IT Security Specialist

OpTech LLC
United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Regular working hours
Job source

Tech stack

Control Objectives for Information and Related Technology (COBIT) Cyber Security Databases Information Technology Audit Information Technology Operations Information Systems Security Architecture Professional Smartsuite IT General Controls (ITGC) Information Technology

Job description

The Security Analyst will be responsible for assisting in the responsibilities of executing the security framework compliance/governance activities and requirements. Day-to-day responsibilities will also include documenting adherence to governance requirements across policies/standards, procedures, controls, compliance, training and awareness, and preparing metrics/KPIs and reporting materials.

  • Evaluate the design and operation effectiveness of Business/IT operations against the HITRUST CSF and identify areas of improvement
  • Interview SMEs, examine evidence documentation, analyze and perform testing
  • Learn the company functions/processes by conducting process walk throughs
  • Analyze root cause of issues, provide recommendations for process improvements and risk mitigation based on assessment findings
  • Collaborate with cross-functional teams to mitigate risks and ensure compliance with HITRUST CSF
  • Deliver effective and concise documentation that meets HITRUST quality standards
  • Prepare and provide reporting such as dashboards and metrics, on various areas of performance, issue analysis and assessment statuses
  • Utilize GRC tools to effectively manage assessment remediation plans and documentation
  • Serve as a HITRUST subject matter expert
  • Participate and provide support during audits, assessments, or other required third-party reviews.
  • Support initiatives/projects
  • Build relationships internally to foster a culture of teamwork and collaboration

Requirements

  • At least 4 - 5 years of work experience in IT compliance, IT Assessments and/or IT audit experience as well as knowledge and understanding of governance, risk, compliance
  • Knowledge of security and risk frameworks, standards, best practices (e.g., HITRUST CSF, NIST CSF, ISO/IEC 27001, COBIT)
  • Self-starter with effective written and verbal communication skills along with strong critical thinking skill

Required Skills/Experience - The rest of the required skills/experience. Include:

  • Effective written and verbal communication skills and the ability to tailor communication style to the audience at hand.
  • Experience in coordination and execution of the audit lifecycle, including evidence collection, review, observation tracking, management response collection and auditor relations and communication.
  • Strong demonstration of problem-solving and decision-making ability.
  • Experience working on testing of IT controls across systems, databases, applications and operating systems.
  • Strong ability to frame and deliver messages based on experience and level of the listener.
  • Strong critical thinking skills to actively pursue opportunities to develop and implement solutions to solve work problems. Must be able to solve problems, handle conflict, and make effective decisions under pressure with a highly professional demeanor.
  • Strong organizational skills
  • Strong ability to adjust to changing priorities while multitasking effectively.
  • Self-directed and works with minimal guidance. Proactively seeks guidance when needed.

Preferred Skills/Experience - Optional but preferred skills/experience. Include:

  • Knowledge of Information Technology GCC as well as knowledge and understanding of governance, risk & compliance.
  • Experience performing audits/assessments.
  • Knowledge of security and risk frameworks, standards, best practices (e.g., HITRUST CSF, NIST CSF).
  • Self-starter with effective written and verbal communication skills and strong critical thinking skills

Education/Certifications - Include:

  • Undergraduate university degree (4-year) preferred but not required.
  • Masters (e.g., MBA, MSIS, MIS, etc.) degree preferred but not required.
  • Five (5) years of combined IT experience to include two (2) years IT security work
  • Experience in Information Security, IT general controls, IT compliance, IT assessments and/or IT audit experience.
  • Certified Information Systems Security Professional (CISSP), CISA, CPA/CA, CISM or other equivalent professional certification preferred but not required.

About the company

OpTech is a woman-owned company that values your ideas, encourages your growth, and always has your back. When you work at OpTech, not only do you get health and dental benefits, but you also have training opportunities, flexible/remote work options, growth opportunities, 401K and competitive pay. Apply today! To view our complete list of openings, please visit our website at www.optechus.com

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · WWC Europe 2026

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

4:01 min

Managing application isolation via pluggable database models

Wei Hu Wei Hu · WWC 2022

10:42 min

Essential soft skills and evaluating security candidates

Kurt Eder · LIVE

Videos

See all

Related articles

See all