BNY Mellon Careers
Principal Architect, Information Security
- Plans and designs security architecture and solutions by evaluating network and security technologies; developing requirements for applications, OS, data in motion and data at rest; designs maintainable security solutions, including access administration, public key infrastructures (PKIs), data leakage and information protection as well as COTS hardware and software; adhering to industry standards and frameworks
- Determine security requirements by evaluating business strategies and requirements; researching information security standards; conducting system security and vulnerability analyses and risk assessments; studying architecture/platform; identifying integration issues; when needed preparing cost estimates.
- Enhances existing design and competence by planning delivery of solutions; answering technical and procedural questions for less experienced team members; teaching improved processes; mentoring team members.
- Wide breadth of knowledge across security products, tools, and industry trends; ability to create solutions using a pragmatic, risk-based approach.
- Assesses security threats and vulnerabilities using structured methodologies such as NIST Cybersecurity Framework and ISO 27001.
- Prepare and maintain security operating procedures and associated documentation.
- Prepares system security reports by collecting, analyzing, and summarizing data and trends; presents reporting for management review.
- Create process improvement by identifying inefficiencies and solutions for process improvements.
- Works with IT Security team on placement and configuration of key monitoring and prevention tools.
- Writes clear implementation guidelines for the implementation engineers.
- Guides and confirms that the design has been implemented as per the requirements.
- Enhances department and organization reputation by accepting ownership for accomplishing new and different requests; exploring opportunities to add value to business strategies and objectives.
- Updates job knowledge by tracking and understanding emerging security practices and standards; participating in educational opportunities; reading professional publications; maintaining personal networks; participating in professional organizations.
- Experience with SDLC methodologies, especially related to Secure SDLC, dynamic and static code analysis and application threat modeling.
- Bachelor's degree in computer science or a related discipline, or equivalent work experience required, advanced degree preferred
- 10-12 years of experience in information security or related technology experience required, experience in the securities or financial services industry is a plus
- CISSP (CISSP:ISSAP is a plus), GIAC, GSEC, CEH, OSCP or equivalent certifications as appropriate
- Knowledge of ITIL or other ITSM methodology or certification a plus
- Solid understanding of TCP/IP and networking concepts
- Strong knowledge of networking concepts and architecture, including security considerations associated with networking hardware like Routers, Switches, Firewalls, Gateways etc.
- Prior experience in emerging networking areas, including Software Defined Networking (SDN) strongly desired
- Strong knowledge of VPN & Routing technologies & concepts including but not limited to IPsec, MPLS, GRE, GET VPN
- Successful implementation experience with DevSecOps methodologies, tools and practices
- Solid understanding of Operating system security concepts
- Understanding of malware, emerging threats, attacks, and vulnerability management
- Strong deductive reasoning, critical thinking, problem solving, and prioritization skills
- Experience assisting the development and maintenance of tools, procedure, and documentation
- Track record of effective project management and project delivery
- Strong service mentality including the resolution of stakeholder escalations and incident management
- Ability to work in a fast-paced team environment
- Ability to develop detailed process and procedure documentation
- Ability to present complex solutions and methods to both technical and non-technical stakeholders
- Excellent written and verbal communication and organizational skills
- Strong team player who collaborates well with others to solve problems
For over 230 years, the people of BNY Mellon have been at the forefront of finance, expanding the financial markets while supporting investors throughout the investment lifecycle. BNY Mellon can act as a single point of contact for clients looking to create, trade, hold, manage, service, distribute or restructure investments & safeguards nearly one-fifth of the world's financial assets. BNY Mellon remains one of the safest, most trusted and admired companies. Every day our employees make their mark by helping clients better manage and service their financial assets around the world. Whether providing financial services for institutions, corporations or individual investors, clients count on the people of BNY Mellon across time zones and in 35 countries and more than 100 markets. It's the collective ambition, innovative thinking and exceptionally focused client service paired with a commitment to doing what is right that continues to set us apart. Make your mark: bnymellon.com/careers.
Client Technology Solutions provides our business partners with client-focused, technology-based solutions. These enhance their ability to be successful through world-class software solutions and leading-edge infrastructure. Client Technology Solutions provides employees with the tools and resources to enhance their professional qualifications and careers.
BNY Mellon is an Equal Employment Opportunity/Affirmative Action Employer.
Minorities/Females/Individuals With Disabilities/Protected Veterans.
Primary Location: United States-District of Columbia-Washington
Internal Jobcode: 45012
Job: Information Technology
Organization: Information Security-HR11724
Requisition Number: 1709285