At BNY, our culture allows us to run our company better and enables you to grow and succeed. As a leading global financial services company at the heart of the global financial system, we influence nearly 20% of the world’s investible assets. Every day, our teams harness cutting-edge AI and breakthrough technologies to collaborate with clients, driving transformative solutions that redefine industries and uplift communities worldwide.
Recognized as a top destination for innovators and champions of inclusion, BNY is where bold ideas meet advanced technology and exceptional talent. Together, we power the future of finance – and this is what #LifeAtBNY is all about. Join us and be part of something extraordinary.
Job Summary
BNY is seeking an Information Security Analyst to support cyber risk analysis, reporting, and control oversight activities. This role is responsible for reviewing and analyzing complex data and information to provide insights, conclusions, and actionable recommendations, while also providing direction and guidance on reports and analyses to ensure recommendations align with customer and business needs and capabilities.
This role offers the opportunity to contribute directly to BNY’s information security posture by supporting risk visibility, control effectiveness, cyber hygiene, and data-driven decision-making across the organization.
This role is based in Pittsburgh, PA and is a 12-month assignment.
Key Responsibilities
- Data Analysis & Actionable Recommendations: Review and analyze complex data and information to provide insights, conclusions, and actionable recommendations aligned with business and customer needs.
- Reporting Guidance & Business Alignment: Provide direction and guidance on reports and analyses, ensuring outputs and recommendations are aligned with business capabilities and objectives.
- Risk Mitigation & Standards Oversight: Recommend courses of action to mitigate risk and ensure that appropriate standards are established and met in coordination with ISD ECM.
- Higher-Risk Change Escalation: Escalate higher-risk change activity for risk treatment when appropriate.
- Operational Roadblock Identification: Identify operational roadblocks to ensure timely remediation and implementation of countermeasures.
- Cross-Functional Collaboration: Work closely with Information Security and various other organizations in a collaborative and goal-oriented manner.
- Information Security Infrastructure Support: Consult with other IT areas and lines of business and provide professional support for major components of the company’s information security infrastructure.
- Area Objective Contribution: Contribute to the achievement of area objectives through strong analysis, reporting, and partnership across teams.
- Cyber Hygiene & Control Effectiveness: Support continuous cyber hygiene, control completeness, and control effectiveness efforts across the environment.
- Risk Findings Aggregation: Collate automated and self-identified risk findings to support reporting, analysis, prioritization, and follow-up actions.
Qualifications
- Experience in GRC, information security, or related technology environments required
- Strong knowledge of cyber security frameworks such as NIST CSF, CRI, and ISO
- Strong experience with business intelligence, data analysis, and reporting platforms such as SQL, DB2, Power BI, Business Objects, Qlik, Tableau, Excel, and PowerPoint
- Knowledge and conceptual understanding of the System Development Life Cycle (SDLC)
- Logical and physical database design skills
- Strong analytical and troubleshooting skills
- Self-motivated individual and strong team player
- Clear, concise, and effective written and verbal communication skills
- Strong time management, independent thinking, and decision-making capabilities
- Bachelor’s degree in computer science or a related discipline, or equivalent work experience required; advanced degree preferred
Preferred Experience
- Experience working in a financial services or securities environment
- Strong background in business intelligence and security reporting
- Experience supporting risk analysis, remediation tracking, and operational control improvement initiatives
Why Join Us
This role offers the opportunity to play a meaningful part in strengthening BNY’s information security and risk management environment. You’ll work across Information Security, IT, and business teams to analyze complex security and risk data, support remediation efforts, and improve control effectiveness across the organization. This is a strong opportunity for someone who enjoys combining cyber framework knowledge, reporting and analysis skills, and cross-functional collaboration to drive meaningful outcomes.
At BNY, our culture speaks for itself, check out the latest BNY news at:
BNY Newsroom
BNY LinkedIn
Here’s a few of our recent awards:
America’s Most Innovative Companies, Fortune, 2025
World’s Most Admired Companies, Fortune 2025
“Most Just Companies”, Just Capital and CNBC, 2025