Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Offensive Risk Strategist image - Rise Careers
Job details

Offensive Risk Strategist

Introduction

Since 1973, East West Bank has served as a pathway to success. With over 110 locations across the U.S. and Asia, we are the premier financial bridge between the East and West. Our teams of experienced, multi-cultural professionals help guide businesses and community members on both sides of the Pacific looking to explore new markets and create new opportunities, and our sustained growth and expertise in industries like real estate, entertainment and media, private equity and venture capital, and high-tech help build sustainable businesses and expand our associates’ potential for career advancement. 

 

Headquartered in California, East West Bank (Nasdaq: EWBC) is a top-performing commercial bank with a strong foundation, an enterprising spirit and a commitment to absolute integrity. East West Bank gives people the confidence to reach further.

Overview

The Offensive Risk Strategist is responsible for leading and managing the organization’s vulnerability assessment program which includes threat modeling / assessments, red teaming, and penetration testing programs to proactively identify, analyze, and mitigate risks. This role ensures a comprehensive security posture by overseeing simulated attack scenarios and delivering actionable insights for remediation.

 

As an East West Bank employee, the Threat and Vulnerability Manager will be part of a growing and stable organization that provides career path development opportunities while serving a growing and profitable market.  This position is key to strengthening the organization’s defenses, driving innovation in security practices, and collaborating with a talented team in a dynamic and fast-paced environment.

Responsibilities

  • Develop, implement, and maintain a comprehensive vulnerability assessment program.
  • Perform regular vulnerability assessments across IT systems, applications, cloud platforms, and networks.
  • Assess and prioritize vulnerabilities based on risk levels, potential business impact, and threat intelligence.
  • Manage Attack Surface Monitoring.
  • Update and disseminate threat intelligence on active Threat Actors (Threat Actor Profiles).
  • Deliver regular briefings to leadership on vulnerability trends and risk status.
  • Establish automated threat Intelligence process for ingestion of TI and development of action plans.
  • Establish an effective Threat Assessment, Red Teaming and Threat Modeling capability for the bank.
  • Oversee internal and external penetration testing engagements, ensuring alignment with industry standards such as OWASP, NIST, and MITRE ATT&CK.
  • Validate the effectiveness of remediation actions through follow-up assessments.
  • Evaluate new tools and technologies to enhance the efficiency and effectiveness of security assessments
  • Stay updated on emerging threats, vulnerabilities, and attack techniques to adapt assessment methodologies.
  • Incorporate threat intelligence and industry best practices into vulnerability and red team programs.
  • Support automation and orchestration to maximize team talent and reduce routine tasks.
  • Support regulatory reviews, assessments as well and monitor and lead reporting and remediating identified control and regulatory issues
  • Foster collaboration between security, IT operations, and business teams to ensure alignment on security goals.
  • Promote a culture of security awareness across the organization.

Qualifications

  • Expertise in vulnerability management and penetration testing tools and techniques.
  • Proficiency in red teaming methodologies and frameworks (e.g. MITRE ATT&CK, TIBER-EU)
  • Knowledge of secure coding practices and application security testing.
  • Familiarity with cloud security (AWS, Azure, or GCP) and DevSecOps practices
  • Excellent communication skills for technical and non-technical audiences.
  • Strong analytical and problem-solving abilities.
  • Highly organized and efficient. Ability to work independently and as part of a team in a fast-paced, dynamic environment.
  • Bachelor's degree in Cybersecurity, Information Technology or related field required, advanced degree (Masters level) preferred
  • Minimum of 5 years in cybersecurity, with at least 3+ years in vulnerability management, penetration testing, or red teaming.
  • Hands-on experience in vulnerability assessments, penetration testing methodologies, and red teaming strategies.
  • Strong understanding of both offensive and defensive security techniques.
  • Preferred Certification such as CCSP, CISSP, CEH, OSCP, OSCE, GPEN, GWAPT, CVA, or other red team and penetration testing credentials.

Compensation

The base pay range for this position is USD $120,000.00/Yr. - USD $180,000.00/Yr. Exact offers will be determined based on job-related knowledge, skills, experience, and location.

Average salary estimate

$150000 / YEARLY (est.)
min
max
$120000K
$180000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Offensive Risk Strategist, UNAVAILABLE

At East West Bank, we’re on the lookout for an Offensive Risk Strategist to join our dynamic team in San Marino. This isn’t just any role; it’s an opportunity to lead our vulnerability assessment program, where you will play a crucial part in ensuring our organization stays a step ahead of potential threats. You’ll get to flex your skills in threat modeling, red teaming, and penetration testing while managing the organization’s overall security posture. Imagine being at the forefront of proactive risk management, where you’ll conduct regular assessments across our IT systems, applications, and networks to identify potential vulnerabilities. With your strategic insights, you’ll aid senior leadership in making informed decisions about our security tactics and enhance our defensive mechanisms. Not just a numbers game, you will collaborate with talented professionals and foster a culture of security awareness throughout the bank. Your input will drive innovation in our security practices and pave the way for career advancement within our growing bank. If you're passionate about cybersecurity and ready to protect and serve our clients while advancing your career, East West Bank is eager to welcome you. Join us and help shape a secure future!

