Senior Security Engineer
Information Security Analyst job 25 miles from Alpharetta
Title: Sr. Security Engineer
Duration: 12 Months
Qualifications:
6+ years' experience with SAP Security Design, Implementation and Administration in SAP ECC required, including production support experience with specific experience with SAP Transportation Management System
Proficient in SAP authorization concepts, including authorization reporting, troubleshooting transaction codes, and project implementation
Strong understanding of Sarbanes Oxley legislation, risks and mitigating controls (segregation of duties, etc)
Responsibilities:
Responsible for the design, testing, evaluation, implementation, support, management, and deployment of security systems/devices used to safeguard the organization's information assets.
Also responsible for analyzing the information security environment and assisting with the development of security measures to safeguard information against accidental or unauthorized modification, destruction, or disclosure.
Works with the technical team to recover data after a security breach.
Configures and installs firewalls and intrusion detection systems.
Develops automation scripts to handle and track incidents.
Investigates intrusion incidents, conducts forensic investigations and mounts incident responses.
Delivers technical reports and formal papers on test findings.
Installs firewalls, data encryption, and other security measures.
Maintains access by providing information, resources, and technical support.
Ensures authorized access by investigating improper access; revoking access; reporting violations; monitoring information requests by new programming; recommending improvements.
Updates job knowledge by participating in educational opportunities; reading professional publications; maintaining personal networks; participating in professional organizations.
Accomplishes information systems and organization mission by completing related results as needed.
Builds, deploys, and tracks security measurements for computer systems and networks.
Mitigates security vulnerabilities by implementing applicable solutions and tools.
Performs vulnerability testing, risk analyses, and security assessments.
Collaborates with colleagues on authentication, authorization, and encryption solutions.
Tests security solutions using industry standard analysis criteria.
Responds to information security issues during each stage of a project's lifecycle.
Performs risk assessments and testing of data processing systems.
Establishes system controls by developing framework for controls and levels of access; recommending improvements
Establishes computer and terminal physical security by developing standards, policies, and procedures; coordinates with facilities security; recommends improvements.
Safeguards computer files by performing regular backups; developing procedures for source code management and disaster preparedness; recommends improvements.
Determines the sensitivity of the data in order to recommend the appropriate security needs.
Develops proposals for, and consider cost effective equipment options to satisfy security needs.
Communicates with the technical team, management team and users companywide if data security is breached.
Designs infrastructure to alert the technical team of detected vulnerabilities.
Evaluates new technologies and processes that enhance security capabilities.
Supervises changes in software, hardware, facilities, telecommunications and user needs.
Defines, implements, and maintains corporate security policies.
Analyzes and advises on new security technologies and program conformance.
Creates, tests, and implements network disaster recovery plans.
Recommends security enhancements and purchases.
Trains staff on network and information security procedures.
Develops security awareness by providing orientation, educational programs, and on-going communication.
Recommends modifications in legal, technical and regulatory areas that affect IT security.
Security Architect
Information Security Analyst job 25 miles from Alpharetta
IT Security Architect 4
Client: VITA
Duration:08 Months
ABOUT THE ROLE Security Architect IV to create System Security Plans for suppliers. The role involves conducting interviews with business units, analyzing responses to security controls, and ensuring compliance with COV SEC530 (NIST 800-53).
We are seeking a highly skilled and experienced Security Architect IV contractor to develop and write System Security Plans (SSPs) for various suppliers and enterprise applications. This critical role requires a deep understanding of security controls, risk management, and compliance requirements. Previous experience as a Security Control Assessor is beneficial.
Key Responsibilities:
Collaborate with business units to gather and analyze information for the creation of comprehensive System Security Plans (SSPs).
Conduct interviews with key stakeholders to understand system components, operations, and security needs.
Evaluate responses to security control questions and identify any gaps or areas requiring remediation.
Ensure all systems meet the security and compliance requirements of COV SEC530, based on NIST 800-53 standards.
Develop detailed documentation outlining security measures, risk assessments, and system vulnerabilities.
Provide guidance on risk mitigation strategies and recommend security improvements.
Assist in ensuring that enterprise applications and supplier systems comply with industry standards and regulatory requirements.
Qualifications:
Proven experience in writing System Security Plans and conducting security assessments.
In-depth knowledge of NIST 800-53, COV SEC530, and other relevant security frameworks.
Strong understanding of risk management, security controls, and compliance processes.
Excellent communication skills, with the ability to collaborate with cross-functional teams and business units.
Ability to work independently and manage multiple projects simultaneously.
This is a contractor position offering an opportunity to contribute to the security and compliance efforts of the organization, ensuring the protection of sensitive data and infrastructure.
Information Security Analyst - REQ # 1262
Information Security Analyst job 13 miles from Alpharetta
Mitsubishi Electric Trane HVAC US LLC is looking for an Information Security Analyst in Suwanee, GA.
The Information Security Analyst role is responsible for ensuring compliance with Mitsubishi Electric Information Security Management (ISM) standards and best practices. This includes, but is not limited to, the areas of network security, software and hardware approval, physical and digital vulnerability management and general continuous improvement opportunities in the company s information security posture. The ideal candidate will have a strong understanding of security standards, risk management and auditing practices.
The essential functions of the position include, but are not limited to the following:
Conduct software review for approved/unapproved software and software approval.
Conduct regular security audits and assessments to ensure compliance with ISM policies.
Identify, analyze, and report security vulnerabilities and risks.
Assist in the development and implementation of security controls and procedures.
Collaborate with internal teams to enhance security policies and awareness.
Monitor security incidents and support investigation efforts.
Provide recommendations for improving security frameworks and best practices.
Stay updated with evolving security standards, regulatory requirements, and industry trends.
Willing to travel up to 25% for various Company meetings and training.
Performs other IT department related job junctions as assigned.
Qualifications & Skills:
Bachelor's degree in Cybersecurity, Information Technology, or a related field (or equivalent experience).
3 to 5 years minimum of experience in an Information Security Management (ISM) role.
Proven experience in security auditing, compliance, or risk assessment.
Familiarity with security standards such as ISO 27001, NIST, and SOC2.
Strong analytical and problem-solving skills.
Excellent communication and documentation abilities.
Team player demonstrating METUS core values including a desire to win together, deliver excellence, drive sustainability, focus on execution and learn continuously.
The base pay range for this position at commencement of employment is expected to be between $85,600 and $117,700 per year however, base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience.
The total compensation package for this position may also include other elements, including target bonus plans and discretionary awards. Subject to the terms and conditions of the applicable plans then in effect, eligible employees may enroll in a 401(k) plan, as well as participate in Company-sponsored medical, dental, vision, and basic life insurance plans for the employee and the employee s eligible dependents. Employees will also receive 80 hours of vacation per year, 56 hours of paid sick leave annually, and 13 paid holidays throughout the calendar year, depending on hire date. Employees may also take up to 12 weeks of paid or unpaid [parental/disability/emergency/etc.] leave, if eligible.
ABOUT MITSUBISHI ELECTRIC TRANE HVAC US
Formed in 2018, Mitsubishi Electric Trane HVAC US (METUS) is a leading provider of ductless and VRF systems in the United States and Latin America. A 50 percent 50 percent joint venture between Ingersoll Rand plc and Mitsubishi Electric US, Inc., the company provides innovative products, systems and solutions capable of cooling and heating any application from a home to a large commercial building. METUS is a leading marketer of Zoned Comfort Solutions and Variable Refrigerant Flow (VRF) air-conditioning and heating technology. Systems sold by the joint venture include a wide variety of technologically advanced products designed to deliver superior efficiency, comfort and control.
