Back to Jobs

IT - Info Security Analyst V -cybersecurity metrics, cyber risk reporting, SOC

Remote, USA Full-time Posted 2026-03-20
RETURNING MANAGER FOLLOW-UP QUESTIONS: Previous JP#: Feedback from last time & Areas of Opportunities: ASSIGNMENT DETAILS: Position Title: US - IT - Info Security Analyst V (US equivalent of TDJP00057333) # of positions: 2 Start Date: ASAP Duration: 8 months Extension possible: Possibility based off of business needs and performance Conversion Possible: Possibility based off of business needs and performance Billing Cost Center: 1274 Business Unit: 4 - Global Security and Defence (S_1017254) Schedule: M-F, core business hours 40 hours per week, 8 hours per day OT: No Rotation: No Work Location: • Remote, Onsite, or Hybrid: hybrid if they live near a hub or remote if they do not • Anchor Days (if applicable): N/A • Address: we will discuss hub and remote details in the supplier call tomorrow Travel Required: No Possibility of any Additional Upcoming Furlough: Standard STORY BEHIND THE NEED: Reason for request/why opened: Project support Scope of Project: uplifting reporting space within GRC groups Team Size/Culture: 10 people, collaborative working environment Training Period: TD onboarding and hit the ground running Selling Points of Position (CVP): Opportunity for long-term, very high visibility work with leadership team, opportunity to network and grow within bank ADMIN/CLERICAL ONLY: Back-office vs Telephone work: CANDIDATE PROFILE DETAILS: Degree/Level of Education: Post secondary is a nice to have work experience is more important Certifications Required: Nothing required Years of Overall Experience: 8+ years with flexibility How will performance be measured: hitting deliverables and timelines Preferred/Ideal Candidate Background: banking or financial experience is an asset, strong BI tool experience and advanced level Excel skills SUMMARY OF THE ROLE: • Typical Day-to-Day Responsibilities • How much time is being spent in meetings 25% of their day will be spent in meetings • Who are they interacting with (internal/external) internal partners • Will the contractor have access to any customer data? No Role Summary The Senior Security Metrics and KRI Design Analyst is responsible for defining, governing, and driving adoption of enterprise security performance metrics, including Key Risk Indicators (KRIs), Key Performance Indicators (KPIs), and operational security metrics. This role partners with cyber domain leaders (IAM, SOC, Vulnerability Management, GRC, Cloud Security, AppSec, Third Party Risk, etc.) to translate security strategy and risk appetite into measurable outcomes, and to ensure metrics are implemented, trusted, automated, and consumed by operational teams and executives. This role is accountable for full lifecycle delivery: strategy -> design stakeholder alignment implementation data quality reporting continuous improvement. Key Responsibilities 1) Metrics Strategy, Design & Standardization • Lead design and ongoing evolution of security metric taxonomy, ensuring consistent definitions for KRIs, KPIs, and operational measures. • Build/maintain a security metrics library including: • metric definitions (name, intent, formula, thresholds) • risk mapping (control objectives, risk statements) • tiering and criticality (enterprise vs domain vs team level) • target ranges and escalation logic • Ensure metrics align to: • enterprise risk appetite/tolerance • security strategy and OKRs • regulatory or audit expectations (as applicable) 2) Stakeholder Engagement & Socialization • Facilitate working sessions with security leaders to drive alignment on: • metric definitions • thresholds / limits • performance expectations • ownership and action plans • Translate technical security outcomes into business-relevant language suitable for executives and non-technical stakeholders. • Establish strong partnership with ERM, Audit, Compliance, and Technology leaders to ensure metric credibility and broad adoption. 3) Implementation Leadership (Build & Operationalize) • Drive implementation of metrics into reporting workflows and tooling (e.g., Power BI/Tableau, Archer, ServiceNow, Splunk, Jira, CMDB, EDR platforms). • Partner with data engineering teams to automate metric feeds and reduce manual reporting. • Define data requirements and map sources to metric logic. • Build repeatable metric operational procedures: • refresh cycles • validations • approvals • artifact retention 4) Reporting, Insights & Executive Readouts • Develop executive-ready reporting packages for: • Security leadership • Technology leadership forums • Risk committees / Board materials (as required) • Provide analysis beyond the numbers: • trend drivers • root cause hypotheses • leading indicators vs lagging indicators • recommended actions • Prepare talking points and narrative summaries to ensure metrics drive decisions not just reporting. 5) Data Quality, Controls, and Governance Establish controls to ensure metrics are: • accurate • complete • consistent across domains • traceable back to systems-of-record • Implement documentation, QA checkpoints, and periodic metric reviews (e.g., quarterly definition validation). • Enforce metric governance and reduce metric sprawl. Key Competencies • Metrics design + governance mindset • Executive presence / ability to brief leadership • Strong facilitation and workshop leadership • Ability to balance precision with pragmatism • Data storytelling and narrative building • Ownership mentality; proactive problem solver Deliverables / Success Measures (first 6 12 months) • Established and published Security Metrics Library with approved KRIs/KPIs • Implemented reporting for priority security domains with automated feeds • Built executive dashboards with consistent definitions and thresholds • Operationalized review cadence: • monthly operational reporting • quarterly threshold/definition reviews • Reduced manual reporting and improved trust in security metrics MUST-HAVE Hard Skills: 1.) 8+ years experience in cybersecurity metrics, cyber risk reporting, cyber operations, GRC, or business intelligence supporting InfoSec/IT. 2.) Strong understanding of security domains such as: -SOC / incident response -vulnerability management -IAM / PAM -cloud security -AppSec / SDLC security -third party risk 3.) Excel (advanced), PowerPoint (executive storytelling) 4.) At least one BI tool (Power BI/Tableau/Qlik) SOFT SKILLS: 1.) Strong communication skills (written and verbal) 2.) Comfortable presenting and speaking to executives NICE-TO-HAVE 1.) Experience with frameworks such as NIST CSF, NIST 800-53, ISO 27001, CIS Controls 2.) Experience with metric automation sources/tools: -Splunk, Sentinel, CrowdStrike, Qualys/Tenable -ServiceNow (IRM/GRC/SecOps) -Archer 3.) Certifications (nice to have): -CISSP / CISM / CRISC -Security+ (if earlier-career senior) -ITIL Foundation 4.) Experience building KPI/KRI governance or measurement programs 5.) Prior banking or financial institution experience DISQUALIFIERS is there any information/experience on a candidate's resume that would disqualify them from consideration for this position? 1.) Job hopping, short term contracts, unexplained gaps TIMELINES/IMPORTANT DATES: • Upcoming PTO: Fred 16-20 th • Supplier Call: Feb 11 th at 3pm (45 minutes) • Distribute Requisition: Feb 11 th • Halting: Feb 13 th • Shortlist De-Brief: 24 hours • Target interview: Feb 18 th and onward • Interview process: 1-2 steps, virtual, 30 minutes • Interview de-brief: as completed Benefits: • Medical, Vision, and Dental Insurance Plans • 401k Retirement Fund Remote About the Company: GTT, LLC Apply tot his job Apply To this Job

