Senior Information Security Analyst

Accede Solutions Inc
United States
18 days ago
Apply on www2.jobdiva.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Cyber Security Databases Federal Information Processing Standards (FIPS) Software Engineering Software Vulnerability Management Information Technology Cybercrime

Job description

· Develop and implement security standards, policies, and procedures to safeguard resources ensuring compliance with HIPAA, NIST, FedRAMP, and/or HITRUST requirements. · Evaluate security and privacy risks by balancing business drivers, best practices, and external drivers. Provide proactive solutions or recommendations through collaboration across business units. · Security Operations and Vulnerability Management · Support vulnerability management activities. Validate creation, documentation, and completion of Plans of Action and Milestones (POA&Ms) · Lead computer security incident response efforts including but not limited to preparing executive summaries, recommending mitigation strategies, and tracking remediation efforts. · Facilitate BCP/DR planning including coordination of documentation and testing. · Lead the creation and ensure the ongoing maintenance of documentation for multiple systems including but not limited to risk assessments, privacy impact assessments, and security plans. Validate compliance of documentation with government and industry standards. · Maintain accurate and up-to-date documentation of incidents, tickets, vulnerabilities, and compliance activities. · Work closely with Federal contract teams to ensure implementation of security controls and best practices as required by the contract. · Stay current with industry trends, emerging threats, security technologies, and pertinent regulations. · Provide guidance and mentorship to junior members of the security team. · Be timely with response, use professional communication, and approach vulnerability and risk management from the perspective of business enablement.

Requirements

As a Senior Information Security Analyst, you will be a key member of our security team, responsible for safeguarding our organization’s systems and data from cyber threats. Your primary focus will be assessing security risks, developing and implementing security measures, and ensuring compliance with regulations, contractual requirements, and established policies and standards. You will play a crucial role in supporting our Federal business teams and must have an understanding of FedRAMP, NIST 800-53, HIPAA, and/or FIPS. This role requires expertise in cybersecurity practices, excellent analytical skills, and the ability to collaborate effectively with cross-functional teams. Our preferred candidate will have experience with one or more Federal agencies including CMS, HHS, or HRSA., · 5-7 years of work experience in IT in one or more areas of infrastructure, application development, database, and systems management · 3 or more years of experience must be in an information security role with demonstrated working knowledge of information security, federal and state rules and regulations, company/business unit operations, compliance policies, procedures, and/or programs in the area of assignment · 2-year degree in Information Technology, Information Security, or related field and/or equivalent training and/or experience. · Bachelor’s degree in Computer Science, MIS, Information Assurance, or a related field is preferred · Experience working with FedRAMP, NIST 800-53, HIPAA, and/or FIPS · Industry-standard certification (CISSP, SSCP, GSNA, or CISA) is preferred. · Experience with NIST, ISO, and HIPAA requirements/guidance is highly desirable.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www2.jobdiva.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

4:01 min

Managing application isolation via pluggable database models

Wei Hu Wei Hu · World Congress 2022

2:03 min

Platform compliance and security certifications for sensitive data

Chad Carlson · World Congress 2021

Videos

See all

Related articles

See all