The family of brands supported by METUS includes: Mitsubishi Electric Cooling & Heating, Trane / Mitsubishi Electric and American Standard Heating & Air Conditioning Mitsubishi Electric. More information is available at ************************* . We offer an excellent compensation and benefits package including 401(K).
In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification document form upon hire. We are an equal employment opportunity employer. All employment decisions are made without regard to race, color, religion, sex, pregnancy, breastfeeding or related medical condition, national origin, ancestry, citizenship, age, marital status, sexual orientation, gender identity, gender expression, domestic partnership, physical disability, mental disability, medical condition, genetic characteristic or information, military or veteran status or other legally protected status (except when one of these criteria is a legally permissible bona fide occupational qualification). The Company will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the Company, or (c) consistent with the Company s legal duty to furnish information.
To view the EEO is The Law Poster and the supplement, please click here or visit ***********************************************************************
Applicants with a disability who need assistance with the application process may contact Human Resources by email at *********************** or by calling ************.
Cyber Security Analyst
Information Security Analyst job 25 miles from Alpharetta
about the role Orange Cyberdefense specializes in the design, implementation and support of the most reliable and innovative security solutions and services - we are seeking a SOC Analyst to join our global team for a major account. As a SOC Analyst you are responsible for the detection, investigation and defense against cyber-attacks. In our SOC, you will work with security experts and use the latest technologies to analyze potential security incidents.
As the team is working based on FTS (follow-the-sun) model involving Brazil, France & Malaysia teams, shift work is required for this role.
Your key responsibilities as a SOC Analyst will include to:
* Ensure that customer environments are always protected against cyber-attacks
* Triage and investigate alarms generated by SIEM tools, endpoint protection tools, network anomaly detection tools, etc. by performing in-depth analysis
* Undertake threat hunting investigations and campaigns
* Escalate relevant threats to customers and providing advice based on these threats
* Detect anomalies and attack patterns along the entire cyber-kill chain as described by MITRE ATT&CK
* Support our customers during a security incident and ensure effective defense against attacks
* Continuously develop improvements and detection methods to optimize detections
* Report monthly on the status of customer environments
* Advice customers on cyber trends.
about you
* Cybersecurity needs to be your passion, securing the customers assets your mission. As security is often a tradeoff between different aspects, you need to be pragmatic and result driven to get your message delivered while reducing the risk for the customer.
* Excellent English written/verbal and communication skills.
* Minimum of 2 years of experience in a similar role
* Experience using SIEM and/or EDR/XDR security tools - Knowledge in SPLUNK technology is a plus.
* A degree in Computer Science, Cyber Security, Digital Forensics or Engineering - or equivalent industry recognized certification/experience
* Ideally have experience with penetration testing, incident detection, incident response and malware analysis
* Broad knowledge on threat analysis and experience in intelligence reporting.
* Ideally have experience with penetration testing, incident detection, incident response and malware analysis.
* Ideally have certifications such as CySA+, CEH, OSCP, OSDA, Splunk Power
* Ideally have experience working within a SOC, if not then any experience within an IT Department providing customer support
Experience in reversing malware is a plus
Industry certifications like CISA, CISM, CISSP is a plus
additional information
Our Competitive Benefits Package Includes:
* Comprehensive health coverage (medical, dental, vision) for you and your family
* Financial protection: life, disability, AD&D, and business travel insurance
* 401(k) plan with company match
* Pre-tax savings through HSA and FSA accounts
* Employee assistance program, tuition reimbursement, and adoption support
* Healthy living and wellness reimbursements
* Group-rate insurance options: home, auto, pet, and more
* Generous PTO and paid volunteer days
* Legal assistance, critical illness, hospital indemnity, and ID theft protection plans
department
Global Delivery & Operations
Orange Business manages and integrates the complexity of international communications, freeing our customers to focus on the strategic initiatives that drive their business. Our extensive experience and knowledge in global communication solutions, together with our understanding of multinational business and local support in 166 countries and territories, ensure that our customers receive a consistent, global solution wherever they do business
contract
Regular
Cyber Security Analyst
Information Security Analyst job 25 miles from Alpharetta
Role Value Proposition:
The Incident Response Analyst will be a member of UpTime365's Global Cyber Incident Response Team. In this role, an analyst will use cutting edge tools and solutions, and collaborate with global team members across the organization to perform cyber incident response and protect UpTime365's partners against cyber threats.
Key Responsibilities:
Response to cyber security events and incidents by analyzing forensic data, logs, and threat intel to validate security threats, assess impact, determine root cause, and help coordinate remediation actions.
Maintain awareness of emerging threats.
Willingness and self-motiviation to learn and take advantage of all training opportunities provided.
Perform proactive threat hunting to identify potential threats to UpTime365 and its partners.
Partner with global incident response teams to coordinate global incident response.
Eventual participation on a rotating on-call roster for off hour escalations.
Requirements
Essential Business Experience and Technical Skills:
A bachelor's degree in cyber security or computer science, or 2-4 years of combined IT and Cyber Security related work experience.
1-3 years of experience analyzing logs (e.g. endpoint, network, identity), performing data correlation, and using SIEM or log management tools.
Basic understanding of the Windows operating system and command line tools, network fundamentals, and cyber security concepts and frameworks.
Scripting experience for analysis and automation of repeatable processes.
Security specific certifications from SANS and other industry recognized organizations are desirable.
Benefits
Dental insurance
Medical insurance
Vision insurance
401K
Paid vacation and sick leave
Tuition fee reimbursement
Students loan assistance
Fleet Assurance Analyst
Information Security Analyst job 25 miles from Alpharetta
at LiftOne
Find Your Career With LiftOne
We're a family-owned company under our third generation of leadership and have built our business based on the principles of trust, integrity and a desire to help our customers and employees succeed.
LiftOne invests in people, facilities and innovative technology as part of the essential role we play in supporting our country's supply chain and enabling critical goods to be delivered to homes and businesses. We're a privately held company, and pair our scale with a strong foundation in our culture and values. This combination gives us a competitive advantage in the market and helps make us a trailblazing organization that is built to last.
We're looking for hard-working, team-oriented professionals who enjoy working on new challenges every day. We believe our employees are the key to our success, and we're committed to providing a work experience that helps our team grow to their full potential. We offer great benefits, competitive salaries and opportunities for advancement to all our employees.
Be a part of the essential work we do at LiftOne and make a difference for our customers, our community and our company. Learn more about what it means to become a team member with LiftOne.
Summary
The Fleet Assurance Analyst is responsible for reviewing operational data and dashboards to develop actionable business insights across LiftOne's service and fleet management platforms. This individual will develop greater customer engagement through LiftOne's growing market footprint, help drive service performance, and enable continuous improvement efforts.
The ideal candidate should be self-directed and focused on delivering business impact. The candidate should be able to understand business problems, formulate actionable plans, and create leads for customer engagement. The candidate should also be an effective communicator, capable of delivering insights in a concise and consumable manner to both technical and non-technical audiences.
Essential Functions
Translate Fleet and Asset key performance indicators into customer recommendations
Minimizing downtime from Scheduled vs. Unscheduled work order evaluation
Optimizing fleet life with hour meter and equipment usage analysis
Reducing total cost of ownership with maintenance agreements and PM plans
Collaborate with finance and sales teams to help optimize customer fleet mix and asset management
Organizing recommendations for fleet replacement through break even analysis
Manage the dashboard tools to guide exception management capabilities
Develop deep understanding of LiftOne operations and strategy
Review dashboards and collaborate with Data Governance team to ensure data integrity
Other duties as assigned.
