Job description
Job Description
Job Summary:
The Information Security Analyst will participate in information security and privacy efforts across various business areas and vendor engagements, ensuring appropriate security controls are in place and adhered to.
This role involves working within a GRC system, partnering with stakeholders to develop and maintain System Security Plans, representing the Information Security Office in projects, and assisting with the development and maintenance of security standards and processes.
Location: Virginia, United States, Responsibilities:
- Participating in Information Security and Privacy efforts across all business areas and vendor engagements.
- Working within a Governance Risk and Compliance (GRC) system to add and update information security information, records, and documentation.
- Partnering with business stakeholders to develop and maintain information System Security Plans (SSP).
- Representing the Information Security Office in PMO lead projects.
- Collaborating with users to understand business challenges, developing options tailored to providing value, facilitating compliance, and providing timely and clear communications.
- Assisting with development and maintenance of information security standards and processes.
- Assisting with controls documentation, including information system diagraming, populating risk assessment templates and drafting control narrative documentation.
- Assisting in reviewing contracts, agreements, and other vendor documentation.
Required Skills & Certifications:
- At least 3 years of demonstrated experience in Information Security concepts related to governance, risk, and compliance.
- Extensive knowledge of the principles and practices of information security.
- Extensive knowledge of the principles and methods applied to information technology infrastructure planning, implementation, and management.
- Ability to organize work, set priorities, meet established deadlines, and follow up on assignments.
- Familiarity or experience working with a security framework (NIST, ISO 27001, COBIT, .
- Superior organizational skills and attention to detail.
- Ability to continually prioritize and adapt to ambiguous situations.
- Experience drafting Information Security and Privacy policies, standards, and procedures.
- Ability to interpret and understand security documentation including flow diagrams and process maps.
- Ability to understand general contract terms and conditions.
- Ability to create diagrams, flowcharts, and spreadsheets using desktop software.
- Ability to write clearly and concisely to various audiences.
Preferred Skills & Certifications: Special Considerations: Scheduling:
Required Skill Profession
Computer Occupations