What are the responsibilities and job description for the Information Security Analyst position at IHC?
Job Details
Description
SUMMARY
The Security Analyst is responsible for supporting information security operations in compliance with the company’s information security policy.
ESSENTIAL DUTIES AND RESPONSIBILITIES
- Configure and maintain security and audit software systems
- Provide first-tier incident response support
- Assist with audits and risk assessments
- Analyze and respond to security incidents, conduct forensic investigations and document findings.
- Prepare and maintain critical documentation such as policies, procedures, standards, baselines, guidelines, incident reports, and audit responses
- Coordinate third-party service provider and vendor risk assessments
- Perform vulnerability scanning and coordinate penetration testing utilizing third-party tools and services
- Contribute to disaster recovery and business continuity planning efforts
- Contribute to data classification, data retention, and data loss prevention efforts
- Report key metrics to management
- Stay informed of industry best practices and information security frameworks
- Identify vulnerabilities, assess potential risks, and recommend security measures to mitigate threats.
- Meet department attendance requirements, including being prompt and available during scheduled shift
- Performs other related duties and tasks as needed.
Qualifications
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
- A bachelor’s degree in computer science or a related discipline is preferred, but not required. A minimum of five years of experience in an information security role is necessary.
- Knowledge of Microsoft and Mac operating systems, SQL Server user administration, networking devices, and security systems such as firewalls, IDS and IPS, SIEM, endpoint protection, encryption, and multifactor authentication
- Knowledge of common security frameworks (ISO, NIST, etc.) and regulatory compliance (PCI, SOX, HIPAA, NYDFS, CCPA)
- Ability to build relationships with all levels within the organization via in person, virtual and written communication.
SUPERVISORY RESPONSIBILITIES
- None
CERTIFICATES, LICENSES, REGISTRATION
- While a current information security certification (such as Security , CISSP, or similar) is not required at the time of hire, the individual must obtain the certification within 15 months of starting the role.
PHYSICAL DEMANDS
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Small Motor Skills: Picking, pinching, typing or otherwise working primarily with fingers rather than with whole hand or arm, as in handling.
Speaking: Expressing or exchanging ideas by means of spoken word. Those activities in which require detailed or important spoken instructions must be conveyed to other workers accurately and quickly.
Hearing: Ability to receive detailed information through oral communication with or without correction.
Repetitive Motion: Substantial movement (motions) of the wrist, hands and fingers.
WORK ENVIRONMENT
This Hybrid Remote / In-office role provides the opportunity to gain knowledge while collaborating with co-workers while also considering a life work balance.
The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Normal office environment with controlled temperature.
ADDITIONAL REQUIREMENTS
The company reserves the right to determine if this position will be assigned to work on-site, remotely, or a combination of both. Assigned work location may change. In the case of remote work, physical presence in the office/on-site may be required to engage in face-to-face interaction and coordination of work among co-workers.
COMPUTER PROGRAMS USED ON A DAILY BASIS
Microsoft Office
Asana
BOX
Trend Micro
Acunetix
Arctic Wolf
Barracuda
Cloudflare
Wordfence / WordPress
Wiz
Jamf / Apple Business Manager
KnowBe4