Supervisory Responsibilities
This job has no supervisory responsibilities.
Qualifications
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable qualifying individuals to perform the essential functions.
Education and/or Experience
Associate degree from a 2-year college or university; or two years' related experience and/or training; or equivalent combination of education and experience
Bachelor's Degree in Analytics, Operations, Business Administration, or similar degree preferred
Excellent problem-solving skills, within a fast-paced environment.
Strong communication skills, written and verbal, with ability to convey results of analyses in a clear and concise manner
Ability to independently handle multiple projects at a time, prioritize, and manage time effectively
Operate and participate in a highly collaborative team environment
Experience using or creating dashboards, preferred
Understanding of operations management principles, preferred
Computer Skills
Proficiency in Microsoft Office (Word, Excel, Outlook and PowerPoint)
History of working with data visualization tools (e.g. Tableau, Power BI), preferred
Working knowledge of ServiceMax platform, preferred
Workplace Requirements
The physical demands and work environment described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Physical Demands
While performing the duties of this Job, the employee is regularly required to stand; walk; use hands to finger, handle, or feel; reach with hands and arms and talk or hear. The employee is frequently required to sit. The employee must frequently lift, carry, push, pull and /or otherwise move up to 25 pounds. Specific vision abilities required by this job include close vision, distance vision, peripheral vision, depth perception and ability to adjust focus.
Work Environment
While performing the duties of this Job, depending on site location, the employee may be exposed to moving mechanical parts and equipment. The employee may occasionally be exposed to high, precarious places, fumes or airborne particles; outside weather conditions and vibration. The employee may occasionally be exposed to wet and/or humid conditions; toxic or caustic chemicals; extreme cold; extreme heat and risk of electrical shock. The noise level in some work environments is occasionally loud.
We are an Equal Opportunity Employer
We require all employees to treat all our employees and candidates as equals. All personnel actions are conducted in the spirit of equal employment. We're committed to recruit, train, promote and retain associates without regard to race, color, religion, gender, gender identification and expression, national origin, marital status, age, disability, genetic information, military status, sexual orientation or any other characteristic protected by applicable local, state or federal laws.
#LiftOne
EEO/AA Employer. All qualified individuals - including minorities, females, veterans and individuals with disabilities - are encouraged to apply.
Information Security Analyst - IV
Information Security Analyst job in Alpharetta, GA
America Networks is a leading sensor and networking solutions partner for companies in any Industrial, Manufacturing, and Waste management space. We design and manufacture sensors for storage tanks, water metering, energy metering, gas monitoring, and asset management.
Our founders are hardcore telecommunications engineers with combined 200 + years of experience in designing, optimizing and performance engineering; for several mid - large wireless carriers internationally - that saw a need to provide low power, cost efficient sensors to collect data, create alerts, and predict needed actions. We have combined these sensors with low power, wide area (LPWA) networking technologies to provide clients various options to decrease re-occurring costs associated with operating an IoT network of sensors and connected devices.
We specialize in design, deployment, optimization, and support of these Networks. Whether an off-the-shelf or custom solution is needed, we'll create a solution and push the data on the best cloud platform to fit your needs, including your own.
Job Description
The responsibility of this position includes data protection, logging and monitoring for data security of our Big Data and Enterprise Data Warehouse platforms. Tools will be used to classify column level data according to confidentiality categories. This position will also be responsible for development and deployment of advanced data science algorithms to automatically detect and alert data usage anomalies. Encryption, tokenization, data masking, etc. will be applied to data according to confidentiality levels.
• B.S. or equivalent work experience
• 6+ years in related discipline
• Experience with all phases of the Software Development Lifecycle, including system analysis, design, coding, testing, debugging and documentation
• Teamwork & collaboration skills to work across organizations and lead cross-functional teams
• Communication & stakeholder management skills
• Problem solving skills to develop quick yet sound solutions to resolve complex issues
• Programming Language(s): KSH, JAVA
• Software: SHA 256, MD5, SSH, SSL, TLS, Teradata Tools and Utilities (BTEQ, MLoad, FastExport, FastLoad, TPT, TDCH, Query Grid, etc.), Hortonworks Hadoop software (Sqoop, HIVE, HBASE, SPARK, KAFKA, Kyvos, Ranger, Knox, Kerebos, etc.), Informatica software (Secure@Source, TDM, DDM, PowerCenter, BDM, EIC, IDL, IDQ, IIS, etc.), Aster, Tableau, Cognos, Qlik and other BI tools.. AWS cloud security for Hadoop/Teradata and HPE Voltage.
Demonstrated excellent teamwork and also ability to work independently with minimal supervision.
Expert knowledge of the wireless industry and data management activities.
Must have Hadoop and cloud security expertise with usage logging, monitoring, tokenization/encryption, access controls, and analysis.
Additional Information
Vivek Salvatore
vivek.salvatore(@)americanetworks.com
(
*************
Information Security Analyst - Threat Intelligence
Information Security Analyst job in Alpharetta, GA
Are you passionate about the changing threat landscape, love the challenge of understanding how the latest malware works, and can evangelize the risks and issues across a broad organization? Are you looking for a challenging leadership position that will allow you to shape the future of security across the internet? Do you thrive on working with a close-knit, highly-motivated team?
Come join Lancope's threat intelligence team to help protect Lancope's customers against cyber-attacks. The successful candidate will join a global team of senior security analysts focusing on the changing threat landscape and effect on Lancope's customers. This position requires a professional with a strong security software and threat analysis background that is capable of identifying and establishing the relationships and processes within and external to Lancope to build an investigative threat research structure and flow. The team will source data across Lancope, i.e. internal product and traffic monitoring groups, as well as through external partner and qualified third-party relationships.
Lancope is looking for a full time Information Security Analyst for Lancope's Threat Intelligence Team. Analysts in this role will have experience in threat research and a desire to own innovative ideas from invention, through proof-of-concept, and to deployment.
Primary Responsibilities
Conduct literature reviews and keep abreast of state of the hack, data sources, data analysis techniques and big data
Invent and/or apply new techniques to telemetry data on a global scale and identify new security threats
Develop and document proofs-of-concept (POCs) to demonstrate the efficacy, performance, and scalability of new techniques
Publish and present research findings, including methodology and measured efficacy improvements
Help guide the development by working with product teams
Partner to turn successful POCs into product features and actionable intelligence.
Education and Experience
The ideal candidate for this role brings considerable experience, motivation, and organization along with both intense curiosity and desire to make an impact in internet security. Researchers in this role enjoy considerable latitude and work hands-on to complete all phases of applied research. The successful applicant will have demonstrable skills in some of the below areas:
At least 2 years relevant experience
Network administration, System administration (Windows or Unix)
IT security with a focus on computer forensics, incident response, malicious code/exploits, anti-virus, etc.
Knowledge of the current security threat landscape, especially network and web-based threats
Familiar with Windows exploits, malware and malicious code trends
Knowledge of TCP/IP and application in securing systems, investigating security incidents
Solid understanding of computer science fundamentals, software engineering
Knowledge of one or more programming/scripting languages
Web application and script development
Log and data analysis
Strong written and verbal communication
Self-motivated and highly ambitious
Creative problem solving skills and excellent troubleshooting/debugging skills
Excellent teamwork and people skills
Ability to manage multiple tasks and work towards long-term goals
Incident response experience a definitive plus
Information Security Associate or Specialist
Information Security Analyst job in Alpharetta, GA
The use of IT (Information Technology) infrastructure in the company is vital for daily operation. The IS (Information Security) Specialist should Provide secure Information Technology infrastructure service to the company as well as companywide employees and staff.
