drjobs CL - Security Analyst - Project Lead العربية

CL - Security Analyst - Project Lead

Employer Active

The job posting is outdated and position may be filled
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

others - USA

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Job Description


Job Description: Suppliers:
CANDIDATES SUBMITTED THAT DO NOT HAVE A COMBINATION OF HANDS ON EXPERTISE ADMINISTERING SECURITY DEVICES AND EXPERTISE IN SECURITY ARCHITECTURE.
CANDIDATES WITH JUST SECURITY AUDITING AND COMPLIANCE EXPERIENCE.
RESUMES ARE TOO LONG AND VAGUE. PLEASE KEEP RESUMES TO A MAXIMUM OF 2 PAGES.

SCOPE OF THE PROJECT:
EVALUATES EXISTING AND PLANNED TECHNOLOGY ENVIRONMENTS OF THE AGENCY, VENDORS AND OTHER PARTNERS, FOR COMPLIANCE WITH INFORMATION SECURITY POLICIES AND STANDARDS. RECOMMENDS INFORMATION SECURITY MEASURES AND PRACTICES, IN CONTEXT OF THE AGENCY'S BUSINESS GOALS, TO SAFEGUARD INFORMATION ASSETS IN ACCORDANCE WITH APPLICABLE FEDERAL, STATE, AGENCY AND INDUSTRY POLICIES, STANDARDS AND BEST-PRACTICES. PARTICIPATES IN REVIEWS AND UPDATES OF SECURITY POLICIES, STANDARDS, PROCEDURES; AND OF THE EMPLOYEE SECURITY AWARENESS PROGRAM. CONTRIBUTES TO CREATION AND MAINTENANCE OF SECURITY COMMUNICATIONS, INFORMATION SHARING AND OTHER DOCUMENTATION NECESSARY TO PERFORM THE FUNCTIONS OF THE CISO DIVISION OF THE AGENCY.

KNOWLEDGE OF SECURITY ADMINISTRATION IN ONE OR MORE OF THE FOLLOWING AREAS OF TECHNOLOGY: NETWORK DEVICES, WORKSTATIONS, SERVERS, STORAGE TECHNOLOGY, SECURITY INSTRUMENTATION. ABILITY TO WRITE DETAILED SECURITY DOCUMENTATION ON TECHNICAL SECURITY ASSESSMENTS, POLICIES AND PROCEDURES. ANALYTICAL AND PROBLEM SOLVING SKILLS. KNOWLEDGE AND UNDERSTANDING OF INFORMATION RISKS CONCEPTS AND PRINCIPLES AS A MEANS OF RELATING BUSINESS NEEDS AND SECURITY CONTROLS. ABILITY TO COMMUNICATE WITH AUDIENCES WITH VARYING LEVELS OF TECHNICAL KNOWLEDGE. ABILITY TO ESTABLISH AND MAINTAIN EFFECTIVE WORKING RELATIONSHIPS TO EFFECTIVELY PERFORM JOB DUTIES THAT BY THEIR NATURE CREATE TENSION. KNOWLEDGE OF PROJECT MANAGEMENT.

SECURITY REVIEWS AND ENGINEERING LEADS THE EVALUATION OF NEW INFORMATION TECHNOLOGY PROJECTS AND PROPOSED CHANGES TO EXISTING TECHNOLOGY FOR COMPLIANCE WITH SECURITY POLICIES AND STANDARDS. WORKS WITH THE ARCHITECTURE AND INFRASTRUCTURE TEAMS ON THE DESIGN, ENGINEERING, AND IMPLEMENTATION OF TECHNOLOGY SOLUTIONS TO ENSURE SECURE EMPLOYMENT. PROVIDES EXPERTISE TO AND COLLABORATES WITH PROJECT STAKEHOLDERS TO MAKE RECOMMENDATIONS THAT HELP ACHIEVE BUSINESS AND FUNCTIONAL GOALS, WHILE MEETING SECURITY REQUIREMENTS. MANAGES SECURITY REVIEWS IN ACCORDANCE WITH ESTABLISHED IT AND SECURITY PROCESSES.

PERIODIC/CYCLICAL COMPLIANCE ASSESSMENTS - APPROVES SECURITY PLANS WITH THE CISO AND LEADS PERIODIC/CYCLICAL SECURITY ASSESSMENTS AND RISK ASSESSMENTS OF THE AGENCY, VENDORS, AND OTHER PARTNERS IN ACCORDANCE WITH SECURITY POLICIES AND STANDARDS, IN A MANNER THAT PROVIDES AN ACCURATE REPRESENTATION OF THE SECURITY POSTURE OF THE ENTITY BEING EVALUATED. CREATES PLANS, ASSESSMENTS, REVIEWS AND RESULTS IN THE FORM OF SYSTEM SECURITY PLANS, SYSTEM SECURITY ASSESSMENTS, RISK ASSESSMENTS, SUBJECT MATTER REVIEWS, FINDINGS, AUTHORIZATIONS-TO-OPERATE AND OTHER DOCUMENTATION SPECIFIED BY POLICIES AND PROCEDURES. CONTRIBUTES TO AND CRITIQUES DOCUMENTATION THAT IS REQUIRED TO BE SUBMITTED TO EXTERNAL AUTHORITIES, INCLUDING IRS, PCI, DSS AND STATE AUTHORITIES. PERFORMS ASSESSMENTS IN ACCORDANCE WITH ESTABLISHED SCHEDULE GOALS AND REQUIREMENTS.

