We are looking for an experienced IT Security Analyst to assess, mitigate, and manage security risks across our organization's IT infrastructure. The ideal candidate will be responsible for conducting security audits, performing risk assessments, implementing security policies, and ensuring compliance with regulatory standards. You will play a critical role in protecting sensitive data and maintaining the integrity of our systems.
- Conduct comprehensive security audits and risk assessments of IT systems.
- Develop, implement, and maintain security policies, procedures, and standards.
- Monitor systems, networks, and applications for security breaches and vulnerabilities.
- Coordinate with IT teams to remediate identified security issues and gaps.
- Prepare detailed security reports, risk matrices, and compliance documentation.
- Ensure compliance with ISO 27001, SOC 2, GDPR, and other regulatory frameworks.
- Evaluate and recommend security tools, technologies, and solutions.
- Conduct security awareness training for employees and stakeholders.
- Perform vendor risk assessments and third-party security reviews.
- Stay updated with emerging threats, vulnerabilities, and industry best practices.
- Strong knowledge of security frameworks (ISO 27001, NIST, COBIT, CIS Controls).
- Experience with security audits, risk assessment methodologies, and gap analysis.
- Understanding of network security, access controls, and identity management.
- Familiarity with compliance requirements (GDPR, HIPAA, PCI DSS).
- Knowledge of governance, risk management, and compliance (GRC) tools.
- Experience with vulnerability scanning tools (Nessus, Qualys, OpenVAS).
- Strong analytical, documentation, and reporting skills.
- Excellent communication and stakeholder management abilities.
- Bachelor's degree in Information Security, Computer Science, or related field.
- 2-4 years of experience in IT security, risk management, or compliance.
- Relevant certifications (CISA, CRISC, ISO 27001 Lead Auditor, CISM).
- Experience with cloud security assessments (AWS, Azure, GCP).
- Knowledge of business continuity planning and disaster recovery.
- Location: On-site
- Employment Type: Full-Time
- Experience: 2-4 Years