At U.S. Bank, we’re on a journey to do our best. Helping the customers and businesses we serve to make better and smarter financial decisions and enabling the communities we support to grow and succeed. We believe it takes all of us to bring our shared ambition to life, and each person is unique in their potential. A career with U.S. Bank gives you a wide, ever-growing range of opportunities to discover what makes you thrive at every stage of your career. Try new things, learn new skills and discover what you excel at—all from Day One.
Job DescriptionThe Secure Cloud Governance team is seeking a senior cloud risk and compliance specialist, to support cloud security automation targets and provide cloud security oversight expertise as part of the U.S. Bank Shield Platform. Candidates will support activities related to the support of application governance automation tools, application migration governance, and the identification, tracking, and mitigation of program-related risks, keeping in mind the security & compliance obligations of the Enterprise. The ideal candidate with have a deep understanding of cloud computing, information security, technology risk management, and security's role in the software development lifecycle, as well as applied experience implementing said principles as part of a large-scale enterprise transformation effort.
The role offers a hybrid/flexible schedule, which means there’s an in-office expectation of 3 or more days per week and the flexibility to work outside the office location for the other days at one of the following locations:
Minneapolis, MNCincinnati, OHResponsibilities:
Assist in the development and maintenance of cloud-focused security solutions and guidance that are integrated with the Enterprise Cloud programReview new platform features and cloud technologies to identify any potential security, information security, or risk issuesCollaborate with internal and external stakeholders to incorporate appropriate cloud, information security, and risk principles into new oversight processesAnalyze security and compliance requirements for cloud-based applications and servicesProvide support in the evaluation of security risks, vulnerabilities, and threats, and assist in the development of mitigation strategiesCommunicate security risks and recommendations to stakeholders in a clear and concise mannerSupporting the development and maintenance of repeatable, documented processes and controls that align to authoritative source requirementsIdentifying and documenting risks and risk treatment plans, facilitating remediation plan development and ongoing monitoring of remediation plans in partnership with technical and business partnersAnalyzing, aggregating, and reporting on thematic security findings and risks, socializing these findings in governance committees to determine actionsIdentifying risks across the organization and driving remediation planning effortsAssisting in the review and validation of security controls, including understanding the efficacy of the control and the level of risk mitigationAssisting in the development and enhancements to risk metrics and reporting high impact items through governance committees or through other escalation processesProviding recommendations to leadership on program effectiveness and enhancements
Basic Qualifications:
Bachelor's degree in engineering or science, or equivalent work experience5+ years' experience with cloud security and/or information security execution rolesEffective communication and collaboration skillsability to articulate complex technical issues in a clear and concise manner.Preferred Skills/Experience:
2+ years' experience with risk management and/or audit in the technology spaceStrong internal initiative, desire to collaborateWorking knowledge/understanding of cloud security principlesExperience using GRC tools such as RSA Archer or ServiceNowWorking knowledge of information security principles, standards, and best practicesExperience in Information Security architecture, technologies, and management
Experience Should Include:
Strong decision-making and problem-solving skillsDetailed knowledge of cloud security concepts and architectureConfidence in communicating technical information to both technical and non-technical audiences and stakeholders at every level of the organizationStrong writing skills with experience in documenting gap analyses and team documentationThe ability to build and maintain relationships across diverse technical and non-technical teamsA diverse technical background including experience with regulatory requirements, technologies and controls that mitigate information security risksExperience using reporting with advanced BI tools such as Tableau and/or Power BIKnowledge of IT industry trends and direction and environment
Top Skills:
Cloud Security Expertise (Azure preferred)Information Security Risk ManagementAuditing, Governance, and/or Information Security Architecture experience a plus
Required Certifications:
Microsoft AZ-900 Certification or similar
Preferred Certifications:
Certified Cloud Security Practitioner (CCSP)Microsoft AZ-500, AZ-303/304 or similar certificationCertified Information System Security Professional (CISSP)Certified Information Security Manager (CISM)Certified in the Governance of Enterprise IT (CGEIT)If there’s anything we can do to accommodate a disability during any portion of the application or hiring process, please refer to our disability accommodations for applicants.
Benefits:
Our approach to benefits and total rewards considers our team members’ whole selves and what may be needed to thrive in and outside work. That's why our benefits are designed to help you and your family boost your health, protect your financial security and give you peace of mind. Our benefits include the following (some may vary based on role, location or hours):
Healthcare (medical, dental, vision)
Basic term and optional term life insurance
Short-term and long-term disability
Pregnancy disability and parental leave
401(k) and employer-funded retirement plan
Paid vacation (from two to five weeks depending on salary grade and tenure)
Up to 11 paid holiday opportunities
Adoption assistance
Sick and Safe Leave accruals of one hour for every 30 worked, up to 80 hours per calendar year unless otherwise provided by law
EEO is the Law
U.S. Bank is an equal opportunity employer committed to creating a diverse workforce. We consider all qualified applicants without regard to race, religion, color, sex, national origin, age, sexual orientation, gender identity, disability or veteran status, among other factors. Applicants can learn more about the company’s status as an equal opportunity employer by viewing the federal KNOW YOUR RIGHTS EEO poster.
E-Verify
U.S. Bank participates in the U.S. Department of Homeland Security E-Verify program in all facilities located in the United States and certain U.S. territories. The E-Verify program is an Internet-based employment eligibility verification system operated by the U.S. Citizenship and Immigration Services. Learn more about the E-Verify program.
The salary range reflects figures based on the primary location, which is listed first. The actual range for the role may differ based on the location of the role. In addition to salary, U.S. Bank offers a comprehensive benefits package, including incentive and recognition programs, equity stock purchase 401(k) contribution and pension (all benefits are subject to eligibility requirements). Pay Range: $119,765.00 - $140,900.00 - $154,990.00U.S. Bank will consider qualified applicants with arrest or conviction records for employment. U.S. Bank conducts background checks consistent with applicable local laws, including the Los Angeles County Fair Chance Ordinance and the California Fair Chance Act as well as the San Francisco Fair Chance Ordinance. U.S. Bank is subject to, and conducts background checks consistent with the requirements of Section 19 of the Federal Deposit Insurance Act (FDIA). In addition, certain positions may also be subject to the requirements of FINRA, NMLS registration, Reg Z, Reg G, OFAC, the NFA, the FCPA, the Bank Secrecy Act, the SAFE Act, and/or federal guidelines applicable to an agreement, such as those related to ethics, safety, or operational procedures.
Applicants must be able to comply with U.S. Bank policies and procedures including the Code of Ethics and Business Conduct and related workplace conduct and safety policies.