Frequently Asked Questions (FAQs) for Offensive Risk Strategist Role at UNAVAILABLE
What are the daily responsibilities of an Offensive Risk Strategist at East West Bank?

As an Offensive Risk Strategist at East West Bank, your daily responsibilities will include developing and managing a vulnerability assessment program, performing regular assessments on IT systems, applications, and networks, and prioritizing vulnerabilities based on risk levels and potential business impacts. You will also oversee penetration testing engagements, conduct risk assessments, and deliver briefings to leadership on threat intelligence trends, ensuring the bank maintains a robust security posture.

Join Rise to see the full answer
What qualifications are needed to become an Offensive Risk Strategist at East West Bank?

To become an Offensive Risk Strategist at East West Bank, you will need a Bachelor's degree in Cybersecurity or a related field, with an advanced degree preferred. You should also have a minimum of 5 years in cybersecurity, including 3+ years specifically in vulnerability management and penetration testing. Relevant certifications like CCSP, CISSP, or OSCP are highly recommended, showcasing your expertise in security practices.

Join Rise to see the full answer
How does East West Bank support career advancement for an Offensive Risk Strategist?

At East West Bank, we believe in nurturing our talent and providing career advancement opportunities for roles such as the Offensive Risk Strategist. As a part of a growing organization, you will gain exposure to cutting-edge security tools and practices, be part of meaningful projects, and have access to continuous learning and development initiatives that will help propel your career in cybersecurity.

Join Rise to see the full answer
What makes the Offensive Risk Strategist position at East West Bank unique?

The Offensive Risk Strategist role at East West Bank is unique because it merges creativity with technology and security. You will work in a collaborative environment that values both proactive and reactive security measures, allowing you to influence and innovate security practices directly. Additionally, being part of a culturally diverse team that spans Asia and the U.S. adds an enriching aspect to your everyday work.

Join Rise to see the full answer
What tools and technologies might an Offensive Risk Strategist use at East West Bank?

An Offensive Risk Strategist at East West Bank will utilize an array of tools and technologies including vulnerability management systems, penetration testing frameworks, and threat intelligence platforms. Familiarity with cloud security (AWS, Azure) and techniques like MITRE ATT&CK is also essential, as well as using automated solutions for efficient threat assessments and remediation validations.

Join Rise to see the full answer
Common Interview Questions for Offensive Risk Strategist
Can you explain your experience with penetration testing methodologies?

When asked about your experience with penetration testing methodologies, provide specific examples of the frameworks you've utilized, such as OWASP or NIST. Discuss real-life scenarios where you not only conducted tests but also analyzed results and formulated actionable remediation plans.

Join Rise to see the full answer
How do you stay updated on the latest cybersecurity threats?

To effectively answer this question, highlight your commitment to continuous education through resources like cybersecurity forums, webinars, and professional organizations. Mention specific platforms or certifications you pursue to keep abreast of emerging threats in the cybersecurity space.

Join Rise to see the full answer
Describe a time when you identified a vulnerability and how you handled it.

In responding to this question, outline a clear situation where your actions led to identifying a critical vulnerability. Explain the steps you took in assessing the risk, structuring a response, and implementing a solution, along with the results of those actions.

Join Rise to see the full answer
What role does threat intelligence play in vulnerability assessment?

When addressing the role of threat intelligence, explain how it helps identify potential vulnerabilities based on real-world data. Emphasize the importance of integrating threat intelligence into your risk assessments to prioritize vulnerabilities effectively.

Join Rise to see the full answer
How would you approach setting up a vulnerability assessment program?

For this question, detail your approach starting from establishing goals, selecting the right tools, performing initial assessments, and setting a schedule for regular evaluations. Stress the importance of continuous improvement and adapting to new threats over time.

Join Rise to see the full answer
Can you discuss your experience with red teaming?

In your response, provide insights into any red teaming exercises you've participated in. Elaborate on how you simulated attackers to evaluate security measures, detailing how these exercises informed strategic security improvements within the organization.

Join Rise to see the full answer
What steps would you take if you discovered a serious vulnerability?

When answering this, describe a systematic approach: assessing the severity, notifying stakeholders, collaborating on a remediation plan, implementing the fix, and performing follow-up validation assessments to ensure effectiveness.

Join Rise to see the full answer
Describe your experience with cloud security and how it relates to vulnerability management.

Mention specific cloud platforms you're familiar with and how they integrate into your vulnerability management process. Discuss any relevant projects where you secured cloud environments and the tools you used.

