Senior Security Analyst
SynchronyAbout the role
Job Description:
Role Summary/Purpose:
The Senior Security Risk Analyst will execute the work of the Synchrony (SYF) Application Security - Technology, Risk and Analytics Team. This individual will leverage knowledge of security policies, standards, and industry best practices as the key point of contact for documenting deviations from security standards. The Senior Security Risk Analyst will contribute towards process improvements including assessment of vulnerability risk, enhancement of metrics, development of documentation, and identifying opportunities for streamlining and automation. This position will also be responsible for executing the strategic direction set by the VP of Application Security - Technology, Risk and Analytics.
Our Way of Working
We’re proud to offer you choice and flexibility. At Synchrony, our way of working allows you to have the option to work from home, near one of our Hubs or come into one of our offices. Occasionally you may be required to commute to our nearest office for in person engagement activities such as business or team meetings, training and culture events.
Essential Responsibilities:
The Application Security - Technology, Risk and Analytics Team coordinates across all elements of the IT organization at all levels, including senior executives. This role requires experience in information security, risk management, and vulnerability management. Responsibilities include:
Evaluate and process exceptions to information security policies and standards related to vulnerability management
Perform analysis to evaluate risk associated with exceptions to standards
Assist in presenting exception risk metrics and vulnerabilities identified through the security exception process to technology leadership
Provide effective prioritization and tracking of exception request queue
Maintain cooperative relationship with infrastructure, application, database, network, and desktop/laptop teams to drive remediation
Analyze vulnerability data and assist with the prioritization and remediation of the identified vulnerabilities commensurate to risk and the vulnerability management standard
Understand vulnerabilities, their impacts, mitigation techniques, and document and articulate this understanding to various stakeholders
Update and develop security standards and templates as required to meet new regulatory/audit/etc. requirements
Leverage and enhance existing Application Security frameworks/policies/standards to ensure Synchrony Application Security maintains a minimum of industry best practices commiserate with organization’s risk profile while also ensuring compliance with industry standards (e.g., PCI DSS)
Coordinate collection of data and documentation in support of examinations/audits
Work with existing solution vendors (e.g., Qualys, Fortify, and Sonatype) as necessary; identify potential solutions
Perform other duties and/or special projects as assigned.
Qualifications/Requirements:
Bachelor’s degree and a minimum
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s