Information Security Analyst
Rose International · Madison, WI · Yesterday
Information TechnologyFull-time
About the Role
This is a temporary, full-time Information Security Analyst position with a hybrid work model based in Madison, WI. The role is primarily remote with some onsite work possibility. The candidate must be a Wisconsin resident, and no relocation is allowed. Remote work will be discussed with candidates in the interview phase.
Required Skills & Experience
- Broad knowledge of information security and experience in application development, technical architecture, contracting, audit, or vendor management
- Familiarity with NIST or another recognized framework
- Demonstrated ability to solve complex problems, convey both oral and written instruction, and handle multiple task interruptions while providing services in a professional and courteous manner
- Demonstrated attention to detail and organizational skills
- Demonstrated ability to work effectively with customers to solve business challenges while balancing the need for confidentiality, integrity, and availability
- Demonstrated commitment to fostering a diverse working environment
- Demonstrated ability to work independently, as part of a team of peers, and also to support and contribute to a multidiscipline team environment
Responsibilities
- Identifying and continuously assessing risk
- Developing, institutionalizing, and improving strategies to mitigate risk
- Limiting the potential effects of information security events
- The selection, assessment, authorization, and monitoring of security controls while contributing to the overall information security plan
- Partner with organizational leaders to incorporate information security best-practices into technical and operational development
- Provide recommendations on how to improve the information security posture of programs and reduce risk
- Communicate risks in simple and comprehensible terms. Provide options to mitigate risk considering business impact
- Draft security requirements to be included into charters, scope documents, procurements
- Document and communicate analysis. Answer clarifying questions
- Escalate to ISS leadership if an acceptable level of risk cannot be achieved
- Be a solutions-focused advocate
- Intake projects and other program initiatives and champion them through the appropriate ISS work stream
- Gather information as needed so that security team can perform thorough analysis
- Communicate work stream deliverables to the customer
- Verify that the deliverable meets the customer need, follow-up on any clarifications
- Coordinate across ISS meeting their security-focused needs
- Coordinate with other client staff and other program staff as needed in order to arrive to an outcome
- Responsibility and authority will vary based on the use case and customer need
- Request and/or gather artefacts demonstrating compliance
- Schedule/facilitate communications between auditor/incident response, vendors, technical teams, and other program stakeholders
- In partnership with ISS, assess audit results and develop corrective action plans/plans of action and milestone
- Provide oversight to the resolution, test for compliance, and request authority to close
- Respond to regulatory inquiry and draft documents as needed
- Back-up other security liaison roles
- Draft and deliver status reports
- Establish and maintain positive working relationships with stakeholders
- Establish and documents standard operations for job-related activities
Schedule
8:00 AM - 5:00 PM
Pay
Min Hourly Rate: $48.00 | Max Hourly Rate: $50.00