Join Rise to see the full answer
How do you handle communication with non-technical stakeholders?

This is a great time to showcase your communication skills. Describe your approach to translating complex technical concepts into understandable terms, perhaps by using analogies or summarizing issues succinctly to ensure alignment on security initiatives.

Join Rise to see the full answer
Why do you want to work at East West Bank as an Offensive Risk Strategist?

While addressing this question, link your personal values and career aspirations with East West Bank's mission and vision. Talk about your enthusiasm for contributing to a bank that supports diverse markets and your eagerness to impact its security posture positively.

Join Rise to see the full answer
Similar Jobs
Posted 8 days ago

Join St. Joseph's Hospital as an Imaging Assistant Tech to enhance patient care and support medical procedures.

Join a leading healthcare team at St. Michael Medical Center as an Anesthesia Technician to support patient anesthesia care.

Photo of the Rise User
Posted 5 days ago

Join Peraton as an AWS DevOps Engineer to support mission-critical cloud solutions.

PIC Remote No location specified
Posted 8 days ago

Join PIC as an IT Transition Support Specialist to manage the transition of IT services into production.

Photo of the Rise User

Join the University of Tennessee at Chattanooga as an IT Administrator to enhance and support their IT infrastructure.

Photo of the Rise User
NBCUniversal Remote 30 Rockefeller Plaza, New York, NEW YORK
Posted 4 days ago

Join NBCUniversal as a Sr Cyber Security Manager to oversee and execute a comprehensive Cyber Security strategy across the Sports and News divisions.

Photo of the Rise User
MetroStar Hybrid Kansas City, Missouri, United States
Posted 11 days ago
Photo of the Rise User
Posted 11 days ago
Ginas Tech Jobs Hybrid 1212 S. Naper Blvd., Suwanee, GA, United States
Posted 5 days ago

Looking for a Mid-Level Manager, Internet of Things (IoT) Technician to oversee IT operations in Suwanee, GA.

Photo of the Rise User

Build innovative data solutions as a Senior Solution Architect with Core BTS's Azure Data and Analytics team.

MATCH
Calculating your matching score...
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
No info
HQ LOCATION
No info
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
March 30, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Cleveland just viewed Client Services Manager at Vitesse PSP
Photo of the Rise User
Someone from OH, Pickerington just viewed Sr. Client Project Manager at Forge Biologics
Photo of the Rise User
Someone from OH, Fairborn just viewed IOS Developer at Advansys
Z
Someone from OH, Reynoldsburg just viewed Educator Onboarding Associate at Zen Educate
Photo of the Rise User
7 people applied to IT Asset Analyst at Xero
Photo of the Rise User
Someone from OH, Canton just viewed SEASONER at Shearer's Foods
Photo of the Rise User
73 people applied to Jr SOC Analyst at IBM
Photo of the Rise User
Someone from OH, Avon Lake just viewed Data Analyst I - Hospitality Data Team at Lightspeed Commerce
Photo of the Rise User
Someone from OH, Columbus just viewed Brand Awareness Specialist - Entry Level at Smart Solutions
Photo of the Rise User
44 people applied to Cyber Crime Analyst at TEKsystems
Photo of the Rise User
9 people applied to SOC Analyst at Prosegur
Photo of the Rise User
31 people applied to IT Intern at USAA
Photo of the Rise User
Someone from OH, Cleveland just viewed Quality Assurance Weekender at Anheuser-Busch
Photo of the Rise User
Someone from OH, Lewis Center just viewed Marketing & Partner Operations Lead, USA, Remote at Fundraise Up
Photo of the Rise User
Someone from OH, Dayton just viewed Community Health Advocate at CVS Health
Photo of the Rise User
55 people applied to SOC Analyst I at Epsilon
Photo of the Rise User
Someone from OH, Cleveland just viewed Power Platform Developer - (Remote - US) at Jobgether
Photo of the Rise User
Someone from OH, Cincinnati just viewed Mechanical Engineering Intern (June - August) at Exowatt
Photo of the Rise User
Someone from OH, Dayton just viewed Data Science, AI Data at Meter
Photo of the Rise User
Someone from OH, Dayton just viewed Lead Data Engineer at Kanerika Software
I
Someone from OH, Dayton just viewed Machine Learning Intern at Inductive Bio
A
Someone from OH, Dayton just viewed Applied AI Research Intern (USA) at Articul8
Photo of the Rise User
Someone from OH, Dayton just viewed Machine Learning Internship at Provectus
S
Someone from OH, Dayton just viewed Machine Learning Engineer Intern at Sayari
Photo of the Rise User
Someone from OH, Highland Heights just viewed Software Engineer (Android) at Solvd
Photo of the Rise User
Someone from OH, Columbus just viewed IT Quality & Training Analyst at Privia Health