Information Security Analyst
Role details
Job location
Tech stack
Job description
-
Security Research and Recommendations: Independently research and provide technical recommendations regarding information security policies, practices, system development, and architecture for both on-premise and public cloud infrastructure.
-
Security Tools and Resources Development: Work autonomously and collaboratively with team members to design, architect, develop, and continuously enhance information security tools and resources.
-
Security Requirements and Compliance: Collaborate with resource owners to determine and establish appropriate security requirements, policies, and practices; interpret and ensure compliance with existing policies and procedures.
-
Incident Investigation and Response: Investigate and respond appropriately to internal and/or external complaints (e.g., scanning, hacking, spamming, harassment, abuse, DMCA notices, and any other incidents that include a cyber element).
-
Forensic Analysis: Develop methodologies and perform forensic and other in-depth analyses of critical central systems for signs of unauthorized activity or abuse.
-
Threat Assessment and Action Planning: Exercise discretion and independent judgment to determine possible threats, assess potential severity, and develop appropriate action plans for addressing identified issues.
-
Staying Current on Security Trends: Stay up-to-date on the latest security techniques, tools, and evolving threats; contribute to periodic security briefings and updates for members of the campus community.
-
Other Duties: Perform other duties as assigned to support the organization's information security goals and objectives.
Requirements
Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field, or equivalent work experience.
- 3+ years of experience in information security, with a strong focus on security policy development, threat analysis, and incident response.
- In-depth knowledge of information security principles, best practices, and industry standards, such as NIST, ISO 27001, and CIS.
- Familiarity with both on-premise and public cloud security architectures, particularly in AWS or Azure.
- Experience with security tools and technologies, such as SIEM, IDS/IPS, firewalls, and vulnerability scanners.
- Strong analytical and problem-solving skills, with the ability to assess complex security issues and develop effective mitigation strategies.
- Excellent communication and collaboration skills, with the ability to work effectively with cross-functional teams and stakeholders.
- Ability to work independently and exercise sound judgment in high-pressure situations.
- Passion for staying current with the latest developments in information security and a commitment to continuous learning and improvement.
Certifications such as CISSP, CISM, or CompTIA Security+ are highly desirable.