Role Description.
Define and implement Macro (Servers, Groups and Shared resource) and Micro (Personal and Single) IT infrastructure. Analyze, Plan, Design, Develop and Implement IT Infrastructure and IT Security solutions to support company IT requirements. Analyze and prevent any Information risk ensuring the companys information integrity. Define, maintain and monitor the execution of IS and IT policies. Execute and monitor company IT/IS Compliance.
Essential Duties and Responsibilities
-Monitoring and maintaining computer systems and networks
-Responding in a timely manner to service issues and requests
-Providing technical support across the company
-Support equipment repair and replacement service
-Testing Benchmarking new technology
-Maintain and execute IT Training program for new employs
-Monitor IT/IS Infrastructure (including servers and network devices) to ensure data integrity
-Reporting of daily system issues.
-Analyze and propose system improvements.
-Documentation related to IT/IS policies, issues, and procedures.
-Participation and active analyst, designer, and developer in IT projects.
-Monitoring of IT/IS infrastructure-related expenses.
-Other duties as assigned.
Requirements
Qualifications: Listed below are the minimum and/or desired qualifications of the position including education, work experience, and knowledge & skills that are required to perform satisfactorily in the position:
Education and Work Experience:
-Vocational or undergraduate degree in information systems and computer science or related field.
-One (1) to three (3) years of information systems, computer science and/or IT-related experience.
Knowledge and Skills:
-PC and Server management
-IT Hardware and Software installation
-Initiative skills
-Problem-solving skills
-Understanding of IT infrastructure and application architectures
-Great Social and Communication Skills
-Great Oral and Written Communication Skills
-System process analysis and design capabilities/experience
-Server Operating systems (Windows Server, Linux, HP-UX, Unix, Sun Solaris)
-Antivirus, NAC, DLP, MDM and other IS Solutions
-IS Related definition and policies (ex. ISO 27001)
-Networking (Cisco/HP) and network devices (Routers and Switch)
-VPN
-TCP/IP, UDP, Network standards
-LDAP, Active Directory and Exchange
-Access Control
-Security Cameras
-Firewall, Web Filter and other network security appliance solutions
-Database systems (SQL Server/MySQL/Oracle) and programming skill (is a plus)
-MS Office skills (especially Excel skills)
Physical Demands:
-Position requires sitting at a desk working on a computer for at least 2/3 of time.
-Position requires regular and reliable attendance.
-Position requires local travel up to 10% of the time.
Security Analyst Senior
Information Security Analyst job 25 miles from Alpharetta
Location: Ideal candidates will be able to report to our Pulse Point location at 740 W. Peachtree St NW, Atlanta, GA 30308 Work Hours: Monday to Friday, 8:00 am to 5:00 pm The Security Analyst Senior coordinates and prepares the security scanning for database technologies to identify potential vulnerabilities in compliance with policy and best practice.
How you will make an impact:
* Work with database subject matter experts to understand database infrastructure, identify database technologies, and establish routine scanning to ensure compliance with company policy.
* Represent infrastructure security support in significant projects and perform the most complex operations and administration tasks.
* Oversee and serve as the technical escalation of results of preventative maintenance.
* Design and analyze vendor services meeting business and information security requirements and maintain vendor relationships.
* Certify that recently created databases and/or migrated databases from previous instance are scanned within enterprise service level agreement (SLA) timeline.
* Document standard operating procedures (SOP), maintain and update runbook.
* Report monthly certified databases, number of scans, report on the business-critical databases to enterprise.
* Validate report data to ensure accuracy.
* Create process flows and metrics for internal review.
* Run vulnerability scans on databases before releasing to production to eliminate potential vulnerabilities and validate proper controls are in place.
* Administer vulnerability and secure configuration scanning for databases and servers on premise and in the cloud.
* Analyze vulnerabilities with available exploits to identify opportunities to mitigate or remediate vulnerability exposure on impacted systems.
* Administer vulnerability risk assessment methodology based on Common Vulnerability Scoring System (CVSS) utilizing Qualys, Guardium and Prisma vulnerability assessment technologies.
* Communicate with system owners to help support remediation of identified vulnerabilities.
Minimum Requirements:
Bachelor's degree in Information Systems, Computer Science, or a related field.
Additional Requirements:
* Three (3) years of experience working in related occupation(s).
* Three (3) years of experience must include:
* Three (3) years of experience with administration of database vulnerability management assessment tools.
* Three (3) years of experience with performance of vulnerability assessment utilizing the Common Vulnerability Scoring System (CVSS).
* Three (3) years of experience in administration of database technologies, including SQL, Oracle, and DB2.
* Three (3) years of experience operating and administering infrastructure or applications with Cloud environments.
* Three (3) years of experience executing activities in alignment with compliance and contractual requirements, AICPA SOC 2, Payment Card Industry Data Security Standard (PCI-DSS) and HiTrust.
Alternate Education/Experience Requirements:
* Employer will accept a Master's degree in Information Systems, Computer Science or a related field plus 1 year of related experience.
* Must have skills listed above.
SALARY: $130,105.16 per year
APPLY: **********************************
Job Level:
Non-Management Exempt
Workshift:
Job Family:
IFT > IT Security & Compliance
Please be advised that Elevance Health only accepts resumes for compensation from agencies that have a signed agreement with Elevance Health. Any unsolicited resumes, including those submitted to hiring managers, are deemed to be the property of Elevance Health.
Who We Are
Elevance Health is a health company dedicated to improving lives and communities - and making healthcare simpler. We are a Fortune 25 company with a longstanding history in the healthcare industry, looking for leaders at all levels of the organization who are passionate about making an impact on our members and the communities we serve.
How We Work
At Elevance Health, we are creating a culture that is designed to advance our strategy but will also lead to personal and professional growth for our associates. Our values and behaviors are the root of our culture. They are how we achieve our strategy, power our business outcomes and drive our shared success - for our consumers, our associates, our communities and our business.
We offer a range of market-competitive total rewards that include merit increases, paid holidays, Paid Time Off, and incentive bonus programs (unless covered by a collective bargaining agreement), medical, dental, vision, short and long term disability benefits, 401(k) +match, stock purchase plan, life insurance, wellness programs and financial education resources, to name a few.
Elevance Health operates in a Hybrid Workforce Strategy. Unless specified as primarily virtual by the hiring manager, associates are required to work at an Elevance Health location at least once per week, and potentially several times per week. Specific requirements and expectations for time onsite will be discussed as part of the hiring process.
The health of our associates and communities is a top priority for Elevance Health. We require all new candidates in certain patient/member-facing roles to become vaccinated against COVID-19 and Influenza. If you are not vaccinated, your offer will be rescinded unless you provide an acceptable explanation. Elevance Health will also follow all relevant federal, state and local laws.
Elevance Health is an Equal Employment Opportunity employer, and all qualified applicants will receive consideration for employment without regard to age, citizenship status, color, creed, disability, ethnicity, genetic information, gender (including gender identity and gender expression), marital status, national origin, race, religion, sex, sexual orientation, veteran status or any other status or condition protected by applicable federal, state, or local laws. Applicants who require accommodation to participate in the job application process may contact ******************************************** for assistance. Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state, and local laws, including, but not limited to, the Los Angeles County Fair Chance Ordinance and the California Fair Chance Act.
