Regions is looking to advance its cyber security program and capabilities through developing, communicating, and implementing a security architecture to safeguard and protect private and personally identifiable information.
Requirements
- Seven (7) years of experience in cyber security, with a focus on software development, secure software development lifecycle (SDLC), or security architecture
- Experience in the design and implementation of cyber security solutions
- Advanced knowledge of risks associated with virtualization and cloud-based computing and the impact of those technologies on an organizations security posture
- Advanced knowledge of security principles, solutions, tools, methodologies, and techniques
- Proficiency in Microsoft Office (Excel, Word, PowerPoint, Outlook, etc.)
- Architecting secure cloud workloads in AWS and/or Azure: prior demonstrable work designing and securing production systems
- Architecting secure LLM integrations across clouds and model providers
Responsibilities
- Develops and establishes a strategic cyber security architecture and strategic vision, including standards and frameworks that are aligned with the overall business and Regions’ information technology strategy
- Provides advisory and consultative services to businesses, information technology groups, and cyber security senior leadership
- Works closely with Enterprise Architecture and Application Development groups to enhance the security posture of new and existing systems
- Designs cyber security architecture, evaluates and mitigates potential risk, and approves implementation of systems and applications into production
- Performs assessments using the National Institute of Standards and Technology (NIST) Cyber Security Framework and the Federal Financial Institutions Examination Council (FFIEC) Cyber Assessment Tool to identify gaps and remediate deficiencies
- Ensures systems and applications are implemented with compensating controls to meet regulatory requirements (e.g. GLBA, SOX, HIPPA, FFIEC, etc.) as well as other organizational compliance (PCI) requirements
- Tracks metrics for compliance to internal cyber security standards set by application and system owners
Other
- Bachelor’s degree in Computer Science, or related field
- Ability to effectively evaluate risk vs. reward
- Ability to independently problem solve with sound judgement
- Ability to translate complex technical information across all levels of the organization through communications and/or presentations
- Strong verbal, written communication, and organizational skills