Colony Brands, Inc. · 4 days ago
IT SECURITY ANALYST (ONSITE)
Colony Brands, Inc. is one of the world’s largest and most successful direct marketing catalog and e-Commerce companies. They are seeking an IT Security Analyst to promote and execute their information security programs, policies, and regulatory compliance. The role involves developing and implementing a comprehensive information security program and working closely with IT to select and deploy technical controls to meet security requirements.
ConsumerHealth Care
Responsibilities
Defining and promoting the information security policies, processes, and standards by designing technologies in a secure manner, monitoring compliance against company policies, applicable law(s), investigating and reporting of security violations and incidents
Reporting and advising on information security issues to ensure internal security controls are appropriate and operating as intended
Analyzing information and processes to balance normal vulnerability levels with investment, personnel and end-user capabilities
Serving as a subject matter expert to the business and providing security guidance
Partnering with Project Teams to facilitate and implement new systems, policies, and processes
Partnering with Managed service SOC to coordinate centralized logging and identification of security incidents or misconfigured security controls
Coordinating/conducting responses to information security incidents (ability to begin forensic investigation as part of the Incident Response process)
Preparing documentation, business notifications, and security alerts
Daily interaction with our employees while managing security alerts from EDR (Endpoint Detection & Response), SIEM (Security Incident & Event Management), Vulnerability Management, Phishing identification tools, and general service tickets
Researching, recommending, and developing security and risk mitigation solutions
Qualification
Required
Bachelor's degree in MIS, Computer Sciences, Information Technology or related discipline with related business experience
Significant technical knowledge around information security engineering and policy/procedures
Ability to utilize security systems such as endpoint detection & response tools, vulnerability scanners, logging software, Multi Factor Authentication, SAML Federation, email filtering, and experience with patch management processes
Experience with diverse desktop and server environments, networking, artificial intelligence solutions, and operational security technologies both on premise and in the Cloud
Solid written and verbal communication skills at all comprehension levels
Preferred
A Broad and in-depth understanding of information security and information technology auditing
A commitment to continuous improvement and knowledge growth; this role requires someone who will stay current with security technologies
Security+ Certification
Experience working with small to mid-size companies
PCI, SOC1, Audit &/or HIPAA experience