Security Analyst Senior
Information Security Analyst job 25 miles from Alpharetta
Location: Ideal candidates will be able to report to our Pulse Point location at 740 W. Peachtree St NW, Atlanta, GA 30308
Work Hours: Monday to Friday, 8:00 am to 5:00 pm
The Security Analyst Senior coordinates and prepares the security scanning for database technologies to identify potential vulnerabilities in compliance with policy and best practice.
How you will make an impact:
Work with database subject matter experts to understand database infrastructure, identify database technologies, and establish routine scanning to ensure compliance with company policy.
Represent infrastructure security support in significant projects and perform the most complex operations and administration tasks.
Oversee and serve as the technical escalation of results of preventative maintenance.
Design and analyze vendor services meeting business and information security requirements and maintain vendor relationships.
Certify that recently created databases and/or migrated databases from previous instance are scanned within enterprise service level agreement (SLA) timeline.
Document standard operating procedures (SOP), maintain and update runbook.
Report monthly certified databases, number of scans, report on the business-critical databases to enterprise.
Validate report data to ensure accuracy.
Create process flows and metrics for internal review.
Run vulnerability scans on databases before releasing to production to eliminate potential vulnerabilities and validate proper controls are in place.
Administer vulnerability and secure configuration scanning for databases and servers on premise and in the cloud.
Analyze vulnerabilities with available exploits to identify opportunities to mitigate or remediate vulnerability exposure on impacted systems.
Administer vulnerability risk assessment methodology based on Common Vulnerability Scoring System (CVSS) utilizing Qualys, Guardium and Prisma vulnerability assessment technologies.
Communicate with system owners to help support remediation of identified vulnerabilities.
Minimum Requirements:
Bachelor's degree in Information Systems, Computer Science, or a related field.
Additional Requirements:
Three (3) years of experience working in related occupation(s).
Three (3) years of experience must include:
Three (3) years of experience with administration of database vulnerability management assessment tools.
Three (3) years of experience with performance of vulnerability assessment utilizing the Common Vulnerability Scoring System (CVSS).
Three (3) years of experience in administration of database technologies, including SQL, Oracle, and DB2.
Three (3) years of experience operating and administering infrastructure or applications with Cloud environments.
Three (3) years of experience executing activities in alignment with compliance and contractual requirements, AICPA SOC 2, Payment Card Industry Data Security Standard (PCI-DSS) and HiTrust.
Alternate Education/Experience Requirements:
Employer will accept a Master's degree in Information Systems, Computer Science or a related field plus 1 year of related experience.
Must have skills listed above.
SALARY: $130,105.16 per year
APPLY: **********************************
Job Level:
Non-Management Exempt
Workshift:
Job Family:
IFT > IT Security & Compliance
Please be advised that Elevance Health only accepts resumes for compensation from agencies that have a signed agreement with Elevance Health. Any unsolicited resumes, including those submitted to hiring managers, are deemed to be the property of Elevance Health.
Who We Are
Elevance Health is a health company dedicated to improving lives and communities - and making healthcare simpler. We are a Fortune 25 company with a longstanding history in the healthcare industry, looking for leaders at all levels of the organization who are passionate about making an impact on our members and the communities we serve.
How We Work
At Elevance Health, we are creating a culture that is designed to advance our strategy but will also lead to personal and professional growth for our associates. Our values and behaviors are the root of our culture. They are how we achieve our strategy, power our business outcomes and drive our shared success - for our consumers, our associates, our communities and our business.
We offer a range of market-competitive total rewards that include merit increases, paid holidays, Paid Time Off, and incentive bonus programs (unless covered by a collective bargaining agreement), medical, dental, vision, short and long term disability benefits, 401(k) +match, stock purchase plan, life insurance, wellness programs and financial education resources, to name a few.
Elevance Health operates in a Hybrid Workforce Strategy. Unless specified as primarily virtual by the hiring manager, associates are required to work at an Elevance Health location at least once per week, and potentially several times per week. Specific requirements and expectations for time onsite will be discussed as part of the hiring process.
The health of our associates and communities is a top priority for Elevance Health. We require all new candidates in certain patient/member-facing roles to become vaccinated against COVID-19 and Influenza. If you are not vaccinated, your offer will be rescinded unless you provide an acceptable explanation. Elevance Health will also follow all relevant federal, state and local laws.
Elevance Health is an Equal Employment Opportunity employer, and all qualified applicants will receive consideration for employment without regard to age, citizenship status, color, creed, disability, ethnicity, genetic information, gender (including gender identity and gender expression), marital status, national origin, race, religion, sex, sexual orientation, veteran status or any other status or condition protected by applicable federal, state, or local laws. Applicants who require accommodation to participate in the job application process may contact ******************************************** for assistance. Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state, and local laws, including, but not limited to, the Los Angeles County Fair Chance Ordinance and the California Fair Chance Act.
Information Security Analyst
Information Security Analyst job 25 miles from Alpharetta
360 IT Professionals is a Software Development Company based in Fremont, California that offers complete technology services in Mobile development, Web development, Cloud computing and IT staffing. Merging Information Technology skills in all its services and operations, the company caters to its globally positioned clients by providing dynamic feasible IT solutions. 360 IT Professionals work along with its clients to deliver high-performance results, based exclusively on the one of a kind requirement.
Our services are vast and we produce software and web products. We specialize in Mobile development, i.e. iPhone and Android apps. We use Objective C and Swift programming languages to create native applications for iPhone, whereas we use Android Code to develop native applications for Android devices. To create applications that work on cross-platforms, we use a number of frameworks such as Titanium, PhoneGap and JQuery mobile.
Furthermore, we build web products and offer services such as web designing, layouts, responsive designing, graphic designing, web application development using frameworks based on model view controller architecture and content management system. Our services also extend to the domain of Cloud Computing, where we provide Salesforce CRM to effectively manage one's business and ease out all the operations by giving an easy platform. Apart from this, we also provide IT Staffing services that can help your organization to a great extent as you can hire highly skilled personnel's through us.
We make sure that we deliver performance driven products that are optimally developed as per your organization's needs. Take a shot at us for your IT requirements and experience a radical change.
Job Description
The candidate will be a member of the Application Security Assessment (ASA) Team enforcing Global Cyber Security & Fraud at First Data. This includes automated vulnerability scanning mixed with manual penetration testing against web-based applications, web services, and thick client applications.
Job Specific Responsibilities Utilize dynamic and static application security testing tools effectively, including IBM AppScan Standard, Fortify SCA, Burp Suite Pro, and Qualys.
Host developer-focused appsec training workshops on topics including secure coding and vulnerability remediation.
Coordinate testing objectives, reporting deliverables, and remediation efforts as the liaison between the financial institution(s), First Data, and third-party assessors.
Provide documented guidance to development teams that define effective remediation solutions for vulnerabilities.
Contribute to maintaining First Data Corporation's PCI-DSS certifications through addressing regulatory requirements.
Availability to work occasional off-hours to complete assessments tied to meeting critical business objectives.
Interview Required: Yes
Information Technology-Info Security Analyst - Information Technology-Info Security Analyst
Qualifications
Bachelors Degree in Information Security, Computer Science, I.T., I.S., Engineering, Analytics or equivalent.
Hands on technical experience with dynamic and static security testing tools, including source code assessments.
Deep analytical skills, strong out-of-the-box thinking.
Ability to effectively perform detailed-oriented technical information security work on a full-time basis.
Excel independently in a fast-paced environment.
Effective oral and written communication skills.
Preferred Qualifications Masters Degree in Information Security, Computer Science, I.T., I.S., Engineering, Analytics or equivalent.
