Information Security Analyst

Stefanini North America and APAC

Richmond (VA)

Hybrid

USD 90,000 - 120,000

Full time

10 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Stefanini North America and APAC is seeking a Security Control Assessor for a hybrid role based in Richmond, VA. The ideal candidate will evaluate information security controls, review policies and procedures, and advise on SAFR requirements to strengthen security posture.

Travel and occasional extended hours may be required. Requirements include a bachelor's degree in computer science or information security and 3–5+ years of relevant experience, with certifications such as CISSP, CISA, or CISM

Qualifications

  • Bachelor's degree in computer science, Information Security, or equivalent experience.
  • 3–5+ years of relevant work experience.
  • Proven experience with conducting security assessments.
  • Knowledge of compliance frameworks and continuous authorization processes (NIST SP800-37, SP800-53/53a).
  • Excellent communication skills and ability to work collaboratively.

Responsibilities

  • Conduct thorough evaluations of information security controls to identify threats and vulnerabilities to the Systems information systems.
  • Review security controls, policies, and procedures to prioritize risks and recommend enhancements.
  • Advise districts on SAFR requirements and best practices based on data review.
  • Participate in project development around new processes and communicate changes to clients and resources.
  • Perform other related duties as assigned.

Skills

Security assessments
Communication
Risk management
Collaboration
SAFR knowledge

Education

Bachelor's degree in computer science or information security

Job description

Stefanini is looking for an Security Control Assessor - Richmond, VA/Hybrid

W2 candidates only!

Position Overview:

The Security Control Assessor plays an integral role in ensuring that an organization's information systems are evaluated for security risks and vulnerabilities, aligning with established information security policy and standards. This position involves a thorough examination of security controls, policies, and procedures to identify any weaknesses that could potentially be exploited. By conducting comprehensive assessments, the Security Certification Assessor provides essential insights and recommendations to enhance the security posture of the organization. Their expertise supports the development of strategies to mitigate identified risks, ensuring the protection of sensitive information and the integrity of IT systems. Through their work, the company is better equipped to navigate the complex landscape of cybersecurity threats, maintaining compliance with SAFR requirements, and safeguarding assets.

Responsibilities:
  • Conduct thorough evaluations of information security controls to identify potential threats and vulnerabilities to the Systems information systems.
  • The process includes a detailed review of security controls, policies, and procedures to prioritize risks and recommend enhancements that support organizational security goals.
  • Reviews data and assists in advising districts on best practices and how to implement the necessary changes to address their business and information security needs.
  • Key participant in project development surrounding new processes and the integrating of new processes with existing ones. Assists in developing communications of these changes to impacted clients and other resources.
  • Performs other related duties as assigned.
Working Conditions:
  • Will require the use of standard office equipment such as computers, phones, photocopiers, etc.
  • Physical Demands: Requires some degree of sitting (for prolonged periods of time), standing, lifting carrying, pushing, pulling less than 20 lbs.
Job Requirements
Details:
Hours of Work:
  • May require extended work hours. The ideal candidate will work a hybrid schedule and be in a district office two days a week. Occasional travel including overnight stays may be necessary.
Required Qualifications:
  • Bachelor's degree in computer science, Information Security, or equivalent experience with 3 to 5+ years of relevant work experience
  • Proven experience with conducting security assessments
  • Knowledge of compliance frameworks and continuous authorization processes. Prefer NIST SP800-37, SP800-53/53a.
  • Excellent communication skills and the ability to work collaboratively.
  • Reviewing data and advising customers on SAFR requirements and best practices
  • Building strong collaboration and negotiation relationships
  • Understands and applies the risk management discipline in decision making and contributes to the functional area's risk management.
Preferred Qualifications:
  • Certifications such as CISSP, CISA, CISM.
  • Experience in a policy and assurance or quasi-governmental environment
  • Familiarity with cloud service providers and associated security challenges
  • Knowledge of SAFR lifecycle compliance and testing
  • The candidate must possess skills that include experience with:
  • Reviewing data and advising customers on SAFR requirements and best practices
  • Building strong interpersonal collaboration, negotiation, creativity, attention to detail, and communication relationships

Listed salary ranges may vary based on experience, qualifications, and local market. Also, some positions may include bonuses or other incentives.

Stefanini takes pride in hiring top talent and developing relationships with our future employees. Our talent acquisition teams will never make an offer of employment without having a phone conversation with you. Those face-to-face conversations will involve a description of the job for which you have applied. We also speak with you about the process including interviews and job offers.

About Stefanini Group:

The Stefanini Group is a global provider of offshore, onshore and near shore outsourcing, IT digital consulting, systems integration, application, and strategic staffing services to Fortune 1000 enterprises around the world. Our presence is in countries like the Americas, Europe, Africa, and Asia, and more than four hundred clients across a broad spectrum of markets, including financial services, manufacturing, telecommunications, chemical services, technology, public sector, and utilities. Stefanini is a CMM level 5, IT consulting company with a global presence. We are CMM Level 5 company.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Analyst
Information Security Analyst

Stefanini, Inc • Richmond (VA), Northern (KY)

Hybrid
USD 163,328,000 - 177,655,000
Hybrid work schedule
Hybrid InfoSec Analyst: Security Controls & Assessments
Hybrid InfoSec Analyst: Security Controls & Assessments

Stefanini, Inc • Richmond (VA), Northern (KY)

Hybrid
USD 163,328,000 - 177,655,000
Hybrid work schedule
SOC Analyst
SOC Analyst

Stefanini North America and APAC • Dover (DE)

Hybrid
USD 75,000 - 110,000
Software Engineer
Software Engineer

Stefanini, Inc • Richmond (VA), Northern (KY)

On-site
USD 134,000 - 141,000
Site Reliability Engineer
Site Reliability Engineer

Stefanini North America and APAC • Dearborn (MI)

On-site
USD 120,000 - 150,000
Data Center Technician
Data Center Technician

Stefanini North America and APAC • San Jose (CA)

On-site
USD 65,000 - 95,000
Site Reliability Engineer
Site Reliability Engineer

Stefanini, Inc • Dearborn (MI)

Hybrid
USD 84,000 - 91,000
Support IT Security
Support IT Security

Stefanini • Town of Florida (NY)

On-site
USD 120,000 - 170,000
IT Senior Auditor
IT Senior Auditor

Stefanini • Princeton (NJ)

On-site
USD 80,000 - 100,000
Automation Engineer
Automation Engineer

Stefanini, Inc • Richmond (VA), Northern (KY)

Hybrid
USD 110,000 - 117,000