Security Awareness Analyst / GRC Analyst

DevCare Solutions
Harrisburg, PA, United States
26 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$62,400.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Active Directory Amazon Web Services Apple Mac Systems Microsoft Azure Border Gateway Protocol Ubuntu (Operating System) CentOS Cisco PIX Cisco Routers Cloud Computing Security Cloud Engineering
+37 more
Control Objectives for Information and Related Technology (COBIT) Cyber Security Computer Networks Dynamic Host Configuration Protocol Linux Domain Name System (DNS) Information Security Management IT Management Internet Protocol Security (IP SEC) Intrusion Detection Systems Virtual Private Networks (VPN) Network Security Lightweight Directory Access Protocols (LDAP) Log Analysis Routing Network Protocols Open Shortest Path First (OSPF) PCI Data Security Standards Role-Based Access Control Phishing Security Software Security Information and Event Management Single Sign-On TCP/IP Software Vulnerability Management Wide Area Networks EndPointSecurity Identity Services Engine Google Cloud Load Balancing Firewalls (Computer Science) Information Technology SolarWinds (Software) Network Support Cybercrime Splunk Vulnerability Analysis

Job description

Join our dynamic cybersecurity team as a Security Awareness Analyst / Cybersecurity GRC (Governance, Risk, and Compliance) Analyst! In this vital role, you will champion the development and implementation of security awareness programs while ensuring our organization’s compliance with industry standards such as ISO 27001, ISO 27000 series, and NIST frameworks. Your energetic approach will help foster a security-conscious culture across all levels of the organization, empowering teams to recognize and mitigate cyber threats proactively. This position offers an exciting opportunity to blend security education with rigorous risk management, making a tangible impact on our cybersecurity posture., * Design, execute, and continuously improve security awareness campaigns to educate employees on cybersecurity best practices, including topics like phishing prevention, password hygiene, and data protection.

  • Conduct comprehensive security risk assessments and vulnerability management activities to identify potential threats within IT infrastructure, including network security components such as LAN, WAN, firewalls, IDS (Intrusion Detection Systems), and SIEM (Security Information and Event Management) tools.
  • Support the development and maintenance of system security plans aligned with standards like ISO 27001 and FedRAMP; ensure compliance with information security policies and regulations such as PCI DSS and FISMA.
  • Perform security assessments and vulnerability research using tools like vulnerability scanners, SIEM analysis, and threat intelligence platforms to detect anomalies or potential breaches.
  • Collaborate with network engineering teams to implement secure network architectures utilizing routing protocols (OSPF, BGP), VPNs (Virtual Private Networks), IPsec encryption, load balancing, and cloud security engineering in environments such as AWS or Google Cloud Platform.
  • Assist in incident response activities by investigating security events, analyzing logs via tools like Splunk or SolarWinds, and supporting incident recovery efforts following cybersecurity incidents.
  • Maintain documentation related to system hardening procedures, security event management processes, and compliance audits; prepare reports for executive leadership on risk posture and remediation strategies.

Requirements

  • Proven experience working within cybersecurity frameworks such as NIST standards or COBIT; familiarity with IT governance practices is highly valued.
  • Hands-on knowledge of computer networking concepts including LAN/WAN architecture, Cisco routers/switches (Cisco ASA, Cisco ISE), network protocols (TCP/IP, DNS, DHCP), and network support tools.
  • Demonstrated expertise in information security compliance efforts related to ISO 27001/ISO 27000 series standards; experience with system hardening techniques on operating systems like Windows, Linux (Ubuntu, CentOS), macOS or BSD is preferred.
  • Practical experience utilizing cybersecurity tools such as SIEM platforms (Splunk), endpoint detection & response (EDR) solutions, vulnerability assessment tools, and threat detection & response methodologies.
  • Strong understanding of identity & access management concepts including RBAC (Role-Based Access Control), LDAP/Active Directory integration, SSO (Single Sign-On), and encryption technologies.
  • Knowledge of cloud infrastructure security principles for platforms like AWS or Azure; familiarity with cloud architecture best practices is a plus.
  • Excellent analytical skills in conducting security risk assessments investigation; ability to interpret complex data from intrusion detection systems or log analysis tools for actionable insights.

Join us to be at the forefront of cybersecurity awareness and governance! Your expertise will help shape a resilient organization that values proactive defense strategies while fostering a culture of continuous learning and improvement in information security practices.

Benefits & conditions

Pulled from the full job description

  • Health insurance
  • Paid time off
  • Vision insurance
  • Dental insurance, * Dental insurance
  • Health insurance
  • Paid time off
  • Vision insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

3:50 min

Queues in TCP stacks and continuous network connections

Clemens Vasters Clemens Vasters · World Congress 2022

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all