Senior IS Security Risk Analyst

at Globalpundits Inc
Published May 4, 2022
Location Columbia, SC
Category Default  
Job Type Full-time  


Schedule Notes Cloud Security Engineer to lead Vulnerability Management, Remediation, Audit and Compliance of Infrastructure and Applications. Experience with interpreting DISA STIGS and managing Security Vulnerabilities and Audits Knowledge and Experience with Cloud Security Best practices and standards such as NIST Framework. AWS Certified Security Specialty. Knowledge of TCPIP Network Protocols ,Web Application Security Vulnerabilities and performing Security Penetration testing. Skills AWS Certified Security certification .Certified Information Systems Security Professional (CISSP)Certified Cloud Security Professional (CCSP) are a plus, TCPIP Network Protocols, NIST framework, DISA STIGS (Security Technical Implementation Guides) Assists in determining if AWS tools and Cloud provided services meet the ARS standards. Duties Develop strategies and approaches for business development proposals within a compliance and systems security context. Plan and perform compliance and systems security activities in alignment with contractual role. Communicate and escalate compliance and risk issues to the appropriate customer representative andor level of management. Act as a change agent to influence IS and corporate compliance culture in alignment with business constituency. Develop strong systems security customer business relationship. Provide expert level consultation regards contractual system security obligations, frameworks, control requirements. 20 Oversee remediation of new and outstanding issues, including Information Security Risk Exception process, across multiple business areas and security frameworks. Utilize tools to track and report on compliance posture. 20 Conduct or lead others in the procedural and operational review of internal IS security compliance standards. Oversee formal risk analysis and self-assessments to determine effectiveness of controls and ensure creation of action plans to remediate identified risks. Identify and champion efficiency improvements related to security, risk and compliance processes. Engage appropriate Client Management areas to facilitate process improvements through formal IS Methodology. 20 Lead the development, implementation and documentation of Information Security policies, procedures, processes and programs to guide IS toward continuous compliance. May conduct or lead others in the analysis and interpretation of security regulations and controls. Proactively provide strategic consulting to IS functional teams with the development, implementation, monitoring, and reporting of control processes, documentation and compliance routines for moderate to highly complex work efforts. 20 Serve as an interface with external entities for governance and compliance reviews regarding information security risk. 10 Conduct or lead others in the investigation, documentation and resolution of Information Security Incidents. Advises senior management of critical issues that may affect organization. 10 Research emerging security topics, threats and capabilities to createupdate policy and governance. Engage appropriate leaders to evaluate and mitigate potential exposure. Promote organizational security awareness by developing security training, Security Council bulletins, security policies, standards and best practices, as well as delivering training to personnel Skills Required Skills and Abilities Complete understanding of systems security business life cycle methodologies. Subject Matter Expert in both government and private risk frameworks and control implementations. Comprehensive understanding of business system security risk management, information system security and compliance practices. Demonstrate excellent analytical, problem solving, decision-making skills, interpersonal and ownership skills. Proven ability to interpret and apply knowledge of regulatoryaccreditation requirements. Ability to lead others in solving problems often spanning multiple environments and business areas. Ability to effect change and bring security, risk and compliance knowledge to the organization through the use of positive influence. Understanding of infrastructure and networking architecture WANs, LANs, Internet, intranets and communication protocols. Excellent communication skills in presenting results to customer, senior management, and matrix staff both verbally and in writing. Demonstrated ability to develop metrics, perform critical analysis and develop executive decision support content. Possess excellent collaboration skills with a wide variety of internal matrix and management staff. Required Software and Tools Standard office equipment. Preferred Licenses and Certificates ISC2 Certified Information Systems Security Professional (CISSP). Education Required Education Bachelor's Degree in Computer Science, Information Technology or related degree. or 4 years of job related work experience or 2 years of job related experience plus an associatersquos degree in Computer Science, Information Technology or other job related degree. Required Work Experience 8 years of IT experience including 6 years of IT security, risk assessment andor compliance experience. Successful completion of BCBSSC IS Entry Level Training Program (ELTP) may be substituted for 2 years of IT experience Certifications Licenses CISSP Certified Information Systems Security Professional Required Skills CYBER SECURITY CISSP RISK ASSESSMENT INFORMATION SECURITY Additional Skills EXCELLENT COMMUNICATION SKILLS LIFE CYCLE METRICS NETWORKING PROBLEM SOLVING PROCESS IMPROVEMENTS REMEDIATION RISK ANALYSIS RISK MANAGEMENT SECURITY SUBJECT MATTER EXPERT SYSTEM SECURITY SYSTEMS SECURITY TRAINING BUSINESS DEVELOPMENT CHANGE AGENT DOCUMENTATION GOVERNANCE PROPOSALS SECURITY POLICIES TRADING

Drop files here browse files ...