Job Search and Career Advice Platform

Enable job alerts via email!

Cyber Security Analyst with Cloud Security Experience

Jobs via Dice

Remote

USD 100,000 - 130,000

Full time

Today
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading consulting firm is seeking a mid to senior-level Cyber/Cloud Security Analyst for a fully remote role. This position involves enhancing the security of applications and systems, particularly in the Cloud, and mitigating potential security risks. Strong candidates will have 5-7 years of IT and security experience, relevant certifications, and the ability to effectively communicate security practices across technical and non-technical teams. Join this diverse team that values customer service, employee development, and integrity.

Qualifications

  • 5-7 years of combined IT and security experience required.
  • Preferred certifications include CISA, CISM, CISSP, CCSP, AZ500.
  • In-depth knowledge of security techniques and issues is necessary.

Responsibilities

  • Define security requirements and evaluate business strategies.
  • Provide consulting and security support to internal customers.
  • Serve as a security liaison on assigned projects.
  • Evaluate the effectiveness of awareness and training programs.
  • Mentor less-experienced team members.

Skills

Information Security
Cyber Security
Analytical Skills
Problem-Solving Skills
Interpersonal Skills
Consultative Skills

Education

Bachelor's Degree in Computer Science or Information Systems

Tools

SaaS
PaaS
IaaS
ISO 27001/27002
PCI
NIST
Job description

Software Guidance & Assistance, Inc., (SGA), is searching for a Cyber/Cloud Security Analyst for a REMOTE CONTRACT position with one of our premier Healthcare Services clients.

This position is fully remote; however, candidates should be located in EST/CST time zones.

This is a good fit for you if you are a mid to senior-level Information Security or Cyber Security Professional. The responsibilities will be to enhance the security of applications and systems, particularly in their Cloud security space, and to play a pivotal role in reducing coding, design, or configuration vulnerabilities affecting production environments, thereby mitigating potential security risks.

Responsibilities
  • Defining security requirements by evaluating business strategies and requirements; researching information security standards.
  • Providing consulting services and security support to internal business and technology customers.
  • Serving as a security liaison on assigned projects.
  • Providing input and recommendations to the development teams related to architecture, design, coding practices and SDLC elements that could potentially impact the application or solution from a security perspective.
  • Validating controls for Encryption, Access Control, Web Application Vulnerability Detection, OWASP top 10 and other common web application security parameters.
  • Reviewing application architecture and design from an application security and information security perspective ensuring alignment with organization security standards and industry best practices.
  • Serving as a subject matter expert (SME) for performing vendor risk assessments (including Cloud Services) to improve overall vendor risk program.
  • Assisting with the development of secure coding standards.
  • Providing technical expertise on secure software development and support of all associated activities, processes, and tools for protecting technology-based information.
  • Ensuring that development is done in accordance with industry standards for secure development.
  • Facilitating periodic static code analysis utilizing existing standard service offering.
  • Facilitating dynamic and/or manual security testing utilizing existing standard service offering.
  • Reviewing, developing, testing, and implementing security plans, products, and control techniques.
  • Reviewing circumstances surrounding security gaps in and designing corrective actions.
  • Maintaining awareness of security and technology trends and sharing that knowledge with others.
  • Evangelizing security policies, standards, and nonfunctional requirements where/when needed.
  • Daily and weekly status reporting for work in progress, planned work, and issues.
  • Documenting processes, procedures, assessment outputs, and working papers to support existing SDLC and governance requirements.
  • Representing security and IT risks among other company risk departments and committees.
  • Evaluating the effectiveness of awareness and training programs and making recommendations for improvement.
  • Mentoring less-experienced team members and collaborating across Information Technology.
What your background should look like
  • Bachelor's Degree in Computer Science, Information Systems, or a related field, or equivalent work experience.
  • 5-7 years of combined IT and security work experience with a broad range of exposure to systems analysis, application development, systems administration, and deploying security for business products and services and enterprise solutions at the enterprise level.
  • Preferred certification in one or more Information Security relevant areas such as Audit (CISA), Security Management (CISM), Security Professional (CISSP), Cloud Security (CCSP, CCSK, AZ500).
  • Requires in-depth knowledge of security issues, techniques, and implications across all existing computer platforms.
  • Experience with evaluating and implementing security controls as related to Cloud-based services including SaaS, PaaS, IaaS.
  • Strong computer skills to operate effectively with company systems and programs; working knowledge of applicable computer applications used at the firm.
  • Working knowledge of network solutions and systems.
  • Good analytical and problem-solving skills.
  • Ability to communicate effectively both orally and in writing, and strong interpersonal skills.
  • Ability to prioritize workload and consistently meet deadlines.
  • Strong consultative skills: ability to interface effectively with technical and non-technical leaders.
  • Understands Information Security as it relates to the business and other areas of IT; understands direct impacts and risks.
  • Demonstrated sound understanding of multiple security control frameworks such as ISO 27001/27002, HITRUST, PCI, NIST, GDPR.
Business Experience In a Matrix Organization Required

SGA is a technology and resource solutions provider driven to stand out. We are a women-owned business. Our mission: to solve big IT problems with a more personal, boutique approach. Each year, we match consultants like you to more than 1,000 engagements. When we say let's work better together, we mean it. You'll join a diverse team built on these core values: customer service, employee development, and quality and integrity in everything we do. Be yourself, love what you do and find your passion at work. Please find us at .

SGA is an Equal Opportunity Employer and does not discriminate on the basis of Race, Color, Sex, Sexual Orientation, Gender Identity, Religion, National Origin, Disability, Veteran Status, Age, Marital Status, Pregnancy, Genetic Information, or Other Legally Protected Status. We are committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, and our services, programs, and activities. Please visit our company to request an accommodation or assistance regarding our policy.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.