Job Details

Position: Information Security Analyst (Ref: 14259)
Location: Atlanta, GA 30345 United States
Duration: 9 Months 12 Days - Contract
Openings: 1
Deadline: 09/29/2023
Pay Rate:Login

Description:

***Hybrid
***Local to Metro Atlanta
***Tax Clearance Letter required
***Copy of certifications are required

We are seeking an Information Security Analyst that performs advanced formation security analysis work. The work includes overseeing, planning, directing, implementing, and monitoring security measures.

Roles and responsibilities:
• Coordinates activities in Information Technology, specifically in Information Security.
• Develops and enforces the organization's security policies and procedures, security awareness program, the information security portion of the business continuity and disaster recovery plans, and all industry and compliance issues.
• Incorporates the design of and develops security procedures to allow the deployment, management, and updating of platform and user-specific security policies on a diverse range of internal hardware platforms supporting various software operating systems.
• Includes an additional focus on protecting data by performing threat and incident detection, and incident response.
• Works under minimal direct supervision and may supervise the work of others.
• Completes task designed to ensure security of the systems and information assets through confidentiality, integrity & availability.
• Implements confidentiality measures that protect against unauthorized access, modification, or destruction and helps to develop IT security policies and standards to support the security objectives.
• Develops and enforces the organization's security policies and procedures, security awareness program, the information security portion of the business continuity and disaster recovery plans, and all industry and government compliance issues.
• Works with end users to determine the need of individual divisions and offices within the department.
• Conducts Risk Management analysis to identify areas of risk and develop security measures to prevent loss and assist in the Mitigations of those risks.
• Participates in training, self-study, and statewide initiatives on security standards and best practices to serve as a valuable go-to security subject matter expert.
• Actively monitors the infrastructure and systems for security threats.
• Actively manage various security programs/platforms, monitors the use of data files, and regulates access to safeguard agency information in those computer files.
• Works with business owners, IT managers, Staff, and vendors to provide timely and efficient IT coordination of security services to meet business needs.
• Creates reports on status of information security programs and projects and communicates reports to senior management and the leadership teams.
• Develops, delivers, and maintains security standards, system security plans, best security and operations practices, architecture, and systems. Implement IT system security plans, projects, and other initiatives.
• Reports directly to the InfoSec Team on matters concerning the security status & posture. Assists in Information Security Investigations, Threat Assessments and Mitigations.
• Assists with numerous Information Security tools and programs.

Qualifications:
• Bachelor's degree in information technology, computer science, information assurance, or a related field from an accredited college or university AND Six years of information technology experience, Two years of which in information security or information assurance.
• Hands on working experience with at least two or more of these security technologies (e.g., Vulnerability Management, Penetration Testing, Email Security, EDR, MFA, SIEM, IPS, Firewalls).
• Possess one or more current industry certifications relevant to the job e.g., Security+, CISSP, CISM, C-RISC, CISA, SANS certifications.
• Experience with security tools and technology, i.e., FireEye (Trellix), Tenable.io, Nessus, Splunk, SolarWinds, Varonis, GRC tools, CrowdStrike Falcon, LogRhythm, and policies management.
• Knowledge & experience with cloud technologies: Amazon Web Services (AWS), to include WatchGuard, GuardDuty, Identity & Access Management (IAM), Microsoft Azure.
• Technical knowledge in endpoint security, VPN, Firewall, network monitoring, intrusion detection, web server security, and wireless security.
• Practical experience in systems administration, vulnerability management, endpoint management, and email security operations and management.
• Excellent analytical and critical thinking skills to identify possible threats.
• Familiarity with IRS Publication 1075, NIST SP 800-53 Privacy Controls, NIST SP 800-63 Digital Identity Guidelines, NIST SP 800-88 Guidelines for Media Sanitization, NIST SP 800-18 System Security Plans (SSP), NIST SP 800-52, FIPS-140, NIST SP 800-61, NIST SP 800-83, other NIST SP Guidelines, etc., knowledge of NIST Frameworks, FISMA, CIS Controls, and the Criminal Justice Information Services Policy.
• Progressive experience in information technology, incident response & incident reporting, technical support, cybersecurity, cryptography, and knowledge of data encryption techniques.
• Ability to work independently and prioritize multiple projects in a highly dynamic environment.
• Excellent communication and teamwork skills and demonstrated across a broad group of technical and non-technical stakeholders.
• Assist with Office of Information Security Risk Assessments, System Security Plans, and other reports required by the IRS Office of Safeguards, state audits, and other third-party assessors.

Certifications:
• MUST EMAIL REQUIRED CERTIFICATIONS (Possess one or more current industry certifications relevant to the job e.g., Security+, CISSP, CISM, C-RISC, CISA, SANS certifications).

Required / Desired Skills

  • Bachelor's degree in information technology, computer science, information assurance, or a related field from an accredited college or university (Required 4 Years)
  • Information technology experience (Required 6 Years)
  • Information security or information assurance experience (Required 2 Years)
  • Security+, CISSP, CISM, C-RISC, CISA, SANS certifications (Copy Required) (Required 1 Years)
  • Excellent analytical and critical thinking skills to identify possible threats. (Required 2 Years)
  • FireEye (Trellix), Tenable.io, Nessus, Splunk, SolarWinds, Varonis, GRC tools, CrowdStrike Falcon, and LogRhythm (Required 2 Years)
  • Amazon Web Services (AWS), to include WatchGuard, Guard Duty, Identity & Access Management (IAM), Microsoft Azure (Required 2 Years)
  • Technical knowledge in endpoint security, VPN, Firewall, network monitoring, intrusion detection, web server security, and wireless security (Required 2 Years)
  • Practical experience in systems administration, vulnerability management, endpoint management, and email security operations and management (Required 2 Years)
  • Ability to work independently and prioritize multiple projects in a highly dynamic environment. (Required 2 Years)
  • Knowledge of NIST Frameworks, FISMA, CIS Controls, and the Criminal Justice Information Services Policy (Highly Desired 1 Years)
  • Experience in incident response & incident reporting, technical support, cybersecurity, cryptography, and knowledge of data encryption techniques (Highly Desired 1 Years)
  • Knowledge and experience in Policies and procedures development, revision and management. (Highly Desired 1 Years)

copyright @ www.ProfessionalTechIntegration.com.2011 All rights reserved
Professional Tech Integration, Inc., Computers  Sys Designers & Consult, Norcross, GA