Proficient web-application developer with demonstrable knowledge of HTML, C/C++, Java, VB, Ruby, etc.
CEH, Security+, GWAPT
Additional Information
Regards,
Vikas Kumar
vikas.kumar(@)360itpro.com
Senior Security Analyst (Hybrid - Kennesaw, GA)
Information Security Analyst job 19 miles from Alpharetta
Headquartered in suburban Atlanta, Georgia, Artivion, Inc. is a medical device company focused on developing simple, elegant solutions that address cardiac and vascular surgeons' most difficult challenges in treating patients with aortic diseases. Artivion has over 1,400 employees worldwide with sales representation in over 100 countries. The Company has manufacturing facilities located in Atlanta, Georgia, Austin, Texas and Hechingen, Germany. Additionally, it has sales and distribution offices in various countries throughout Europe, Asia, and South America. For additional information about Artivion, visit our website, www.artivion.com.
Position Overview:
The objective of the Senior Security Analyst position is to lead the design, implementation, and continuous improvement of enterprise security controls that protect the organization's digital assets, systems, and data. Reporting to the Cybersecurity Team Lead, the role is responsible for proactively identifying threats, mitigating risks, and ensuring the organization's cybersecurity posture aligns with business objectives and regulatory requirements. The Senior Security Engineer acts as a technical expert and key contributor to the development of a resilient, scalable, and secure IT environment while mentoring junior team members and collaborating with cross-functional teams.
Responsibilities:
Proactively identify and analyze unauthorized activity (e.g., misuse, malware, intrusion attempts, phishing) on the global network and provide incident documentation.
Perform analysis of security alerts to evaluate true positive malicious risk to the business, determine containment action, and identify required preventative measures.
Perform regular vulnerability scans on network devices & web applications, provide technical & executive reports and assist with the remediation process.
Monitor identity and access management, including monitoring for abuse of permissions by authorized system users.
Assist in the completion of due diligence information security audits from third parties and clients.
Conduct regular vulnerability assessments and penetration tests.
Collaborate with IT and DevOps teams to remediate identified vulnerabilities.
Support audits and assessments related to frameworks such as ISO 27001, NIST, PCI DSS, or SOX.
Ensure security controls align with business objectives, regulatory requirements, and risk management practices.
Contribute to projects that enhance the security posture of the enterprise.
Operationalize actionable Threat Intelligence reports from internal and external sources.
Remain knowledgeable of changes in security technology, industry practices, and state & federal regulatory requirements and serve as an Information Security Subject Matter Expert (SME).
Provide technical assistance to IT staff in the detection and resolution of security incidents.
Manage end-user communication related to security awareness and manage security awareness platform.
Develop and maintain reports and dashboards for reporting on KPIs on security awareness, threats, and events.
Promote activities to foster information security awareness throughout the organization.
Creates and maintains security specific documentation.
Provides additional IT infrastructure support and project assistance as required
Qualifications:
Minimum 5-7 years of experience in the field of Cybersecurity
Security Operations Center (SOC) work experience with a Bachelor's degree in computer science, information systems, or related technical discipline.
CompTIA Security+, CEH, CISSP, SSCP, CCSP or equivalent certification required.
Excellent IT skills, including knowledge of computer networks, operating systems, software, and hardware.
Web and email security systems experience required.
Nessus & Tenable.io or equivalent vulnerability management system experience required.
Anti-virus, Endpoint Detection and Response experience required.
Broad knowledge of technical security controls required.
Good oral and written communication skills.
Can effectively translate and accurately communicate security and risk implications at the most senior levels across technical and non-technical stakeholders.
This is a hybrid position that will report to our corporate headquarters in Kennesaw, GA
Manager, Information Security
Information Security Analyst job 25 miles from Alpharetta
8+ years of progressive experience in cybersecurity with at least 3 years in a leadership or management role within a Security Operations Center (SOC).
Proven hands-on expertise with SIEM platforms (e.g., Splunk, QRadar, Elastic, Sentinel) including rule creation, alert tuning, and use case development.
Practical experience with SOAR platforms (e.g., Palo Alto XSOAR, Splunk SOAR, Swimlane) including playbook design, automation, and orchestration.
Proficiency in Python and scripting for automation, data enrichment, and incident response use cases.
Deep understanding of incident response frameworks (e.g., NIST 800-61, SANS PICERL) and experience leading complex investigations and coordinated response efforts.
Strong knowledge of cyber threat intelligence principles, including threat hunting, IOC management, and integration of threat feeds into SOC tools.
Familiarity with digital forensics techniques, tools (e.g., EnCase, FTK, Volatility), and procedures for endpoint, network, and cloud environments.
Experience with MITRE ATT&CK framework and applying it to detection engineering, threat modeling, and gap analysis.
Demonstrated ability to build and lead high-performing SOC teams, including analysts, engineers, and threat hunters, across multiple shifts or geographies.
Strong grasp of security logging and telemetry best practices across enterprise environments (cloud, endpoint, network, SaaS).
Experience conducting post-incident reviews, root cause analysis, and continuous improvement initiatives.
Knowledge of vulnerability management processes and how they intersect with detection and response efforts.
Familiarity with cloud security monitoring tools and techniques across AWS, Azure, and GCP.
Experience developing and maintaining runbooks, playbooks, and standard operating procedures.
Excellent communication skills for cross-functional collaboration with IT, GRC, legal, and executive teams.
Industry certifications such as CISSP, GCIA, GCIH, GCFA, GNFA, GPEN, OSCP, or Security+ are highly desirable.
Bachelor's or Master's degree in Cybersecurity, Computer Science, Information Systems, or related field preferred.
Job Summary
Manage and coordinate a team of Security Managers and Engineers. Ensure tight rigor and control over Security Operations and Audit processes.
Major Tasks, Responsibilities, and Key Accountabilities
Serves as an internal information security consultant to the organization. Effectively leads and or coordinates all internal dedicated security functions including but not limited to - patching, anti-virus, intrusion prevention, CERT response, log file monitoring, cross division security coordination, systems operational security testing, rule set analysis, threat detection and adaptation, as well as advent security related functions.
Initiates activities to create information security awareness within the organization.
Performs information security risk assessments, and acts as an internal auditor. Evaluates audit findings and drives remediation of identified control deficiencies.
Reviews all system-related security planning throughout the network and acts as a liaison to information systems.
Monitors compliance with information security policies and procedures, addressing problems with the appropriate department manager or data owner.
Oversees the security policy to ensure appropriateness. Provides training and consultation to ensure understanding of and compliance with established security standards and controls. Manages the Computer Security Incident Response Plan.
Manages the Risk Program including coordination and follow-up of the semi-annual risk assessment and development and implementation of business unit policies and standards.
Manages the business unit's audits and examinations. Works with management to put controls in place needed to comply with SOX and PCI regulatory requirements.
Nature and Scope
Solutions require analysis and investigation.
Achieves planned results by decisions and actions based on professional methods, business principles, and practical experience. May recommend/make decisions regarding new programs/initiatives that have significant impact to the business and carry consequences in unsuccessful endeavors.
Manages a larger team or multiple small teams through direction of subordinate management and/or supervisory staff.
Work Environment
Located in a comfortable indoor area. Any unpleasant conditions would be infrequent and not objectionable.
Most of the time is spent sitting in a comfortable position and there is frequent opportunity to move about. On rare occasions there may be a need to move or lift light articles.
Typically requires overnight travel less than 10% of the time.