Similar Jobs

Experienced Remote Live Chat Assistant – Entry-Level Customer Support and Engagement Specialist for arenaflex

Remote, USA Full-time

**Experienced Work-from-Home Data Entry Clerk – Part-Time Opportunity at arenaflex**

Remote, USA Full-time

Amazon Delivery Driver

Remote, USA Full-time

Basic Data Entry Agent Work From Home – No Expe...

Remote, USA Full-time

**Experienced Pharmacy Customer Service Representative – Weekend Remote Opportunity at arenaflex**

Remote, USA Full-time

Experienced Remote Data Entry Clerk and Survey Assistant – Part-time Focus Group Panelist Opportunity with Flexible Scheduling and Competitive Compensation

Remote, USA Full-time

**Experienced Remote Customer Support Specialist – Booking Travel Reservations**

Remote, USA Full-time

Experienced Remote Data Entry Clerk – Work from Home Opportunity with Flexible Scheduling and Professional Growth at arenaflex

Remote, USA Full-time

Experienced Customer Service Representative – Remote Part-time Opportunities for Delivering Exceptional Support and Ensuring Customer Satisfaction at arenaflex

Remote, USA Full-time

**Experienced Part-time Chat Specialist – Customer Service Representative – arenaflex**

Remote, USA Full-time

Online Remote Google Job

Remote, USA Full-time

**Experienced Full Stack Data Engineer – Customer Experience Optimization at arenaflex in Seattle, WA**

Remote, USA Full-time

Strategic IVR & Chat Platform Manager – Customer Experience Innovation Lead at arenaflex (Englewood, CO)

Remote, USA Full-time

**Senior iOS Software Engineer – Real-Time Chat Experience for arenaflex Community in San Francisco, CA**

Remote, USA Full-time

**Experienced Data Entry Clerk – Temporary Summer Position in Danville, IL at arenaflex**

Remote, USA Full-time

Payer Contracting Analyst

Remote, USA Full-time

Recruiter, Part-Time

Remote, USA Full-time

**Experienced Data Entry Clerk – Human Resources Operations Support**

Remote, USA Full-time

Paralegal & Case Manager — Remote-Option, PI Focus

Remote, USA Full-time

**Experienced AI Chat Program Manager – Delivering Exceptional Customer Experiences through Conversational AI Solutions**

Remote, USA Full-time