Information Security
U.S. BankAbout the role
At U.S. Bank, we’re on a journey to do our best. Helping the customers and businesses we serve to make better and smarter financial decisions and enabling the communities we support to grow and succeed. We believe it takes all of us to bring our shared ambition to life, and each person is unique in their potential. A career with U.S. Bank gives you a wide, ever-growing range of opportunities to discover what makes you thrive at every stage of your career. Try new things, learn new skills and discover what you excel at—all from Day One.
Job Description
The U.S. Bank Secure Cloud Governance team is seeking a Governance analyst/consultant to provide risk & compliance expertise in support of our Enterprise Security Posture Management platform. Day to day, the role will be primarily responsible for driving the increased security posture of our third-party cloud environment in key security domains, including but not limited to: IAM, Data Security, Network Security, Endpoint Security, Application Security, Logging & Monitoring and Security Operations. The ideal candidate with have a deep understanding of security risk principles, working knowledge of relevant security and industry frameworks, and ideally technical knowledge of metrics and data to support security objectives.
The role offers a hybrid/flexible schedule, which means there’s an in-office expectation of 3 or more days per week and the flexibility to work outside the office location for the other days at one of the following locations:
Cincinnati, OH
Minneapolis, MN
Responsibilities:
- Learn risk assessment principles, enterprise compliance requirements, and industry guidance to identify key security objectives
- Leverage existing issue, finding, and risk assessment documentation to help build a backlog of security risk reduction opportunities/problems to be solved
- Identify key target-state objectives for security risk reduction in the Enterprise
- Review available configuration data to identify where raw data can be consumed from, to support compliance metrics
- Identify key measurements that can be used to assess achievement of risk reduction
- Support and provide feedback on the generation of dashboarding and visuals to help communicate security posture to organizational peers
- Communicate security risks and requirements to stakeholders in a clear and concise manner
- Assist in the development and enhancements to risk metrics and reporting high impact items through governance committees or through other escalation processes
- Provide recommendations to leadership on program effectiveness and enhancements.
Basic Qualifications:
- Typically a Bachelor's degree, or equivalent work experience
- Typically three to five years of relevant experience
- Effective communication and collaboration skills
- Ability to articulate complex technical issues in a clear and concise manner
Experience Should Include:
- Detailed knowledge of information security concepts and architecture
- Strong attention to detail
- Broad understanding of security tooling and architectures
- Effective interpersonal, verbal, and written communication skills
- Strong writing skills with experience in documenting gap analyses and team documentation
- Experienced practitioner of Agile Ways of Working
- Confidence in communicating technical information to both technical and non-technical audiences and stakeholders at every level of the organization
- The ability to build and maintain relationships across diverse technical and non-technical teams.
Preferred Skills/Experience:
- A diverse technical background including experience with regulatory requirements, technologies and controls that mitigate information security risks
- Experience in IT governance, standards, procedures, and policy
- Experience using reporting with advanced BI tools such as Tableau and/or Power BI
- Certified Cloud Security Practitioner (CCSP)
- Microsoft AZ-500, AZ-303/304 or similar certification
- Certified Information System Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Certified in the Governance of Enterprise IT (CGEIT)
If there’s anything we can do to accommodate a disability during any portion of the application or hiring process, please refer to our disability accommodations for applicants.
Benefits:
Our approach to benefits and total rewards
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s