Information Security Analyst - Business Security and Compliance
World leader in gases, technologies and services for Industry and Health, Air Liquide is present in 80 countries with approximately 66,000 employees and serves more than 3.6 million customers and patients. Oxygen, nitrogen and hydrogen have been at the core of the company’s activities since its creation in 1902. Air Liquide’s ambition is to be the leader in its industry, delivering long-term performance and acting responsibly.
About the role
The Security Analyst supports the Information Security Officer to uphold Governance, Risk Management, and Compliance standards across Digital & IT environments. This role integrates into a global cybersecurity organization characterized by a rich diversity of cultures, local and global operational requirements, and complex technological landscapes.
Responsibilities
- Ensure alignment with Global Cybersecurity Framework
- Enforce policies, procedures, and guidelines
- Define risk, remediation plans, and compensation controls to reduce risk through the use of Deviation Action Treatment Plans (DTAPs)
- Conduct Security Risk Assessments using Group Tools and Processes
- Review cybersecurity risks for Vendors, Suppliers, Contractors, and other Third-Parties
- Lead the process of critical digital asset compliance including stakeholder communications, reporting, review of evidence, and maintaining compliance score
- Identify Privacy and other Regulatory Requirements including AI Evaluations
- Assess compliance with Global Cybersecurity Framework throughout the data and application life cycle (CDA’s, Global ERP systems)
- Assist in cyber crisis management response and/or cyber crisis simulations
- Coordinate cybersecurity incident response with identified stakeholders to define and minimize impact
- Provide support for Digital and IT Audits by providing responses and evidence related to cybersecurity controls
- Lead rules of engagement, scope of work assessments, and logistics for penetration testing engagements as well as lead Penetration Testing Efforts (IT & OT)
- Act as Cybersecurity expert within the organization
Requirements
- Bachelor’s Degree required
- 4-7 years of experience in Cyber Security, risk management, and/or compliance
- Certifications in information security and/or cybersecurity like CISSP, CISM, CGRC
- Level of English C1
Skills
- Knowledge of security control frameworks and standards such as SOC2, ISO 27001, NIST, etc.
- Experience securing cloud-based environments
- Experience with Regulatory Requirements
Benefits
- Medical, Dental, Vision, Life, AD&D, and Disability Insurance
- 401(k) Retirement Plan with company match
- Tuition Assistance
- Paid Holidays, Vacation, and Sick time
- Benefits start on the first day of employment