Overview
Information security analysts are responsible for improving the overall security posture of the organization. They evaluate, test and document security solutions and controls, and work closely with other security team members to remediate risk while ensuring the business can innovate.
Candidate Experience Level
- 4 to 7 years of experience in Cybersecurity, including compliance, regulations, risk management and audit. At least 5 years of experience in securing or utilizing one of the major cloud platforms (Azure, AWS) is desired.
Qualifications
- Accustomed to working with Product and development teams.
- Experience with compliance requirements (GLBA, PCI, HIPAA, SOX, etc.) is preferred.
- Ability to effectively communicate business risk as it relates to information security.
- Experience in conducting risk assessments that protect the business and adhere with compliance and privacy laws.
- Knowledge of multiple computing platforms, including Windows, OSX, Linux, Unix, networks, and endpoints and cloud platforms such as Azure, AWS, and Google Cloud.
- Experience with the application of threat intelligence, indicators of compromise (IOCs), and vulnerability analysis.
- Experience working with MSSPs to support monitoring and response.
Responsibilities
- Utilize and configure technical systems to monitor for unusual and suspicious activity across a wide range of products.
- Assist with security configuration standards for systems and business applications.
- Serve as a member of the information security team to support change management processes.
- Participate in technical and non-technical projects requiring information security oversight and to ensure policies, procedures and standards are met.
- Serve as an additional security team member, aiding in incident monitoring and incident response (IR) in partnership with the security operations center (SOC) teams.
- Maintain vendor management standards, questionnaires, and documentation to adhere to regulatory compliance.
- Interface with internal and external stakeholders for risk assessments.
- Recommend new security approaches and business process changes to support existing security controls; that do not negatively impact or severely impede business innovation.
- Serve as a liaison for the security team regarding product team efforts.
- Perform other duties as assigned.
Desired Certifications
- Certification in Cybersecurity Analysis, Incident Response, or Risk Management