Job Summary:
The Information Security Analyst III will support security compliance and assessment activities by evaluating information security controls, policies, and procedures to identify risks, vulnerabilities, and opportunities for improvement. The role requires experience conducting security assessments, applying risk management practices, and working with compliance frameworks and continuous authorization processes. The analyst will collaborate with stakeholders to review security data, provide guidance on security requirements and best practices, support new process development and integration, and contribute to strengthening the organization's overall security posture.
Key Responsibilities
• Conduct thorough evaluations of information security controls to identify potential threats, vulnerabilities, and control weaknesses.
• Review security controls, policies, and procedures to prioritize risks and recommend enhancements aligned with organizational security goals.
• Review security-related data and advise stakeholders on best practices and necessary changes to address business and information security requirements.
• Support projects involving the development of new processes and integration of new processes with existing environments.
• Assist in developing and communicating process changes to impacted clients and stakeholders.
• Apply risk management principles to support informed decision-making and contribute to functional area risk management.
• Build strong collaborative and negotiation relationships with customers, stakeholders, and other resources.
• Provide guidance on applicable security requirements and best practices.
• Perform other related duties as assigned.
Required Qualifications
• Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent experience with 3-5+ years of relevant work experience.
• Proven experience conducting information security assessments.
• Knowledge of security compliance frameworks and continuous authorization processes.
• Knowledge of NIST SP 800-37 and NIST SP 800-53/53A.
• Experience reviewing security data and advising stakeholders on applicable security requirements and best practices.
• Understanding and application of risk management principles in decision-making.
• Excellent communication and collaboration skills.
• Strong interpersonal, collaboration, and negotiation skills.
• Strong creativity, attention to detail, and analytical capabilities.
• Ability to work effectively with customers and stakeholders to address security and compliance requirements.
Preferred Qualifications
• CISSP, CISA, or CISM certification.
• Experience working in a policy and assurance or quasi-governmental environment.
• Familiarity with cloud service providers and associated security challenges.
• Knowledge of SAFR lifecycle compliance and testing.
• Experience supporting security compliance and assurance programs.
• Ability to build strong interpersonal relationships while demonstrating collaboration, negotiation, creativity, attention to detail, and effective communication.