Information Security Analyst

Highspring Consulting Holdings, LLC
Nashville, TN, United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$80,000.0 - $100,000.0
Working hours
Regular working hours

Tech stack

Antivirus Softwares Microsoft Azure Cloud Computing CompTIA Security+ Cyber Security Computer Networks Internet Security Intrusion Detection and Prevention Intrusion Detection Systems Information Systems Security Architecture Professional Security Information and Event Management Software Vulnerability Management
+4 more
Malware Information Technology Patch Management Vulnerability Analysis

Job description

The Information Security Analyst is responsible for the defining, planning, and monitoring of security measures for the protection of computer systems and information assets. This individual will also be responsible for monitoring and analyzing security measures implemented in Highspring’s infrastructure, as well as assist in the development and enforcement of information security policies. This is a fast-paced environment. Candidates should thrive in an environment with high volumes of work, managing multiple projects/assignments at a time, and working in a highly collaborative atmosphere., The following duties are normal for this job. These are not to be construed as exclusive or all-inclusive. Other duties may be required and assigned.

  • Defines, maintains, and reports on overall computer network security strategies (Best Practices/Common Practices) with all information assets connected to the Highspring network. Must have the ability to communicate security policies and strategies to people of varying technical ability both verbally and in written format.
  • Monitors and provides reports on, intrusion detection and protection systems.
  • Monitors and reports on device security systems such as anti-virus, anti-ransomware, patch management, and vulnerability assessment tools providing appropriate coordination for response efforts maintaining SLAs.
  • Monitors operation of, and provides reports on, security information and event management (SIEM) systems. Must have the ability to examine a variety of data sources to correlate events and determine courses of action.
  • Support the organization’s third-party management program by maintaining current vendor profiles, facilitating vendor security assessments, reviewing compliance and security documentation, and assisting internal stakeholders as well as clients with vendor risk and remediation activities.
  • Participates in the incident response process when incidents are declared and supports post-incident activities.
  • Manages relationships and coordinates operational activities between Highspring and external security services providers (e.g., Managed Security Services Providers (MSSP), Penetration Testers, etc.).
  • Leads the Information Security awareness training program with focused training and simulated social engineering campaigns.
  • Creates and publishes periodic information security assurance risk posture reports as requested/required.

Requirements

  • Knowledge of SIEM systems
  • Knowledge of MS Azure cloud platforms
  • Knowledge of Email Security Appliances (ESA), Checkpoint, Mimecast, Proofpoint, etc.
  • Knowledge of Information Security standards and frameworks (International Organization for Standardization 27000 series, National Institute of Standards and Technology, and Center for Internet Security (CIS) controls)
  • Knowledge of a variety of vulnerability management solutions
  • Strong verbal, written and presentation skills.
  • Knowledge of Intrusion Detection Systems/Intrusion Protection Systems
  • Experience in Privacy a plus.
  • Experience in AI governance, configuration and assessments, a plus, * Bachelor’s degree in computer science, Information Technology or Information Security (Cybersecurity) preferred
  • At least two (2) years of experience in Information Security preferred.
  • One of the following certifications is required: CompTIA Security+; GIAC security certifications and/or Certified Ethical Hacker (CEH); Certified Information Systems Security Professional (CISSP).

Benefits & conditions

Determining compensation for this role (and others) at Highspring depends upon a wide array of factors including but not limited to the individual’s skill sets, experience and training, licensure and certifications, office location and other geographic considerations, as well as other business and organizational needs. With that said, as required by local law, Highspring believes that the following salary range reasonably estimates the base compensation for an individual hired into this position in geographies that require salary range disclosure to be between the range below. The individual may also be eligible for a variety of bonus and financial incentives based on individual and company performance. Base Compensation Range $80,000-$100,000 USD MorganFranklin is an Affirmative Action and Equal Opportunity Employer and will not discriminate in employment on the basis of race, color, religion, sex, sexual orientation, gender identity, age, national origin, veteran status, physical impairment, political affiliation, marital status, disability, or on any other basis prohibited by law.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on localjobnetwork.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

1:06 min

Outline of free tools for Microsoft Azure

Radu Vunvulea Radu Vunvulea · WWC 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

6:18 min

Architecting asynchronous malware scanning for uploaded file contents

Austin Gil · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

Videos

See all

Related articles

See all