JOB SUMMARY:
Reporting to the Chief Information Security Officer, the Information Security Analyst is responsible for the day-to-day administration of the information security compliance activities of the Enterprise and its subsidiaries; including the maintenance of the information security program to ensure that information assets and associated technology, applications, systems, infrastructure and processes are adequately protected in the Enterprise's digital ecosystem; and that the Enterprise’s compliance processes and procedures remain current with regulatory and industry requirements. These responsibilities encompass Information Security Policies & Standards, Enterprise Security Awareness and Testing, Vendor Due Diligence, Annual Audit Support and Technology Risk Management, including Disaster Recovery and Business Continuity. The Information Security Analyst – Compliance supports the CISO in identifying, evaluating and reporting on legal and regulatory, IT, and cybersecurity risk to information assets, while supporting and advancing the Enterprise's business objectives. Technical Information Security activities are managed separately in Security Operations.
The ideal candidate must possess two to four years of experience in information technology or information security with a strong background in processes and best practices in information systems, information security and/or network security. Strong written and oral communication skills, the ability to work in a team environment and a collaborative attitude is required. Additionally, working knowledge of information security controls as defined by leading practices (NIST, ISO 27000, COBIT) and regulatory requirements (FFIEC, PCI-DSS), risk assessments and the ability to perform and/or manage information security audits are also requirements for this role.
DUTIES:
QUALIFICATIONS: