- Serve as a lead security analyst within IT Security Governance and IT Security Operations
- Administer, monitor, maintain, and continuously improve critical security technologies
- Maintain day-to-day cybersecurity operations
- Recommend firewall change requests for approval
- Analyze intrusion detections and take appropriate action
- Analyze security-related incidents and recommend action; notify appropriate owners and IT Security Governance
- Review and approve access requests
- Provide role-based access control (RBAC) to individual users and perform recertification based on segregation of duties and roles
- Map workflows for provisioning users into systems and infrastructure
- Comply with internal and external audit requests
- Monitor the effectiveness of the enterprise-wide information security program
- Provide audit data on access-control-list changes for audits and investigations
- Investigate possible security violations
- Track and maintain operational security access metrics
- Design workflow diagrams for the production, transmission, and use of electronic Protected Health Information (ePHI) and other sensitive information
- Provide guidance regarding security control elements in organizational policies
- Document business processes and their information-security implications
- Develop information security risk identification, tracking, and mitigation processes, strategy, and methodology
- Develop the information security awareness, training, and education program strategy and methodology
- Facilitate or lead development of information security process and operational metrics
- Establish monitoring measures to detect and correct security breaches and policy violations
- Keep current on information security issues related to business processes for departmental policies and procedures
- Analyze and enhance the effectiveness of the enterprise-wide information security program
Requirements
- Minimum high school diploma or GED
- Requires Bachelor's degree, preferably in Computer Science, from an accredited college or university
- Prefers advanced degree in Information Security, Computer Science or related field
- 5 years prior IT security related work experience
- Experience with IDS, IPS, ICE Engine
- Requires one or more of the following certifications: CISSP, SANS GIAC or CISA
- Excellent understanding of IT security concepts with an emphasis on Security and Risk Assessment
- Microsoft 365 security implementation and ongoing support
- Micro-segmentation initiatives to reduce lateral movement risks
- AI performance, governance, and security controls
- Data classification and sensitive data protection initiatives
- Cloud security enhancements
- Continuous vulnerability remediation efforts
- Security architecture improvements aligned with organizational objectives
- Perimeter Defense: Palo Alto Networks (PAN) Firewalls, Prisma GlobalProtect VPN, Cisco Sourcefire, Cisco Stealthwatch, Cisco Identity Services Engine (ISE), Secure Mail Gateway (ProofPoint), Enterprise Proxy
- Endpoint and Data Protection: Endpoint Protection Platforms, Data Loss Prevention (DLP), File Integrity Monitoring (FIM), Absolute/Computrace, Vulnerability Scanning Platforms, Disk Encryption, EDR (Crowdstrike)
- Application and Cloud Security: Web Application Firewall (WAF), Secure Proxy Services, Zscaler, Application Security Programs, Cloud Access Security Broker (CASB), Cloud Security Controls
- Security Operations: Security Information and Event Management (SIEM), Security Monitoring and Alerting, Incident Response Activities, Threat Detection and Vulnerability Management
Core Competencies
Demonstrates expertise in IT Security Governance and Operations, with a strong focus on cybersecurity technologies, risk assessment, and compliance. Proficient in managing security incidents, implementing security controls, and enhancing organisational security posture.
Highest-signal resume keywords
- IT Security Governance
- Cybersecurity Operations
- Risk Assessment
- CISSP Certification
- Security Information and Event Management (SIEM)
ATS Optimization Keywords
Hard Skills
- Intrusion Detection Systems (IDS)
- Intrusion Prevention Systems (IPS)
- Data Loss Prevention (DLP)
- Vulnerability Scanning
- Endpoint Protection Platforms
- Cloud Security Enhancements
- Firewall Management
- Access Control Management
- Security Architecture Improvements
- Incident Response
Soft Skills
- Analytical Thinking
- Problem Solving
- Communication
- Collaboration
- Leadership
Certifications & Qualifications
Industry Keywords
- Cybersecurity
- Information Security
- Data Protection
- Compliance
- Risk Management
Tools & Technologies
- Palo Alto Networks Firewalls
- Cisco Stealthwatch
- Microsoft 365 Security
- Web Application Firewall (WAF)
- Cloud Access Security Broker (CASB)
- Zscaler
- ProofPoint
- Crowdstrike
- Prisma GlobalProtect VPN
- Cisco Identity Services Engine (ISE)