Education and Experience
Typically requires BS/BA in a related discipline. Generally 7+ years of experience in a related field. May require certification. Advanced degree may offset less experience in some disciplines.
Our Goals for Diversity, Equity, and Inclusion
We are committed to creating a culture that promotes equity, respect, and advocacy for every HD Supply associate. We value the diversity of our people.
Equal Employment Opportunity
HD Supply is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.
Information Security Risk and Compliance
Information Security Analyst job 25 miles from Alpharetta
PurpleBox is the leading technology consulting company that focuses on solving business problems utilizing new technologies. We provide Cybersecurity, Cloud Computing, and DevOps consulting services that help businesses manage their business risk more effectively.
Job Description
Multiple Information Security Risk and Compliance Positions are available.
Entry-level to mid-senior level
Internship, Part-Time, Full Time
We are seeking to hire multiple Information Security, Risk, and Compliance professionals to work with our customers on risk assessment, compliance, and cybersecurity projects. As part of project delivery teams, these professionals are responsible for the execution, monitoring, and enforcement of the information security governance, risk management, and compliance projects. The successful candidate will oversee day to day execution of operational information security risk and compliance initiatives at PurpleBox and/or our clients.
Responsibilities:
Manage and execute the day-to-day information security risk and compliance operational activities
Develop and recommend appropriate information security policies, standards, procedures, checklists, and guidelines using generally recognized security concepts tailored to meet the requirements of the organization
Identify and document specific security issues, propose resolution options, and interpret matters from the perspective of involved stakeholders
Communicate regularly with teams and staff as part of risk assessments, follow-up on open issues, status tracking, and other miscellaneous items.
Independently design, recommend, plan, develop, and support implementation of project-specific security solutions to meet requirements
Manage remediation of identified risks and vulnerabilities; identify those within the organization responsible for remediation tasks; track progress on remediation of identified risks and vulnerabilities and provide appropriate reporting to all constituents
Provides regular reporting metrics on the current state of the program.
Other duties as assigned
Qualifications
Bachelor's degree in Computer Science, Information Technology, Business Administration, or related field
Experience in information security risk assessment, compliance and/or security operations
Previous experience in one or more of the areas below is a plus:
--- IT Security Strategy and Management
--- Risk Management, IT Audit, and Compliance
--- Network, System, Database administration, support and/or help-desk experience
--- Application Security, Software Development
--- Security Monitoring, Data Loss Prevention, Incident Response
Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate security and risk-related concepts to technical and nontechnical audiences.
Strong analytical skills to analyze security requirements and relate them to appropriate security controls.
Working knowledge of relevant security regulations, standards and frameworks, including SOC2, ISO27000, PCI, HIPAA, and NIST CSF.
Professional certifications such as CISM (Certified Information Security Manager), CISA (Certified Information Systems Auditor) or other similar credential is a plus.
Additional Information
All your information will be kept confidential according to EEO guidelines.
Information Security Risk and Compliance
Information Security Analyst job 25 miles from Alpharetta
PurpleBox is the leading technology consulting company that focuses on solving business problems utilizing new technologies. We provide Cybersecurity, Cloud Computing, and DevOps consulting services that help businesses manage their business risk more effectively.
Job Description
Multiple Information Security Risk and Compliance Positions are available.
Entry-level to mid-senior level
Internship, Part-Time, Full Time
We are seeking to hire multiple Information Security, Risk, and Compliance professionals to work with our customers on risk assessment, compliance, and cybersecurity projects. As part of project delivery teams, these professionals are responsible for the execution, monitoring, and enforcement of the information security governance, risk management, and compliance projects. The successful candidate will oversee day to day execution of operational information security risk and compliance initiatives at PurpleBox and/or our clients.
Responsibilities:
Manage and execute the day-to-day information security risk and compliance operational activities
Develop and recommend appropriate information security policies, standards, procedures, checklists, and guidelines using generally recognized security concepts tailored to meet the requirements of the organization
Identify and document specific security issues, propose resolution options, and interpret matters from the perspective of involved stakeholders
Communicate regularly with teams and staff as part of risk assessments, follow-up on open issues, status tracking, and other miscellaneous items.
Independently design, recommend, plan, develop, and support implementation of project-specific security solutions to meet requirements
Manage remediation of identified risks and vulnerabilities; identify those within the organization responsible for remediation tasks; track progress on remediation of identified risks and vulnerabilities and provide appropriate reporting to all constituents
Provides regular reporting metrics on the current state of the program.
Other duties as assigned
Qualifications
Bachelor's degree in Computer Science, Information Technology, Business Administration, or related field
Experience in information security risk assessment, compliance and/or security operations
Previous experience in one or more of the areas below is a plus:
--- IT Security Strategy and Management
--- Risk Management, IT Audit, and Compliance
--- Network, System, Database administration, support and/or help-desk experience
--- Application Security, Software Development
--- Security Monitoring, Data Loss Prevention, Incident Response
Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate security and risk-related concepts to technical and nontechnical audiences.
Strong analytical skills to analyze security requirements and relate them to appropriate security controls.
Working knowledge of relevant security regulations, standards and frameworks, including SOC2, ISO27000, PCI, HIPAA, and NIST CSF.
Professional certifications such as CISM (Certified Information Security Manager), CISA (Certified Information Systems Auditor) or other similar credential is a plus.
Additional Information
All your information will be kept confidential according to EEO guidelines.
Information Security Controls Manager
Information Security Analyst job 25 miles from Alpharetta
About defi SOLUTIONS:
It’s an exciting time to join defi!!
defi SOLUTIONS partners with captives, banks, credit unions, and finance companies of all types and sizes to allow lenders to focus and transform their operations. The company’s comprehensive suite of originations, servicing, and analytics solutions together with technology-enabled processing services creates a flexible, configurable, and scalable platform that addresses lenders and borrowers’ ever-evolving needs. defi SOLUTIONS combines the expertise of defi SOLUTIONS and the former Sagent Auto Lending with the backing of Warburg Pincus, Bain Capital Ventures and Fiserv.
Position Purpose:
defi’s IS Controls Manager owns internal and external information security audits, ensures management and client assurance, responds to information requests about defi’s security program, performs entitlement reviews and audit reviews, and recommends and implements process and control changes to ensure compliance.
Essential functions:
Reasonable accommodations may be made to enable individuals with disabilities to perform these essential functions.
Owns defi’s internal and external audits by coordinating kickoffs, meetings, evidence collection, item follow-ups, narrative updates, exception response drafts, and remediation tracking.
Audits information systems, platforms, and operating procedures in accordance with established corporate standards for efficiency, accuracy and security.
Evaluates IT infrastructure in terms of risk to the organization and establishes controls to mitigate loss.
Handles client and prospect information requests for assurance.
Facilitate, coordinate and respond to client Security Audits.
Manages defi’s Information Security policies and standards documentation.
Approve requests for access and perform entitlement reviews.
Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities, and activities may change at any time with or without notice.
Required Education and Experience:
Bachelor’s degree or equivalent work experience
Strong written and verbal communication skills
Proven experience with task management and ability to work with diverse individuals and teams across all levels of an organization
Ability to balance multiple competing priorities and deadlines based on skills and experience
Big picture view with the ability to drill into and manage complex technical details
Travel required: Less than 5%
Affirmative Action/EEO statement:
defi SOLUTIONS is an Equal Opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability or protected veteran status.
Customer Assurance Analyst
Information Security Analyst job 13 miles from Alpharetta
Join the Team Making Possibilities Happen
If you've ever used an ATM, paid a bill through your phone, sent money to a friend or shopped online, chances are your transaction was safeguarded and processed using our software. Now it's your turn to serve the payment needs of organizations and people the world over.
