Intermedia Group - Danbury, CT

posted 8 days ago

Full-time - Mid Level
Danbury, CT
Professional, Scientific, and Technical Services

About the position

The Information Security Analyst is a pivotal, hands-on role dedicated to ensuring the integrity and security of all data across both on-premises and cloud-based applications. This position involves resolving technical issues from inception to resolution and requires a strong technical and infrastructure background. The analyst will implement security frameworks, conduct audits, and collaborate with IT teams to integrate security practices into the development lifecycle.

Responsibilities

  • Implement and maintain the Center for Internet Security (CIS) Controls framework to maintain robust security protocols and procedures.
  • Implement and manage security measures for information systems to prevent breaches, detect vulnerabilities, and manage risk.
  • Conduct regular system audits to ensure compliance with security standards.
  • Proficiency in AI and its application in data security and protection strategies.
  • Collaborate with IT teams to integrate security practices into the development lifecycle.
  • Provide training and guidance to IT staff on cybersecurity best practices.
  • Stay abreast of the latest cybersecurity trends and technologies.
  • Assist with updating and reviewing the System Security Plan (SSP).
  • Develop controls such as firewalls, data leakage protection systems, patching, encryption, and vulnerability scanning.
  • Evaluate, categorize, and remediate security events and vulnerabilities before they become security incidents.
  • Identify security gaps discovered through ongoing monitoring of all information security controls and propose enhancements to security controls.
  • Participate in cybersecurity projects to ensure timely delivery and compliance with information protection requirements.
  • Maintain relationships with Managed Security Services Provider.
  • Own vulnerability management by categorizing, evaluating risk, and implementing remediation steps.
  • Manage patching for servers and endpoints.
  • Participate in on-call rotation for emergency events due to outages or cyber incidents.

Requirements

  • BA/BS degree relating to information technology, compliance, information management, infrastructure, and/or information security.
  • 5 to 7 years of work experience in a related field.
  • Analytical skills developed from training in Cybersecurity, Information Systems, Computer Science, or similar disciplines.
  • Experience managing Rapid7 and NextGen AV systems.
  • Hands-on experience running AI models.
  • Experience with information security framework models such as CIS Framework and NIST.
  • Working knowledge of network switches, routers, firewalls, VPN, and network security.
  • Administration of DLP, antivirus, antimalware, IDS/IPS, SIEM, SMTP, Email security, AD, Group Policy, DNS, DHCP, and VLANs.
  • Knowledge of security best practices such as encryption, hashing, vulnerability scans, and intrusion detection.
  • Ability to oversee and enhance the vulnerability management program.
  • Knowledge of cloud providers' security (AWS, Google Cloud Platform, or Azure).
  • Prior experience managing EDR solutions and SIEM.

Nice-to-haves

  • Previous experience in a HIPAA and FDA regulated environment.

Benefits

  • Relocation assistance available.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service