Information Security Analyst

DISTRO, LLC
Stamford, United States of America
30 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior
Compensation
$ 146K

Job location

Stamford, United States of America

Tech stack

Amazon Web Services (AWS)
Azure
Cloud Computing Security
Computer Security
Intrusion Detection Systems
Zero Trust Network Access
Security Information and Event Management
Firewalls (Computer Science)

Requirements

Do you have experience in SIEM?, Key Responsibilities Develop and maintain information security policies, standards, and procedures Maintain IT risk taxonomy, risk register, and control inventory Align security program with NIST, FISMA, FedRAMP, ISO 27001, CIS Controls Lead Technology Risk and RCSA processes Conduct risk assessments, vulnerability scans, SOC testing, and audits Support audits, compliance reviews, POA&M tracking Monitor and respond to security events; lead incident containment/remediation Maintain SIEM, IDS/IPS, DLP, and endpoint protection tools Manage threat intelligence processes Advise leadership on cybersecurity risks and trends Provide security awareness training and executive-ready communications Required Deliverables IT Risk Taxonomy (NIST RMF aligned) Enterprise IT Risk Register Risk Assessment Methodologies SOC Testing Framework & RCSA Model Threat Intelligence Process Documentation Compliance & remediation tracking Minimum Qualifications 8-10 years in Information Security, Risk Management, or IT Security Operations Experience developing enterprise security programs in regulated environments Expertise with: SIEM, IDS/IPS, Firewalls, Endpoint tools, Vulnerability platforms Knowledge of Zero Trust architecture Understanding of NIST CSF 2.0, NIST RMF, ISO 27001, CIS Controls Cloud security experience (AWS, Azure, GovCloud) Strong analytical, investigative, and communication skills Preferred Qualifications Experience in municipal, state, or federal environments Certifications: CISSP, CISM, CRISC, CEH, GIAC Experience with POA&M remediation and compliance reporting Core Competencies Enterprise Risk Management Security Governance & Compliance SOC & Control Testing Incident Response Threat Intelligence Zero Trust Architecture Cross-Functional Collaboration

Apply for this position