This position can be remote but candidates must live and work in the US in Eastern and Central Time Zone only.
Job Purpose
Serve as Liaison to facilitate ACI's response to external audit/exam/assessment engagements to provide external assurance of ACI's management, operational, and control alignment with applicable regulations, IT security standards, contract requirements, etc. as related to Information Security and Risk Management policies, procedures, and relevant control implementations.
Scope of engagements will include but is not limited to global Regulations of Financial Services/Banking and Healthcare sectors, Industry Standards such as ISO (27001, 27017), PCI (DSS, PIN, 3DS), SSAE18 (SOC1/SOC2), and industry best practice related to Information Security, Risk Management, Business Continuity/Disaster Recovery, Privacy, and more. Source of external engagements include but is not limited to Regulators, Customers, Business Partners, and more.
Essential Functions and Responsibilities
Work collaboratively externally, and internally with many teams across functional areas and geographies to ensure engagements are facilitated professionally and timely. Provide audit/exam/assessment subject matter expertise to ensure engagement achieves its stated goal in a timely manner.
Work proactively to reduce impact of engagement and limit duplication of control analysis and testing, by leveraging readily available assurance package of information and relevant reports available for distribution to auditors/examiners. Work closely with team members to identify similar requests and leverage shared knowledge and experience to efficiently facilitate each engagement.
Facilitate the completion of all required tasks during the engagement, including but not limited to answering due-diligence questionnaires, providing policy/procedure documentation and control evidence to auditor/examiner, coordinating meetings with relevant SMEs, hosting web-sessions, documenting meeting minutes and audit/exam notes, and more.
Utilize all necessary tools to ensure all relevant documentation is gathered and stored during and post engagement.
Communicate engagement requests and notices with urgency to management and key stakeholders, escalate engagement risks effectively and drive to resolution in timely manner to ensure minimal impact to engagement.
Understand and adhere to all Corporate Policies, including but not limited to ACI Code of Business Conduct and Ethics, and Global Information Security Standards
Understand and adhere to all department procedures for facilitation of engagements, tracking and reporting of engagement findings, and escalation procedures as needed.
Communicate effectively and professionally in all aspects of the role, internally and externally, representing ACI's Core Values and promoting a positive environment for ACI to maintain and build trust within the context of external engagements.
Effectively utilize, and support development and maintenance, of team processes and procedure documentation, tools for tracking and reporting engagements, their status and progress, and any outcome requiring further monitoring and reporting.
Contribute to ongoing maturity and development of team to achieve goals outlined by management.
Maintain professional and technical knowledge by attending educational workshops; reviewing professional publications; establishing personal networks; benchmarking state-of-the-art practices; participating in professional societies.
Other duties as assigned.
Qualifications (Education, Experience, Knowledge, Skills, and Abilities)
Bachelor's degree or equivalent experience, preferably in Information Systems related field of study, Information Security Risk Management/Third Party Risk Management, or Compliance, Certification Requirements: CISM, CRISC, CISA, CISSP, or CTPRP required.
3+ years' experience in related fields, such as Information Security, Risk Management/Third Party Risk Management, Compliance
Certification Requirements: CTPRP or equivalent certification required.
Preferred Qualifications (Education, Experience, Competencies)
Certification: CISM, CRISC, CISA, CISSP, or CTPRP required.
Prior experience in Payments Services industry
Benefits: In return for your expertise, we offer growth, opportunity, and a competitive compensation and benefits package in a casual work environment.
Are you ready to help us transform the world of electronic payments? To learn more about ACI Worldwide, visit our web site at ******************** Job ID (Requisition #16097)
ACI Worldwide is an AA/EEO employer in the United States, which includes providing equal opportunity for protected veterans and individuals with disabilities, and an EEO employer globally
#LI-LF1
#LI-Hybrid
M4-14Lead Security Analyst 141809
Information Security Analyst job 25 miles from Alpharetta
Job Description
100% remote.
Our direct client has a new opening for a Lead Security Analyst 141809
This job is 14 months to start, and the client is located in Augusta, ME
Please send your rate and resume.
Top 3 Skills:
5 to 7 years of experience in a leadership role, information security, relationship management, and cross-functional goal achievement
Regulatory compliance & policy implementation
Incident response & threat mitigation
Preferred Skills
Experience with support functions - such as consolidated data centers and disaster recovery sites
State and or/local government experience
Education
Bachelor's degree in information technology or related field. Four years of direct experience with information security consultancy may be used in lieu of a degree
MINIMUM QUALIFICATIONS:
Self-motivated leader with 5 to 7 years of experience in a leadership role, information security, relationship management, and cross-functional goal achievement;
Bachelor’s degree in information technology or related field. Four years of direct experience with information security consultancy may be used in lieu of a degree;
Expertise working with Security and Privacy Controls for Information Systems and Organizations as established by the National Institute of Standards and Technology;
Ability to pass required background checks; and
While not mandatory, experience with support functions—such as consolidated data centers, shared print facilities, and disaster recovery sites—as they relate to the regulatory compliance requirements for federally protected data types is preferred.
By replying to this job advertisement, I agree I want to receive additional job advertisements from Focused HR Solutions, including email, phone and mail to the contact information I am submitting. I consent to Focused HR Solutions, its affiliates, third parties and partners processing my personal data for these purposes and as described in the Privacy Policy. I understand that I can withdraw my consent at anytime.
Manager, Information Security
Information Security Analyst job 25 miles from Alpharetta
Responsible for providing digital forensics, monitoring and compliance related to relevant requirements as requested by the CISO or the legal department. Ensure compliance with all relevant internal instructions and external regulatory compliance standards, including the management of operational risk and adherence to Company Code of Conduct and behaviors.
Major Tasks, Responsibilities, and Key Accountabilities
Oversees and performs computer forensic services including digital evidence collection, preservation, analysis, data recovery, tape back-up and recovery, electronic mail extraction, database examination and address relevant situational requirements.
Performs comprehensive technical analyses and interpretations of computer-related evidence such as e-mail, accounting software, various databases, and information stored on electronic devices.
Communicates effectively with internal customers and stakeholders about investigation status, information security capabilities and counsels requestors on information security guidelines, policies and procedures.
Interviews witnesses who have contravened regulations and generates actionable reports.
Keeps data in correct format, restores files and catalogue data and maintains strict confidentiality at all times.
Maintains detailed written work logs and case documentation following forensic procedures.
Utilizes various monitoring and filtering tools to measure and report on the state of security compliance.
Ensures all lab hardware and software are verified and validated as required by various rules of evidence.
Nature and Scope
Solutions require analysis and investigation.
Achieves planned results by decisions and actions based on professional methods, business principles, and practical experience.
Manages a group or team of professional individual contributors and/or indirectly supervises support staff.
Work Environment
Located in a comfortable indoor area. Any unpleasant conditions would be infrequent and not objectionable.
Most of the time is spent sitting in a comfortable position and there is frequent opportunity to move about. On rare occasions there may be a need to move or lift light articles.
Typically requires overnight travel less than 10% of the time.
Education and Experience
Typically requires BS/BA in a related discipline. Generally 7+ years of experience in a related field. May require certification. Advanced degree may offset less experience in some disciplines.
Our Goals for Diversity, Equity, and Inclusion
We are committed to creating a culture that promotes equity, respect, and advocacy for every HD Supply associate. We value the diversity of our people.
Equal Employment Opportunity
HD Supply is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.