Genesee Regional Bank logo

Security Administrator

Genesee Regional Bank

Rochester, NYJob$94–106K/yrSeen 2w agoSeen in employer's feed 1w ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
$94–106K/yr
Location
Rochester, NY
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Requirements

Credentials this posting asks for.

Associate's degree

Job overview

The Security Administrator is responsible for day‑to‑day execution of operational and technical activities supporting the bank’s information security program, including managing security tools, monitoring alerts, handling incidents, coordinating vulnerability management, and supporting risk assessments and reporting.

Skills & qualifications

RequiredNice to have

Skills

Microsoft DefenderEntra IDMicrosoft 365 Security ControlsMicrosoft PurviewEmail SecurityEndpoint ProtectionIdentity SecurityData SecurityData Loss PreventionVulnerability ManagementPhishing SimulationPrivileged Access ManagementNIST Cybersecurity FrameworkFFIEC GuidanceGLBA RequirementsSecurity Alert TriageIncident ResponseAccess ReviewSecurity Awareness AdministrationTechnical Control Configuration

Qualifications

Associate’s Degree in Cybersecurity or Information Technology or Related FieldMinimum of 5 Years Previous Experience in Information Security Administration or Security Operations or System Administration With a Focus in SecurityWorking Knowledge of the NIST Cybersecurity FrameworkFamiliarity With FFIEC Guidance, GLBA Requirements, and Banking Regulatory ExpectationsExperience Within a Regulated Financial Institution or Similarly Regulated Environment

Full job description

Pay or shift range: $93,500 USD to $105,500 USD

The estimated range is the budgeted amount for this position. Final offers are based on various factors, including skill set, experience, location, qualifications and other job-related reasons.

Description

SALRY RANGE: $93,500 – $105,500

PRIMARY RESPONSIBILITY:

The Security Administrator (SA) is responsible for the day-to-day execution of operational and technical activities supporting the Bank’s Information Security Program. Reporting administratively to the Chief Technology Officer and operating under the functional security direction of the Bank’s CISO or designated CISO advisor, the SA administers, monitors, and optimizes the Bank’s core security technologies and recurring security processes. Responsibilities include security alert triage, incident response support, vulnerability management coordination, access reviews, security awareness administration, technical control configuration, evidence maintenance, reporting, and remediation tracking. The SA executes established security priorities and promptly escalates material risks, incidents, policy exceptions, and control deficiencies to the CISO and appropriate management.

ESSENTIAL FUNCTIONS:

  • Manage and administer core security tools and systems, including email security, endpoint protection, identity security, and data security and compliance platforms, including data classification, information protection, and data loss prevention capabilities.

  • Monitor systems and tools to detect anomalous or malicious activity across endpoints and networks.

  • Own and resolve security related user support tickets, including reports of malware, email compromise, and other security incidents. Perform initial triage, review available logs, correlate activity, preserve relevant evidence, determine preliminary scope and severity, and promptly escalate matters in accordance with the Incident Response Plan.

  • Monitor, investigate, document, and disposition security alerts across the Bank’s security platforms. Identify monitoring gaps, recurring root causes, tuning opportunities, and conditions requiring escalation.

  • Support containment, eradication, and recovery activities in coordination with the CISO, CTO, managed security providers, and other members of the Incident Response Team. Perform preliminary technical analysis and evidence collection and coordinate advanced forensic analysis with internal or external resources when required.

  • Review and coordinate tickets and alerts generated by the Bank’s MDR, SOC, and other managed security providers, ensuring appropriate internal follow-up, escalation, and closure.

  • Monitor and administer controls intended to detect or prevent unauthorized data access, data exfiltration and inappropriate transmission of sensitive information.

  • Administer the access review process to ensure user access is appropriately provisioned.

  • Administer operational components of the vulnerability management program, including scan monitoring, result validation, asset and owner coordination, remediation tracking, exception documentation, and reporting. Technical system owners remain responsible for implementing assigned remediation actions.

  • Oversee phishing simulation campaigns, track results, and provide remedial training as needed. Educate and train end users via vendor-based tools, grass roots education campaigns, and bank provided self-service training.

  • Support the administration and streamlining of the bank’s Privileged Access Management system, defining and maintaining roles, and developing and maintaining appropriate documentation.

  • Support the CISO-led Information Security Risk Assessment process.

  • Administer technical controls supporting the Bank’s approved records-retention requirements within assigned technology platforms.

  • Support policy and procedure maintenance by documenting operational practices, technical control configurations, and implementation evidence to promote consistency and audit readiness.

  • Maintain thorough documentation, diagrams, inventories, evidence, procedures related to assigned security responsibilities.

  • Support implementation and ongoing operation of activities aligned with the Bank’s Information Security Program and CISO-established priorities.

  • Work with the CTO and the IT team to implement and execute the CISO’s information security roadmap to ensure an efficient and effective security posture.

  • Prepare and present Information Security related reports to management.

  • Active participation in demonstrating the behaviors outlined in the GRB Experience.

EDUCATION AND EXPERIENCE:

  • Associate’s Degree in Cybersecurity, Information Technology or related field and a minimum of 5 years previous experience in Information Security Administration, Security Operations, or System Administration with a focus in Security, or the equivalent combination of education and experience.

  • Demonstrated experience administering Microsoft security and compliance technologies, including Microsoft Defender, Entra ID, Microsoft 365 security controls, and Microsoft Purview, or comparable enterprise platforms.

  • Working knowledge of the NIST Cybersecurity Framework and other relevant information security frameworks. Familiarity with FFIEC guidance, GLBA requirements, and banking regulatory expectations is preferred.

  • Experience within a regulated financial institution or similarly regulated environment is preferred.

  • Strong communication skills to explain technical security risks to end users and compliance requirements to business stakeholders.

  • Ability to multi-task and manage multiple priorities.

  • Self-starter and motivated to make improvements, learn, and evolve.

COMPETENCIES:

  • Provide a remarkable client experience. Greet clients with warmth, genuine interest and a smile.

  • Lead by example. Identify current or potential problems, take ownership and see them through to resolution.

  • Act as a unified team. Possess strong interpersonal skills including the ability to proactively communicate with and help others, within and across departments.

  • Ability to work independently. Seek and incorporate feedback on your performance from management, coworkers and clients.

  • Demonstrated proficiency with enterprise computing, security administration, and common productivity and collaboration technologies.

  • Strong verbal, written, analytical, problem-solving, and customer service skills, with the ability to communicate effectively with both technical and non-technical audiences.

  • Ability to handle highly confidential information with sensitivity, tact and discretion.

  • Ability to learn new technology and practices quickly.

PHYSICAL DEMANDS:

While performing the duties of this job, the employee is regularly required to use hands or fingers, handle, or feel and reach with hands and arms. The employee frequently is required to stand, sit, climb or balance, and talk or hear. The employee regularly is required to walk and stoop, kneel, and climb stairs. The employee must occasionally lift and/or move up to 25 pounds. Specific vision abilities required by this job include close vision, distance vision, and ability to adjust focus.

WORK ENVIRONMENT:

The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. The work environment is indoor and climate controlled.

Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.

Genesee Regional Bank is an equal opportunity organization. We recruit, employ, train, compensate, and promote without regard to race, religion, color, national origin, age, sex, disability, veteran status, or any other basis protected by applicable federal, state, or local law.

THIS JOB DESCRIPTION IS SUBJECT TO CHANGE AT ANY TIME.

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities

This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights (https://www.eeoc.gov/poster) notice from the Department of Labor.

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.