> Markdown version of [/jobs/ext/1250904-information-security-analyst](https://www.wearedevelopers.com/jobs/ext/1250904-information-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Analyst - **Company:** Hanover Community Bank - **Location:** Mineola, NY, United States - **Experience:** Starter - **Salary:** $79,040.0 - $87,360.0 - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, CompTIA Security+, Cyber Security, Information Systems, Disaster Recovery, Multi-Factor Authentication, Identity and Access Management, Information Security Management, Information Technology Audit, Intrusion Detection and Prevention, Intrusion Detection Systems, Network Security, Network Administration, Software Maintenance, Phishing, Security Information and Event Management, Data Classification, In-Plane Switching (IPS), Software Security, Advanced Reports, Firewalls (Computer Science), Information Technology - **Published:** July 12, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=68f91758803d1396 ## About the Role * Bachelor's Degree: Required in Computer Science, Cybersecurity, Information Technology, or a related technical field. Equivalent professional experience may be considered. Certifications * Foundational (Required): Must possess or be actively working toward a foundational security certification such as CompTIA Security+, ISC2 Certified in Cybersecurity (CC), or SSCP. * Advanced (Preferred): Possession of, or eligibility for, advanced certifications such as CISSP (Associate status acceptable), CRISC, or CISA is highly desirable. Experience * Minimum Experience: 1-3 years of experience in information security, IT auditing, or network administration, preferably within the financial services sector * Technical Proficiency: Demonstrated experience with security technologies (firewalls, IDS/IPS, SIEM, EDR) and a solid understanding of GRC (Governance, Risk, and Compliance) frameworks Skills and Abilities: * Communication Skills: Strong interpersonal skills with the ability to effectively communicate complex technical concepts to non-technical stakeholders (e.g., Board members, employees). * Analytical Abilities: Excellent problem-solving, analytical skills, and detail-oriented approach to all tasks. * Technical Proficiency: Strong technical knowledge across core security domains: * Infrastructure: Network security, cloud security, and endpoint protection. * Operations: Security Information and Event Management (SIEM) and Security Operations Center (SOC) systems. * Development: Application security principles. * Adaptability: Ability to adapt to evolving information technology and threat landscapes. * GRC Capabilities: Proven ability to perform vendor and system cybersecurity risk assessments. * Program Management: * Experience running information security awareness and training programs. * Experience planning and coordinating business continuity and disaster recovery tests. * Time Management: Ability to prioritize and execute tasks efficiently within required time frames. ## Description * Program Maintenance: Assist the ISO/ISM in developing and maintaining an Information Security Program aligned with GLBA, FDICIA, SOX, FFIEC, FACTA, and the NYDFS 23 NYCRR 500. * Regulatory Monitoring: Stay current on global and regional financial regulations and technology trends to ensure proactive compliance and program evolution. * Audit Management: Serve as a point of contact for internal and external audits, ensuring timely and accurate responses to all requests. * Enterprise Assessments: Develop and maintain security risk assessments that evaluate inherent risks, control effectiveness, and residual risk levels. * Asset Management: Implement and maintain a comprehensive, documented information system asset inventory as required by 2025 NYDFS updates. * Vendor and Project Risk: Evaluate security controls during vendor selection (Third-Party Risk Management) and consult on new product development to ensure "security by design". * Data Classification: Partner with various business units to classify data according to sensitivity and ensure appropriate handling protocols. * Threat Detection: Maintain and tune security tools to monitor for vulnerabilities and potential breaches, providing real-time alerting for the Bank's network. * Access Control: Administer identity and access management (IAM) protocols, including the enforcement of Multi-Factor Authentication (MFA) and regular reviews of privileged access. * Remediation: Collaborate with Information Technology teams to remediate identified security issues and review technical changes for adherence to best practices. * Incident Management: Coordinate incident response planning, including the development of alerting and escalation procedures and managing the response to active security events. * Business Resilience: Manage and oversee the Bank's Business Continuity Plan (BCP) and Disaster Recovery (DR) program, including leading annual Business Impact Analyses (BIA) and recovery testing. * Security Education: Handle the execution of the security awareness program by creating educational content, conducting phishing simulations, and delivering presentations on employee obligations. * Strategic Reporting: Produce security KPI metrics and trend analysis reports for management to demonstrate the current state of the Bank's security posture. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Responsible AI @ Microsoft - Governance, Standards, Learnings](https://www.wearedevelopers.com/videos/1544-responsible-ai-microsoft-governance-standards-learnings) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Empowering and Motivating Developers in a Purpose-Driven Team of the Future](https://www.wearedevelopers.com/videos/1177-empowering-and-motivating-developers-in-a-purpose-driven-team-of-the-future) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Data Analyst Salary in Switzerland](https://www.wearedevelopers.com/magazine/276-data-analyst-salary-in-switzerland) - [IT Salaries in Germany](https://www.wearedevelopers.com/magazine/287-it-salaries-in-germany) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)