Information Security Analyst

Inc. (rms)
United States
7 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Microsoft Azure Cloud Computing Cloud Computing Security Configuration Management Databases Cyber Security Identity and Access Management Microsoft Office Azure Active Directory SonarQube Software Vulnerability Management ServiceNow IT Service Management
+8 more
Microsoft Power Automate Archer IRM Practical Use Cases Information Technology Microsoft Sentinel CIS Benchmarks Splunk Devsecops Qualys

Job description

Lead vulnerability management, prioritization, remediation tracking, and reporting Reduce vulnerability aging, backlog, and overall security exposure Monitor and report exposure to CISA Known Exploited Vulnerabilities (KEV) Support security risk governance, exceptions, risk acceptance, and compensating controls Evaluate security controls across cloud, identity, endpoint, data, and application environments Support security architecture, threat modeling, DevSecOps, IAM/PAM, and third-party risk reviews Provide audit, compliance, regulatory, and due diligence support Build security dashboards, metrics, executive summaries, and risk reports

Must-Have / Preferred Technical Skills Microsoft Defender: Endpoint, Identity, Office 365, Cloud Microsoft Sentinel & Microsoft Purview Microsoft Entra ID Qualys ServiceNow: ITSM, CMDB, IRM, Vulnerability Response Azure strong experience AWS working knowledge Splunk SonarQube Power BI & Power Automate Vulnerability Management / DLP / Cloud Security CIS Controls & SOC 2, Timely vulnerability remediation | Reduction of vulnerability aging & backlog | Overall vulnerability reduction | CISA KEV exposure monitoring | Security risk metrics & reporting | Audit readiness | Control effectiveness

Requirements

7 12 years of progressive Information Security experience Strong background in vulnerability management, security operations, cloud security, GRC, compliance, and audit support Bachelor s degree in Cybersecurity, IT, Computer Science, or related field preferred CISSP, CCSP, SSCP, GCED or similar certifications are a plus

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

52 sec

Defining application, pipeline, and security operations roles

Aarno Aukia · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

Videos

See all

Related articles

See all