Business Impact & Information Security Analyst

Stefanini$124K — $135K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Business Administration, IT, Cybersecurity, Risk Management, Data Science, or related field (Master's or certifications preferred)
  • 3-5 years of experience in business continuity, risk management, or information security
  • Proficiency in business impact analysis methodologies and risk assessment principles
  • Strong understanding of cybersecurity frameworks and attack vectors
  • Exceptional analytical, critical thinking, and communication skills

Responsibilities

  • Lead interviews and workshops with stakeholders to identify critical functions and risks
  • Document operational interdependencies and assess security control effectiveness
  • Research emerging cyber threats and assess their relevance to the organization
  • Evaluate potential disruption scenarios and correlate security events with business impact
  • Assist with security audits and maintain documentation of controls and procedures

Benefits

  • Hybrid work environment
  • Professional development opportunities
  • Access to advanced data collection tools and software
  • Opportunity to engage with senior leadership and contribute to strategic initiatives
  • Exposure to diverse industry sectors, including finance and healthcare
Full Job Description
We are seeking a versatile Business Impact & Information Security Analyst to join our enterprise risk management team. This dual-focused role combines business continuity planning with cybersecurity operations, making it ideal for a well-rounded contractor who can bridge operational resilience and information security. The successful candidate will assess organizational vulnerabilities from both business impact and security threat perspectives, ensuring comprehensive protection of critical assets and operations.

Key Responsibilities:

Organizational Risk & Impact Assessment
  • Lead structured interviews and collaborative workshops with department heads and key stakeholders to identify critical business functions, security requirements, and risk exposure
  • Map critical business functions, workflows, technical dependencies, and security control touchpoints across the organization
  • Document operational interdependencies, assess security control effectiveness, and identify single points of failure from both continuity and security perspectives
  • Research and analyze emerging cyber threats, vulnerabilities, and attack vectors; assess relevance to organizational operations and business continuity


Impact Quantification & Risk Analysis
  • Evaluate and assign severity scores to potential disruption scenarios resulting from system failures, supply chain outages, or security incidents
  • Assess financial, operational, legal, and reputational consequences tied to business disruptions and security breaches
  • Develop integrated risk matrices and impact classification frameworks that address both continuity and security risks
  • Correlate security events and threat intelligence with business impact scenarios
  • Contribute to threat modeling exercises for critical systems and functions


Security Controls & Recovery Planning
  • Evaluate effectiveness of existing security controls and countermeasures through testing aligned with frameworks (NIST, ISO 27001, CIS)
  • Review system configurations against security baselines and hardening standards
  • Assess cloud security configurations and compliance (AWS, Azure, GCP)
  • Define Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) for core applications and business units, factoring in security restoration requirements
  • Establish prioritization criteria for recovery sequencing that incorporates security validation steps
  • Collaborate with IT, operations, and security teams to validate feasibility of recovery targets and security controls


Compliance, Governance & Reporting
  • Assist with security and business continuity audits; provide evidence of control implementation
  • Maintain comprehensive documentation including policies, procedures, runbooks, security controls, and business impact profiles
  • Track and report on security metrics, business continuity KPIs, and integrated risk indicators
  • Synthesize analytical findings into executive-ready dashboards and presentations
  • Deliver integrated continuity strategies and security recommendations to senior leadership
  • Maintain updated documentation in alignment with organizational and regulatory standards


Job Requirements

Details:

Required Qualifications and Skills:

Education
  • Bachelor's Degree or 4 years equivalent experience; Bachelor's Degree preferred in Business Administration, Information Technology, Cybersecurity, Risk Management, Data Science, or related field
  • Master's degree or additional certifications preferred


Experience
  • 3-5 years of experience


Core Competencies:

Business Continuity:
  • Proven proficiency in business impact analysis methodologies and frameworks
  • Strong understanding of risk assessment principles and practices
  • Experience with supply chain dependency analysis


Information Security:
  • Solid understanding of cybersecurity principles, frameworks, and best practices
  • Knowledge of common attack vectors, vulnerabilities, and mitigation techniques
  • Experience with security incident investigation and response procedures
  • Understanding of network protocols, system architecture, and security technologies


Universal Skills:
  • Exceptional analytical and critical thinking abilities
  • Outstanding communication and stakeholder management skills
  • Ability to facilitate productive workshops with diverse audiences
  • Strong problem-solving skills and attention to detail
  • Ability to translate technical concepts for non-technical audiences


Technical Tools:

Business Continuity:

* Experience with enterprise continuity software (ServiceNow BCM or similar platforms)

* Proficiency with advanced data collection frameworks and survey tools

* Strong command of relational databases, SQL, and advanced spreadsheet functions

Information Security:

* Knowledge of firewall, IDS/IPS, and network security tools

* Experience with cloud security tools and CSPM platforms

Certifications:

Business Continuity (Preferred):
  • Certified Business Continuity Professional (CBCP)
  • CBCI, MBCI, or similar

Information Security (One or more):
  • Certified Information Systems Security Professional (CISSP)
  • GIAC Security Essentials (GSEC)
  • Certified Information Security Manager (CISM)
  • Cloud security certifications (AWS Security Specialty, Azure Security Engineer)


Experience
  • 3-5 years of combined experience in business continuity, risk management, and/or information security
  • Demonstrated experience conducting business impact analyses
  • Experience working in regulated industries (finance, healthcare, government) a plus
  • Previous contractor or consulting experience beneficial


Ideal Candidate:

The perfect candidate for this role brings a unique combination of business acumen and technical security expertise. You should be equally comfortable:
  • Facilitating executive workshops on business continuity strategies
  • Presenting risk findings to C-level stakeholders
  • Responding to security incidents
  • Documenting complex workflows and dependencies
  • Implementing security controls and conducting assessments
  • This position offers an excellent opportunity for a versatile professional seeking to make impact across both operational resilience and cybersecurity domains.


#LI-SS3

#LI-HYBRID

Pay Range:

$ 60.00 - $ 65.00

Similar Jobs

More Jobs at Stefanini

More Information Technology Jobs

Find similar Business Impact & Information Security Analyst jobs: