Information Security Risk Analyst II

Mariner Finance

• $93K — $118K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Information Systems Management, Engineering, or similar; experience may substitute for degree.
  • 5+ years of security administration and vulnerability assessment experience.
  • Certifications: CISA/CISM required; CISSP preferred.
  • Strong system administration experience in a Microsoft Windows environment.
  • Proficient in scripting languages for task automation and data manipulation.
  • Experience in developing technical diagrams, reports, and presentations.
  • Ability to communicate complex ideas clearly to both technical and non-technical audiences.

Responsibilities

  • Ensure adherence to industry standards for all Information Security-related responsibilities.
  • Support the Payment Card Industry (PCI) program.
  • Provide technical expertise on security issues to senior management.
  • Create and distribute communications on relevant security matters.
  • Develop security policies and procedures throughout all phases of implementation.
  • Ensure compliance with legal and regulatory requirements for networks and systems.
  • Validate and test security architecture and design solutions.

Benefits

  • Flexible work hours based on business needs.
  • Opportunity for professional development and certifications.
  • Collaborative work environment across departments.
  • Engagement in high-impact security initiatives.
  • Participation in a Security Incident Response Team.
Full Job Description
Base Salary Range

USD $93,772.38 - USD $118,076.32 /Yr.

Job Details

In this role, you will...

Be responsible for performing all functions required to support daily information security risk operations. Perform network, system, computer, and application vulnerability assessments to identify, evaluate, and mitigate security risks, threats, and vulnerabilities to maintain availability, integrity, and confidentiality for the organization.

Responsibilities and Duties:

  • Ensure Mariner's adherence to industry standards and best practices for all Information Security-related responsibilities. This includes but is not limited to: datacenters, networks, telephony, systems, databases, applications, and physical security systems.
  • Provide support to Mariner Finance's Payment Card Industry (PCI) program.
  • Provide technical expertise and guidance about security issues to senior management.
  • Assist in the creation and distribution of effective, periodic communications in the forms of blog posts or job aids to the company about relevant security matters.
  • Contribute to the development of security policies and procedures in all phases of planning, implementation, training, and monitoring/enforcement.
  • Assist in ensuring that appropriately managed controls are in place to meet the legal and regulatory compliance requirements of all Mariner Finance networks and systems.
  • Validate and tests security architecture and design solutions to produce detailed engineering specifications with recommended vendor technologies.
  • Build and maintain relationships with teams and third parties for security development and support issues.
  • Participate in vendor management processes to ensure the security of Mariner's corporate and customer data. Work with the legal team to evaluate security controls.
  • Collaborate with senior team members to define corporate security requirements and evaluate systems to determine if they are appropriate and comply with established security standards.
  • Perform internal risk assessments in cooperation with IT staff and business units.
  • Manage external risk assessment/third-party and internal audit process in cooperation with IT and Compliance departments.
  • Validate results of all internal and external risk assessments and provide prioritized remediation plans to appropriate staff. Track and coordinate validation of remediation.
  • Oversight management for awareness program, privilege management system, brand protection technology, and enterprise managed security service provider.
  • Be a member of the Security Incident Response Team and provides the highest level of technical consultancy to ensure problem resolution is achieved in the shortest possible timeframe.
  • Participate in investigations of security incidents while preparing incident report documents.
  • May perform additional functions depending on market demand and staffing in order to provide consistent quality customer service.


Required Qualifications:

  • Bachelor's degree in a related discipline (Computer Science, Information Systems Management, Engineering, or similar); additional, applicable years of experience may be substituted for the bachelor's degree.
  • Minimum of five (5) years of security administration experience and vulnerability assessment/management experience.
  • Certifications: CISA/CISM.
  • Strong system administration experience in a Microsoft Windows environment.
  • Strong experience using scripting languages to automate tasks and manipulate data.
  • Strong experience developing technical diagrams, topology maps, reports, and presentations with various software applications.
  • Demonstrated ability to explain complex ideas and concepts both verbally and in writing to technical and nontechnical audiences.
  • Ability to work collaboratively inter-departmentally and across business functions.
  • Passion for providing excellent customer service.
  • Ability to work in a fast-paced environment. Ability to multitask, change direction, effectively prioritize, and meet deadlines with both local and remote staff.
  • Must have ability to work with limited supervision and be able to independently determine tasks to complete on a daily basis.
  • Ability to occasionally adjust work schedule to meet business needs (occasional after-hours and weekend requirements).
  • Excellent interpersonal skills necessary to communicate professionally and effectively with vendors, service dealers, customers, and all levels of company staff.


Preferred Qualifications:

  • Certifications: CISSP.
  • Knowledge of web security.
  • Experience with Payment Card Industry (PCI), ISO Standards, and Risk programs.
  • Experience with security planning and incident response.
  • Experience working within or with audit and compliance teams.
  • Working knowledge of OWASP.


Hours of Work:

Work hours will depend on the business hours of the time zone serviced. To the extent permitted by law, the Company may, in its sole discretion, change the work schedule to address business needs.

Physical Demands:

While performing the duties of this job, the employee is frequently required to sit for extended periods; reach with hands and arms; and talk or hear. The employee is occasionally required to move about. The employee must occasionally lift and/or move up to twenty (20) pounds. Specific vision abilities required by this job include close vision and the ability to adjust focus.

This job description is not designed to cover or contain a comprehensive listing of activities, duties, or responsibilities that are required of the employee. Duties, responsibilities, and activities may change or new ones may be assigned at any time or without notice.

Similar Jobs

More Jobs at Mariner Finance

More Information Technology Jobs

Find similar Information Security Risk Analyst II jobs: