At BNY, our culture allows us to run our company better and enables you to grow and succeed. As a leading global financial services company at the heart of the global financial system, we influence nearly 20% of the world’s investible assets. Every day, our teams harness cutting-edge AI and breakthrough technologies to collaborate with clients, driving transformative solutions that redefine industries and uplift communities worldwide.
Recognized as a top destination for innovators and champions of inclusion, BNY is where bold ideas meet advanced technology and exceptional talent. Together, we power the future of finance – and this is what #LifeAtBNY is all about. Join us and be part of something extraordinary.
Job Summary
BNY is seeking a Cyber Risk Analyst to support BNY’s Cyber Risk Management function by evaluating cybersecurity risk, strengthening governance processes, and improving the effectiveness of enterprise cybersecurity controls. This role is responsible for reviewing and analyzing complex cybersecurity data and control information to provide insights, conclusions, and actionable recommendations, while partnering across teams to identify control weaknesses, assess risk exposure, and drive remediation activities.
This role serves as a key contributor to Cyber Control Issue Management, Policy Risk Decisioning (Policy Deviations), Cyber Framework Assessments, and Cyber Hygiene initiatives. The ideal candidate will bring strong analytical and problem-solving skills, a solid understanding of cybersecurity principles and frameworks, and the ability to translate technical findings into actionable risk recommendations for both technical and executive audiences.
This role is based in Pittsburgh, PA, expecting 4-days onsite per week.
Key Responsibilities
- Cyber Control Issue Management: Support the lifecycle management of cybersecurity control issues from identification through remediation and closure, including evaluating business impact, root cause, residual risk, remediation strategy, and compensating controls.
- Risk Analysis & Actionable Recommendations: Review cybersecurity data, control deficiencies, and risk findings to identify trends, recurring issues, systemic weaknesses, and opportunities for control improvement, while providing actionable recommendations aligned to enterprise risk priorities.
- Cyber Risk Decisioning (Policy Deviations): Evaluate requests for cybersecurity policy deviations to determine risk exposure, assess compensating controls and mitigation strategies, and document recommendations supporting risk acceptance, remediation, or rejection.
- Cyber Framework Assessments: Support periodic assessments of cybersecurity controls against industry-recognized frameworks such as CRI Cyber Profile, NIST CSF, and NIST SP 800-53, including control mapping, maturity evaluation, gap identification, and remediation planning.
- Cyber Hygiene & Compliance Monitoring: Monitor compliance of internally managed cybersecurity platforms against enterprise policies and standards, identify improvement opportunities, and support initiatives to improve cyber hygiene and reduce risk.
- Executive Reporting & Metrics: Develop dashboards, metrics, and executive-level reporting on issue health, remediation status, control effectiveness, risk trends, and compliance performance to support leadership, audit, regulatory, and board reporting needs.
- Cross-Functional Collaboration: Partner closely with Cyber Engineering, Architecture, Technology Risk, Compliance, Internal Audit, Business Risk teams, and application owners to assess control weaknesses, facilitate remediation, and improve governance processes.
- Governance & Continuous Improvement: Assist in developing governance standards, procedures, and best practices while supporting continuous improvement efforts across Cyber Risk Management processes.
Qualifications
- 5–7+ years of experience in cybersecurity, information security, technology risk, governance, or cyber risk management required
- Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, Information Technology, or a related discipline, or equivalent combination of education and experience required
- Strong understanding of cybersecurity governance, risk management, and control frameworks
- Experience assessing cybersecurity risks and evaluating control effectiveness
- Strong knowledge of cyber security frameworks such as NIST CSF, CRI Cyber Profile, and NIST SP 800-53
- Excellent analytical, critical thinking, and problem-solving abilities
- Strong written and verbal communication skills with the ability to present technical concepts to both technical and non-technical audiences
- Ability to manage multiple initiatives and priorities in a fast-paced, highly regulated environment
- Strong attention to detail, sound judgment, and risk-based decision-making capabilities
- Comfortable working with large datasets and identifying trends
Preferred Experience
- Experience working within the financial services industry or another highly regulated environment
- Experience using ServiceNow for issue management, governance, workflow, or risk management
- Experience developing dashboards and reporting using Power BI
- Familiarity with GRC platforms
- Experience supporting Internal Audit, Regulatory Examinations, or external assessments
- Working knowledge of MITRE ATT&CK, cybersecurity maturity models, and control testing methodologies
- Professional certifications such as CISSP, CISM, CRISC, CGRC, Security+, or FAIR are desirable
- Continuous learning mindset with interest in evolving cybersecurity threats, regulations, and industry best practices
Why Join Us
This role offers the opportunity to play a meaningful part in strengthening BNY’s cybersecurity risk management and control environment. You’ll work across Cyber Risk, Engineering, Compliance, Audit, and Business teams to assess control effectiveness, support risk-based decisioning, drive remediation efforts, and improve cyber hygiene across the organization. This is an excellent opportunity for someone who enjoys combining cybersecurity framework knowledge, governance and risk analysis, reporting, and cross-functional collaboration to drive meaningful security outcomes.
At BNY, our culture speaks for itself, check out the latest BNY news at:
BNY Newsroom
BNY LinkedIn
Here’s a few of our recent awards:
America’s Most Innovative Companies, Fortune, 2025
World’s Most Admired Companies, Fortune 2025
“Most Just Companies”, Just Capital and CNBC, 2025