IT Security Administrator III

Giesecke & Devrient GB Ltd.

Bolingbrook (IL)

On-site

USD 115,000 - 131,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical insurance
Dental
Vision
401K with employer match
Paid time off
Education assistance

Job summary

Giesecke+Devrient America, Inc. is seeking an Information Security Administrator III to oversee the Information Security program, including ISO 27001, PCI, and internal compliance. You will act as a security SME and consultant to other departments, investigating findings and guiding remediation, with 24x7 readiness for emergencies.

You will supervise IT security staff, manage cryptographic key management, coordinate audits, and maintain training programs. Travel up to 15% may be required.

Qualifications

  • Associate degree in Computer Science or Information Systems.
  • 5 years IT/Information Security experience in a financial or similar industry.
  • CISSP and/or CISA certification required.
  • Audit and Compliance experience (PCI, ISO) preferred.

Responsibilities

  • Administer and enhance the Information Security Management System (ISO 27001, PCI).
  • Provide daily supervision of IT Security staff and tasks.
  • Manage cryptographic key management (PKI, keys handling).
  • Coordinate internal and external audits for security requirements.
  • Develop and maintain information security training and risk management processes.
  • Assist in remediation of IT security vulnerabilities.

Skills

IT Security
Risk assessment
Security governance

Education

Associate degree in Computer Science or Information Systems
5 years IT/Information Security experience
CISSP and/or CISA certification
PCI/ISO audit experience

Job description

Select how often (in days) to receive an alert:


Location: Bolingbrook, IL, US Chicago, IL, US


Job Summary:

The Information Security Administrator III has overall responsibility for the administration of the Information Security program for Giesecke+Devrient America, Inc (G+D). This includes the ongoing administration of G+D’s security certifications for ISO 27001, PCI, and internal information security compliance. Serve as the subject matter expert in data security and act as a consultant in assisting other departments with IT Security process and documentation. Investigate findings to determine root causes and recommend necessary preventative actions to mitigate reoccurrence of the associated risks. Must have ability to provide 24x7 for possible Security or IT related emergencies and/or escalations.


Essential Functions:


  • Administer and preserve G+D Security Certifications through the administration and ongoing enhancement of the Information Security Management System with a primary focus on ISO 27001, Cryptographic Key Management and PCI Logical Security requirements. Ensure Information Security controls are relevant, properly documented and maintained for ongoing recertification and governance activities. Part of the role is to maintain a system that fosters appropriate, demonstrable, auditable and coordinated security procedures, and practices that are compliant with related laws, regulations, policies and professional standards.

  • Provide daily supervision of IT Security staff and tasks.

  • Responsible for effective and comprehensive administration of the cryptographic key management program, which includes the generation, exchange, storage, use, replacement and documentation of cryptographic keys. Possess a full understanding of key management servers, symmetric and asymmetric keys, and public key infrastructure (PKI).

  • Ensure compliance with all applicable internal and external Information Security requirements through coordination of internal and external Logical Security audits.

  • Maintains a system that fosters appropriate information security training and awareness. Responsible for developing and maintaining a system that encourages the routine use of risk assessments and risk management planning related to the information security features of systems, tools and networks.

  • Responsible for assessing, reporting and assisting in the remediation of IT security vulnerabilities for IT systems and applications that are part of G+D operations.

  • Responsible for designing, documenting, training and testing of the corporate IT Security Incident Response Plan.

  • Responsible for maintaining status information regarding the configuration files for information security appliances, software and equipment (monthly firewall rule target/configuration comparison etc.)

