Job Details

ID #15236812
State California
City Pasadena
Job type Contract
Salary USD $60 - $70 60 - 70
Source Prosum
Showed 2021-06-08
Date 2021-06-02
Deadline 2021-08-01
Category Et cetera
Create resume

Security analyst - NIST

California, Pasadena, 91101 Pasadena USA

Vacancy expired!

ESSENTIAL DUTIES AND RESPONSIBILITIES:

  • Develop and maintain a Common Controls program to measure and monitor the maturity level of the established security programs and existing data controls, including conducting periodic assessments to identify gaps and opportunities for improvement. (CIS 20 Common Controls, NIST-CSF, etc)
  • Maintains performance metrics to measure the success of the Governance, Risk and Compliance (GRC) program. (ServiceNow GRC a plus)
  • Conducts information security risk assessments and compliance audits to ensure the organization is meeting its Security goals and complying with regulatory requirements. Both internally and key vendors.
  • Develops and maintains a Risk Register -
  • Serves as a liaison or data analyst, including coordinating with internal and external auditors to effectively communicate requirements and deliver results.
  • Mature and Supports Vendor Risk Management program, including performing due diligence and security assessments.
  • Develops, implements, and communicates Information Security policies, standards and procedures that support security best practices.

    Experience presenting to Executive Leadership and/or Board of Directors
  • Knowledge and experience with security and risk frameworks, standards, best practices (e.g., HIPAA, NIST-CSF, ISO)
  • Must be able to work independently with a high level of direction.
QUALIFICATIONS (Education, Experience, Knowledge, Skills & Ability):
  • Bachelor’s degree in Computer Science, Information Systems Administration, or related field or equivalent work experience
  • Must have at least 5-7 years of governance, risk, compliance, and audit experience and/or 5 years of information systems experience.
  • Experience with information security risk assessments and regulatory controls. (very important) NIST-CSF or FinRamp is a PLUS
  • Familiarity with information security best practices, disaster recovery and business continuity planning.
  • Work experience in a technical project management capacity, including experience with process development.
  • Must have advanced computer skills and a thorough working knowledge of MS Office Suite.
  • CISSP or CISA or CISM preferred

Vacancy expired!

Subscribe Report job