Information Security Analyst/Administrator jobs in United States
info-icon
This job has closed.
company-logo

Diversity Nexus ยท 6 hours ago

Information Security Analyst/Administrator

Diversity Nexus is seeking an Information Security Analyst/Administrator for a long-term contract opportunity. The role involves supporting the execution and administration of the Vulnerability Management function within Information Security, focusing on vulnerability assessments, penetration testing, and remediation efforts to minimize potential attack surfaces.

Staffing & Recruiting
badNo H1BnoteU.S. Citizen Onlynote

Responsibilities

Monitor and analyze vulnerability assessment data to identify and communicate technical risks to the organization
Support the identification and impact classification for new vulnerabilities identified in the environment
Execute and support vulnerability assessments, penetration testing and social engineering activities
Provide the Information Security and IT Security team information on the emerging cyber threat landscape, including threat actor tactics, techniques, and procedures
Review and interpret application security scan results with an understanding of underlying code structures to provide effective feedback
Provide post-development testing support to ensure vulnerability remediation items are validated and tested appropriately
Facilitate vulnerability management processes by tracking and coordinating remediation efforts across multiple teams
Ensure timely closure of security gaps by working with application, infrastructure, and operations teams
Support IS in achieving the vision and strategic objectives of the vulnerability program
Conduct analysis, aggregate and report on vulnerability data from various scanning tools and platforms
Manage and utilize IS tools such as DLP, Code scanner, external security profile, etc. to analyze gaps in security controls
Participate in the IT SDLC program to ensure that security is included in project by default and by design
Develop strong working relationships with other departments and potentially clients across the organization to ensure a high degree of security compliance client satisfaction
Assist with regulatory and compliance requirements, contributing to security audits, assessments, attestations, certifications and client vulnerability inquires
Brief IS leadership on vulnerability assessment results and potential risks
Support leadership to identify capability gaps in vulnerability management services
Collaborate with cross-functional teams to improve security posture and embed security into existing IT and operational workflows
Continue self-development of knowledge, skills and abilities to better support execution of the Information Security (IS) function

Qualification

Vulnerability ManagementPenetration TestingCompliance FrameworksApplication SecuritySecurity AuditsProject ManagementAnalytical SkillsVerbal CommunicationWritten CommunicationProblem-SolvingCollaboration

Required

Bachelor's degree computer science, IT or equivalent
3+ years of experience in IT or IS or Compliance
Experience with major standards such as: SOC 1-2, ISO 27001/2, PCI DSS, HITRUST, SANS, NIST
Demonstrated experience in implementing compliance frameworks for financial services organization or organizations with similar information security needs and requirements
Familiarity and understanding of broad range of IT hardware and software products
Strong project management skills
Excellent presentation, verbal communication, and written skills
Excellent analytical and problem-solving skills
Experience managing typical enterprise security and intrusion detection systems
Ability to work in a collaborative environment across business and technology teams
Ability to interpret application structures and code approaches at a high level in order to review and respond to scan results

Preferred

Certified Information Systems Security Profession (CISSP), PCI DSS, Certified HIPAA Privacy Security Expert (CHPSE), Certified Information Security manager (CISM), Global Information Assurance Certification (GIAC), or related
Experience or knowledge with healthcare or health insurance
Knowledge of CMS and HIPAA related vendor requirements
Working knowledge of Security SDLC tools

Company

Diversity Nexus

twitter
company-logo

Funding

Current Stage
Growth Stage
Company data provided by crunchbase