SECURITY PROCESS ADMINISTRATION AUTHORS AND UPDATES GOVERNANCE, COMMUNICATION METHODS AND ARTIFACTS NECESSARY TO PERFORM THE FUNCTIONS OF THE CISO DIVISION OF THE AGENCY INCLUDING, BRIDGE DIAGRAMS, REPORTS, METRICS, POLICIES, PROCEDURES, SHAREPOINT SITES, SHARED DRIVES, ETC.

SECURITY PROGRAM UPDATES -- ANALYSES AND PROPOSES UPDATES TO INFORMATION SECURITY GOVERNANCE AND THE SC DOR INFORMATION SECURITY AWARENESS PROGRAM. MAINTAINS EXPERT LEVEL KNOWLEDGE CURRENT WITH CHANGES TO EXTERNAL REQUIREMENTS SUCH AS IRS, PCI DSS, STATE POLICIES AND INDUSTRY BEST-PRACTICES. RECOMMENDS AREAS IN WHICH NEW AND ADDITIONAL INFORMATION SECURITY GOVERNANCE IS NEEDED. WRITES, CONTRIBUTES TO WRITING, AND UPDATES SECURITY PLANS, POLICIES, AND PROCEDURES.

REQUIRED SKILLS (RANK IN ORDER OF IMPORTANCE):
STRONG COMMUNICATION (WRITTEN AND VERBAL) AND TEAMWORK SKILLS

HANDS-ON TECHNICAL IT AND/OR SECURITY SYSTEM ADMINISTRATION EXPERIENCE

DEMONSTRATED ABILITY TO LEARN AND ADMINISTER NEW SYSTEMS

RISK AND VULNERABILITY ASSESSMENTS

EXPERIENCE INSTALLING AND USING VARIOUS SECURITY TOOLS

INFORMATION SECURITY PRINCIPLES AND PRACTICES

ABILITY TO ANALYZE AND TEST NEW SOLUTIONS FOR SECURITY REQUIREMENTS

THE ABILITY DOCUMENT DESIGNS, AND WRITE PROCEDURES

IT SECURITY

APPLICATION SECURITY

PREFERRED SKILLS (RANK IN ORDER OF IMPORTANCE):
EXPERIENCE WITH SIEM TECHNOLOGY

ENDPOINT SECURITY EXPERIENCE

EXPERIENCE WITH SCSEMS AND KNOWLEDGE OF IRS PUB 10NA CONTROLS

EXPERIENCE WITH NESSUS

EXPERIENCE IN PROJECTS INVOLVING PCI/NIST SECURITY IMPLEMENTATIONS AND/OR AUDITS

NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY CONTROLS

REQUIRED EDUCATION/CERTIFICATIONS:
BACHELOR DEGREE IN TECHNOLOGY FIELD
Additional Sills: REQUIRED SKILLS (RANK IN ORDER OF IMPORTANCE):STRONG COMMUNICATION (written and vernal) AND TEAMWORK SKILLSHANDS-ON TECHNICAL IT AND/OR SECURITY SYSTEM ADMINISTRATION EXPERIENCEDEMONSTRATED ABILITY TO LEARN AND ADMINISTER NEW SYSTEMSRISK AND VULNERABILITY ASSESSMENTSEXPERIENCE INSTALLING AND USING VARIOUS SECURITY TOOLSINFORMATION SECURITY PRINCIPLES AND PRACTICESABILITY TO ANALYZE AND TEST NEW SOLUTIONS FOR SECURITY REQUIREMENTSTHE ABILITY DOCUMENT DESIGNS, AND WRITE PROCEDURESIT SECURITYAPPLICATION SECURITYPREFERRED SKILLS (RANK IN ORDER OF IMPORTANCE):EXPERIENCE WITH SIEM TECHNOLOGYENDPOINT SECURITY EXPERIENCEEXPERIENCE WITH SCSEMS AND KNOWLEDGE OF IRS PUB 10NA CONTROLSEXPERIENCE WITH NESSUSEXPERIENCE IN PROJECTS INVOLVING PCI/NIST SECURITY IMPLEMENTATIONS AND/OR AUDITSNATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY CONTROLS Skills:
Category
Name
Required
Importance
Level
Last Used
Experience
Miscellaneous NESSUS Yes 1 Advanced Currently Using 2 - 4 Years Network Security IT Security Yes 1 Advanced Currently Using 2 - 4 Years Network Security Security Information Event Management (SIEM) systems development / configuration Yes 1 Advanced Currently Using 2 - 4 Years

Employment Type

Full Time

Company Industry

About Company

100 employees
Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.