through training, and collaboration with other technology teams, the Senior Technical Risk Analysts
      acquire the knowledge, further expertise, and update information and practices to maintaining an excellent
      level of performance demanded by pervasive security threats and evolving security practices.

    What you need to have:

    • 10+ years of working experience in IT.

    • 5+ of explicit working experience in information security, and risk; having performed technical risk
      identification, evaluation, and risk management processes. Use of risk management instruments and tools,
      such as risk registers and assessment tools.

    • In-depth knowledge of IT, SDLC, information security, privacy, technical risks evaluation.

    • Deep understanding of identity and access management (IAM) technologies and standards ─inclusive of
      cloud identity platforms & Microsoft AD─ encryption, networking, firewalls, web applications, on-premises,
      and cloud application hosting environments.

    • In-depth cloud service security and architecture

    • Strong knowledge of NIST and ISO security risk frameworks, controls, and standards.

    What makes you stand out?

    • Exceptional communication skills to all levels of the organization & external contacts

    • Must be a self-starter, work with limited supervision & be able to work well with others in a globally
      diverse IT environment.

    • Experience coding/scripting with common languages such as Java Script, Python & Perl is preferred.

    • CISSP and/or CSSLP certification is preferred. Other Information Security oriented certifications a plus

    What is in it for you?

    • A company with a strong brand and strong results to match.

    • Culture of internal mobility, collaboration, and valued partnerships.

    • Competitive pay (salary and performance bonus potential).

    • Full benefits package – starting day one (medical, dental, vision, life insurance, 401k match AND contribution).

    About MMC.Marsh is the world's leading insurance broker and risk adviser. With over 35,000 colleagues operating in more than 130 countries, Marsh serves commercial and individual clients with data driven risk solutions and advisory
    services. Marsh is a business of Marsh McLennan (NYSE: MMC), the leading global professional services firm in the areas of risk, strategy and people. With annual revenue approaching US $17 billion and 76,000 colleagues
    worldwide, MMC helps clients navigate an increasingly dynamic and complex environment through four market-leading businesses: Marsh, Guy Carpenter, Mercer, and Oliver Wyman. Follow Marsh on Twitter @MarshGlobal; LinkedIn; Facebook; and YouTube or subscribe to BRINK.
    Marsh McLennan and its Affiliates are EOE Minority/Female/Disability/Vet/Sexual Orientation/Gender
    Identity employers


    The applicable base salary range for this role is $82,600 to $165,200.

    The base pay offered will be determined on factors such as experience, skills, training, location, certifications, education, and any applicable minimum wage requirements. Decisions will be determined on a case-by-case basis. In addition to the base salary, this position may be eligible for performance-based incentives.

    We are excited to offer a competitive total rewards package which includes health and welfare benefits, tuition assistance, 401K savings and other retirement programs as well as employee assistance programs.



  • Apple New York, United States

    Summary · Posted: Apr 9, 2024 · Role Number: · Imagine what you could do here. At Apple, new ideas quickly become great products, services, and customer experiences. Bring passion and dedication to your job and there's no telling what you could accomplish. Do you relish takin ...


  • Bank of China USA New York, United States

    This incumbent will support the operational risk management activities, including Risk and Controls Assessment, Process Library Management, Risk and Controls Taxonomy, Controls Testing, Issues Management, and Risk Analytics in accordance with Heightened Standard. S/he will admini ...


  • Ernst & Young Advisory Services Sdn Bhd Hoboken, United States

    Press Tab to Move to Skip to Content Link · EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities. At EY, you'll have the chance to build a career as unique as you are, with the global scale, support, incl ...


  • Ernst & Young Hoboken, United States

    Job Description · EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities. At EY, you'll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technolo ...


  • Michael Page Manhattan, United States TEMPORARY

    About Our Client Our client is located near Midtown NYC and is one of the largest Chinese banks located in the US. They have been around for 40 years and they focus on corporate and correspondent banking. · Job Description Report into the Head of Risk Assessment and assist with ...


