Security Analyst

Sonsoft Inc

Marysville (OH)

On-site

USD 80,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A tech consulting firm based in Marysville, Ohio is looking for a professional with extensive experience in risk management and information security to implement and oversee the risk management framework. The ideal candidate will possess strong communication skills and be able to handle confidential information with integrity. Candidates must have a Bachelor's degree in Information Systems and a minimum of 3-5 years in risk management. This position is a contract role and only U.S. citizens and those authorized to work in the U.S. are encouraged to apply.

Qualifications

  • Minimum of 3-5 years in information security risk management.
  • Experience with risk assessment methodologies and compliance.
  • Knowledge of security frameworks like ISO 27002 and NIST.

Responsibilities

  • Implement risk management framework and reporting methodologies.
  • Develop processes for risk identification and monitoring.
  • Perform third party supplier risk assessments.

Skills

Risk management
Security policies
Interpersonal communication
Problem-solving
Microsoft Office Suite

Education

Bachelor's degree in Information Systems
Professional certification (CISSP, CRISC, CISA, CISM)

Job description

Sonsoft , Inc. is a USA based corporation duly organized under the laws of the Commonwealth of Georgia. Sonsoft Inc. is growing at a steady pace specializing in the fields of Software Development, Software Consultancy and Information Technology Enabled Services.

Job Description
Musts
  • Bachelor's degree in Information Systems or equivalent work experience of a minimum of 3-5 years as an information security risk management practitioner, preferably in the financial, consulting, and/or global organizations.
  • Prior work experience of risk management disciplines, security policies and standards, technology risk assessment, and third party supplier risk process and requirements.
  • Current or previous experience with risk assessment methodologies and conducting risk analysis in a regulated environment or related IT audit background.
  • Knowledge of security and control frameworks, such as ISO 27002, NIST, CobiT, COSO and ITIL.
  • Experience with implementation of information security best practices for key areas such as access control, data protection, systems development life cycle, PCI DSS, and cloud services.
  • Professional certification in risk management, and/or audit is preferred (e.g., CISSP, CRISC, CISA, or CISM).
Wants
  • Demonstrate broad competency and understanding in a variety of IT security areas.
  • Security Policy Development and Management.
  • Assist with documenting security policies, standards, and guidelines.
  • Based on the organization's requirements, maturity level, and compliance objectives.
  • Facilitate, coordinate, and maintain project schedules, plans, and scope using standard project management methodologies.
Business Experience
  • Proven ability to work with and across all levels of the organizations and navigate organizational boundaries.
  • Excellent organizational, interpersonal and communication skills with strong written, oral, and presentation skills; both delivery and creation of power points (must be able to distill complex topics into simple concepts).
  • Ability to effectively communicate with technical and executive audiences and develop and maintain strong peer/client/customer relationships underpinned by a service oriented approach to work.
  • Adept with time management, tasks and projects prioritization, and multi-tasking.
  • High level of personal integrity, and the ability to professionally handle confidential matters and exude the appropriate level of judgment and maturity.
  • High degree of initiative, attention to detail, follow-up skills, deliver on commitments, dependability and ability to work with little supervision.
  • Demonstrated problem-solving skills and capability to drive process improvements.
  • Proficient with Microsoft Office Suite especially Excel and Power point.
Description
  • Implement the overall risk management framework and processes, tools, and reporting methodologies on a continuous cycle.
  • Develop and standardize processes and procedures for ongoing risk identification, tracking, monitoring, and evaluating security measures and remediation efforts; communicate security control deficiencies and recommend mitigation plans, report status progress and with non-compliance issues; measure adherence to the security controls from a policy, governance and risk standpoint.
  • Perform third party supplier risk assessments by reviewing contracts for compliance with security policies, standards and practices; document security gaps and recommend appropriate remediation actions as necessary to minimize risks to the business.
  • Assist with documenting security policies, standards, and guidelines based on the organization's requirements, maturity level, and compliance objectives.
Qualifications
  • Planning, designing and implementing an overall risk management process for the organization.
  • Risk identification, analysis, tracking, monitoring, documenting exceptions, and communicating risks to owners.
  • Risk assessment, which involves analyzing risks as well as identifying, describing and estimating the risks affecting the business.
  • Risk evaluation, which involves comparing estimated risks with criteria established by the organization such as costs, legal requirements and environmental factors, and evaluating the organization’s previous handling of risks.
  • Establishing and quantifying the organization’s 'risk appetite', i.e. the level of risk they are prepared to accept.
  • Risk reporting in an appropriate way for different audiences, for example, to the board of directors so they understand the most significant risks, to business heads to ensure they are aware of risks relevant to their parts of the business and to individuals to understand their accountability for individual risks.
  • Corporate governance involving external risk reporting to stakeholders.
  • Carrying out processes such as purchasing insurance, implementing health and safety measures and making business continuity plans to limit risks and prepare for if things go wrong.
  • Conducting audits of policy and compliance to standards, including liaison with internal and external auditors.
  • Providing support, education and training to staff to build risk awareness within the organization.
Additional Information

U.S. citizens and those authorized to work in the U.S. are encouraged to apply. We are unable to sponsor at this time.

Note:-

  • This is aContractjob opportunity for you.
  • Only US Citizen, Green Card Holder, TN Visa, GC-EAD,H4-EAD & L2-EAD can apply.
  • No OPT-EAD & H1B Consultants please.
  • Please mention yourVisa Statusin youremailorresume.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst (In-Persons Interview)
Security Analyst (In-Persons Interview)

Sonsoft Inc • Marysville (OH)

On-site
USD 80,000 - 100,000
Security Administrator II
Security Administrator II

Sonsoft Inc • Marysville (OH)

On-site
USD 80,000 - 100,000
Security Administrator
Security Administrator

Sonsoft Inc • Marysville (OH)

On-site
USD 80,000 - 110,000
Application Security
Application Security

Sonsoft Inc • Exton (PA)

On-site
USD 90,000 - 120,000
Security Analyst
Security Analyst

Cygnus Professionals Inc • Boston (MA)

On-site
USD 80,000 - 100,000
Sr. IT Risk Analyst
Sr. IT Risk Analyst

Insight Global • Chicago (IL)

On-site
USD 120,000 - 180,000
Information Security Risk Analyst
Information Security Risk Analyst

Compunnel, Inc. • San Francisco (CA)

On-site
Security Administrator III
Security Administrator III

Sonsoft Inc • Marysville (OH)

On-site
USD 85,000 - 110,000
Cloud Security Specialist
Cloud Security Specialist

Sonsoft Inc • Windsor Mills (OH)

On-site
USD 80,000 - 100,000
Senior Security Analyst
Senior Security Analyst

TecTammina • Houston (TX)

On-site