Senior Information Security Analyst

MGT

Stamford (CT)

On-site

USD 90,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A consultancy firm is seeking a senior-level Information Security Analyst for a long-term contract in the Stamford area. The role involves developing cybersecurity frameworks in line with NIST standards, conducting risk assessments, and managing security operations. Candidates should have extensive experience in information security, especially with NIST frameworks, along with strong hands-on skills in management tools. This is a fully on-site position requiring commitment for 6–12 months, supporting a large municipal government client.

Qualifications

  • 8–10 years of progressive experience in information security or IT risk.
  • Experience with NIST, ISO 27001, and CIS Controls.
  • Hands-on experience in vulnerability management and security operations.

Responsibilities

  • Develop and maintain security policies and standards.
  • Monitor and respond to security incidents.
  • Conduct vulnerability assessments and support audits.

Skills

Information security policies
NIST frameworks
SIEM experience
Risk assessments
Stakeholder communication

Tools

AWS
Azure
GovCloud

Job description

MGT is seeking a senior-level Information Security Analyst for a long-term W2 contract engagement supporting a large municipal government client in Connecticut. The consultant will be embedded directly with the client’s Cybersecurity Officer and work cross-functionally with IT, Legal, and department leadership.

This is a hands-on GRC + Security Operations role. The selected professional will design, implement, and operationalize a structured IT risk and cybersecurity framework aligned to NIST and federal standards.

Location: On-site (Stamford area, CT)
Schedule: 35 hours per week (fully on-site)
Duration: 6–12 months with likely extension
Employment Type: W2 contract through MGT
Key Responsibilities
  • Program & Framework Development
    • Develop and maintain information security policies, standards, and procedures
    • Align cybersecurity program to NIST CSF 2.0, NIST RMF, FISMA, FedRAMP
    • Build and maintain enterprise IT risk register and control inventory
    • Design and implement annual Risk & Control Self-Assessment (RCSA) framework
    • Conduct application and infrastructure risk assessments
    • Perform SOC testing and support SOC audits
  • Security Operations
    • Conduct vulnerability assessments and targeted risk reviews
    • Monitor and respond to security events and incidents
    • Lead breach investigations, containment, and remediation
    • Support SIEM, IDS/IPS, DLP, endpoint protection, and vulnerability management tools
    • Develop POA&M tracking and remediation reporting
  • Governance & Advisory
    • Participate in audits and compliance assessments
    • Develop threat intelligence monitoring processes
    • Deliver security awareness training
    • Serve as security risk advisory lead across departments
Required Experience
  • 8–10 years progressive experience in information security, IT risk, or security operations
  • Strong experience with NIST frameworks, ISO 27001, CIS Controls
  • Hands-on experience with SIEM, IDS/IPS, firewalls, endpoint security, vulnerability management
  • SOC testing and audit support experience
  • Familiarity with Zero Trust architecture
  • Experience with AWS, Azure, or GovCloud
  • Government or regulated environment experience preferred
  • Strong documentation and stakeholder communication skills
Additional Requirements
  • Ability to commute daily and work fully on-site
  • Available for full 35-hour schedule
  • Commitment to 6–12 months
  • Comfortable with public-sector budget parameters
  • Background screening required

This is not an advisory-only role. The client needs a senior professional who can both design the framework and operationalize it.

If interested, please message directly or apply via LinkedIn.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior InfoSec Analyst: GRC & Security Ops, On-Site CT
Senior InfoSec Analyst: GRC & Security Ops, On-Site CT

MGT • Stamford (CT)

On-site
USD 90,000 - 120,000
Senior Cyber Security & GRC Engineer
Senior Cyber Security & GRC Engineer

Emergent Software • Hartford (CT)

On-site
USD 140,000 - 180,000
Senior Cyber Security & GRC Engineer
Senior Cyber Security & GRC Engineer

Emergent Software • Houston (TX)

On-site
USD 120,000 - 160,000
Senior Cyber Security & GRC Engineer
Senior Cyber Security & GRC Engineer

Emergent Staffing • Hartford (CT)

On-site
USD 130,000 - 180,000
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
Senior Information Technology Audit Manager
Senior Information Technology Audit Manager

Smith Arnold Partners • Connecticut

On-site
USD 120,000 - 160,000
Senior Cybersecurity Analyst / Information Security Manager - Top Secret Clearance
Senior Cybersecurity Analyst / Information Security Manager - Top Secret Clearance

Akima • Rockville (MD)

On-site
USD 150,000 - 190,000
Medical insurance
Dental insurance
Vision insurance
+3
Senior Project Manager (IT/Security) (Remote)
Senior Project Manager (IT/Security) (Remote)

Diversified Services Network, Inc. • McKnight and Bay (MA)

Hybrid
USD 90,000 - 120,000
Senior Project Manager (IT/Security) (Remote)
Senior Project Manager (IT/Security) (Remote)

Dsnworldwide • Springfield (IL)

Hybrid
USD 110,000 - 140,000
Senior Security Risk & Technical Assurance Analyst
Senior Security Risk & Technical Assurance Analyst

Gambit Technologies • New York (NY)

Hybrid
USD 140,000 - 200,000