  • Independently contribute ideas and process improvements and look for creative solutions and better ways of doing things, in order to meet goals of continuous improvement

  • Identify, analyze, and address problems in order to resolve issues whenever possible in a way that minimizes the negative impact on the organization

  • Work with the ISF (information security forum) materials and tools including participation in local ISF chapter meetings

  • Analyze issues not only from a local point of view but should also consider the global scope of G+D operations

  • Performs other duties as assigned

  • Complies with all policies and standards


Qualifications and Skills:

Education and Experience



  • Associate degree in Computer Science or Information Systems

  • 5 years IT/Information Security experience, preferably in a financial service or similar industry

  • CISSP and/or CISA certification required

  • Audit and Compliance experience (PCI, ISO)


Knowledge Skills and Abilities



  • Solid knowledge and understanding of IT Security Standards (ISO 27001) and IT Process Standards (ITIL, COBIT)

  • Solid understanding of the key technical and organizational concepts of Information Security-related Systems (firewalls, intrusion detection, virtualization technologies, encryption, VPN, etc.).

  • Ability to develop and defend technical recommendations and budgetary plans and communicate them in non-technical “business language”

  • Ability to communicate information security issues clearly and appropriately to audiences with diverse technical backgrounds, without creating unnecessary urgency


Job Specifications:


  • Work performed in a light industrial setting

  • Exposure to some shop noise

  • Significant amount of walking between offices and throughout facility

  • Some lifting required

  • Travel up to 15% may also be required.


The pay range for this position is $114,520 - $130,760 and is eligible for an annual bonus.


Benefits offered to eligible employees include,



  • medical (PPO and HDHP with HSA)

  • dental

  • vision

  • paid time off

  • paid holidays

  • 401K w/ employer match

  • short/long term disability

  • life insurance

  • healthcare and dependent care flexible spending

  • EAP

  • commuter benefits

  • education assistance

  • pet insurance

  • legal

  • and more


Giesecke+Devrient ePayments America, Inc. is an Equal Opportunity Employer – M/F/Veteran/Disability/Sexual Orientation/Gender Identity

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Administrator III
IT Security Administrator III

Giesecke+Devrient ePayments America, Inc. • Chicago (IL)

On-site
USD 115,000 - 131,000
life insurance
paid time off
paid holidays
+2
IT Security Administrator III
IT Security Administrator III

Giesecke+Devrient • Bolingbrook (IL)

On-site
USD 115,000 - 131,000
Medical insurance
Dental insurance
Vision insurance
+3
Client Service Representative I
Client Service Representative I

Giesecke & Devrient GB Ltd. • Bolingbrook (IL)

On-site
USD 45,000 - 50,000
Medical and dental benefits
401(k) with employer match
Paid time off and holidays
Production IT Systems Engineer II
Production IT Systems Engineer II

Giesecke+Devrient • Bolingbrook (IL)

On-site
USD 70,000 - 90,000
Medical and dental insurance
401k with employer match
Education assistance
+1
Secure Vault - Warehouse Coordinator
Secure Vault - Warehouse Coordinator

Giesecke & Devrient GB Ltd. • Bolingbrook (IL)

On-site
Annual bonus eligibility
Comprehensive benefits package
Senior IT Security Administrator - ISO 27001 & PCI
Senior IT Security Administrator - ISO 27001 & PCI

Giesecke+Devrient • Bolingbrook (IL)

On-site
USD 115,000 - 131,000
Medical insurance
Dental insurance
Vision insurance
+3
Client Service Representative I
Client Service Representative I

Giesecke+Devrient ePayments America, Inc. • Bolingbrook (IL)

On-site
USD 45,000 - 50,000
Medical benefits
Dental
Vision
+10
IT Security Engineer II
IT Security Engineer II

MedImpact Healthcare Systems Inc. • San Diego (CA)

On-site
USD 110,982 - 199,769
Medical, Dental, Vision, and Wellness
401K with Company match
PTO and Holidays
+4
Electromechanical Field Service Technician III
Electromechanical Field Service Technician III

Giesecke & Devrient GB Ltd. • East Rutherford (NJ)

On-site
USD 68,000 - 75,000
Quality Inspector-1st Shift
Quality Inspector-1st Shift

Giesecke & Devrient GB Ltd. • Bolingbrook (IL)

On-site
USD 26,000 - 29,000
Medical insurance
401K
Paid Time Off
+3