  • Michael Page Manhattan, United States TEMPORARY

    About Our Client Our client is located in (Midtown) New York, NY. They are a foreign investment bank that is looking to hire a Risk Assessment Consultant for their legal and compliance department. · Job Description The Risk Assessment Consultant will be responsible for the follo ...


  • ASB Resources New York, United States

    Location: Iselin, NJ Or midtown, NY ( onsite 5 days) · Job Title: Infrastructure Audit/Risk Assessment Support · Job Description: Please see below. · Responsibilities: · •Communicate with auditors to answer questions and provide clarification · •Review audit findings and pro ...


  • Sumitomo Mitsui Banking Corporation New York, United States

    SMBC Group is a top-tier global financial group. Headquartered in Tokyo and with a 400-year history, SMBC Group offers a diverse range of financial services, including banking, leasing, securities, credit cards, and consumer finance. The Group has more than 130 offices and 80,000 ...


  • EY Hoboken, United States

    Today's world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of over 950 people who col ...


  • Citigroup New York, NY, United States

    The Risk Appetite Assessment Principal is a strategic professional who closely follows latest trends in own field and adapts them for application within own job and the business. Recognized subject matter expert within at least one aspect of non-financial risk. Strong commercial ...


  • Amex New York, United States

    **You Lead the Way. We've Got Your Back.** · With the right backing, people and businesses have the power to progress in incredible ways. When you join Team Amex, you become part of a global and diverse community of colleagues with an unwavering commitment to back our customers, ...


  • Sumitomo Mitsui Banking Corporation New York, United States

    SMBC Group is a top-tier global financial group. Headquartered in Tokyo and with a 400-year history, SMBC Group offers a diverse range of financial services, including banking, leasing, securities, credit cards, and consumer finance. The Group has more than 130 offices and 80,000 ...


  • Deutsche Bank San Francisco, United States Permanent

    Job Description: · Job Title Risk & Control Assessment (RCA) & Scenarios Implementation Support · Corporate Title Analyst · Location New York, NY · Overview · Deutsche Bank is a leading provider of financial services to agencies, corporations, governments, private profession ...


  • UBS Weehawken, United States

    **Financial Crimes IT Tech Delivery Manager- Risk Assessment** · United States - New Jersey · Information Technology (IT) · Group Functions · Job Reference # · 242451BR · City · Weehawken · Job Type · Full Time · Your role · Were looking for someone like that to streng ...


  • JPMorgan Chase Bank, N.A. Jersey City, United States

    Firmwide Control Management (CM) ensures a robust control environment across the organization. We are seeking multiple team members to support the execution of the Compliance Risk Assessment (CRA) Program. This high-profile role involves assessing key compliance risks across the ...


  • Deutsche Bank New York, United States

    Job Description:Job Title Risk & Control Assessment (RCA) & Scenarios Implementation SupportCorporate Title AnalystLocation New York, NYOverviewDeutsche Bank is a leading provider of financial services to agencies, corporations, governments, private professionals and institutions ...


  • UBS Weehawken, United States

    **Financial Crimes IT Tech Delivery Manager- Risk Assessment** · United States - New Jersey · Information Technology (IT) · Group Functions · Job Reference # · 242451BR · City · Weehawken · Job Type · Full Time · Your role · Were looking for someone like that to strengthen our co ...


  • Nexus Innovations York, United States

    The Schwarz IT KG is responsible for the selection, provision, operation, and further development of IT infrastructures, platforms, and business applications as the central IT service provider. This includes providing IT services for both Kaufland and Lidl, as well as the Schwarz ...


  • Velocity Enterprises Hudson, United States

    We are looking for motivated employees for over 500 different professions, all across Germany. Whether you are an experienced professional or just starting your career, we offer numerous entry and training opportunities. · We are currently seeking a Train Traffic Controller (m/f/ ...


  • ASPCA New York, United States

    Please make sure to attach your resume to complete your application. · Summary: · The ARC (Animal Recovery Center) and CARE (Canine Annex for Recovery and Enrichment) facilities are dedicated to the recovery and rehabilitation of victims of cruelty and neglect admitted through NY ...