Info Security Gov & Risk Specialist

Axelon Services Corporation
Charlotte, NC
Full-time

Job Title : Info Security Gov & Risk Specialist (Hybrid)

Location : Charlotte, Denver, or Iselin

Job Overview :

Defines, enhances, and implements information security configuration controls, while ensuring consistent and effective information security administration procedures and processes.

Key Responsibilities and Duties :

  • Review industry configuration safeguards and monitor compliance for infrastructure assets : databases, workstations, network, middleware, servers, cloud services, and mobile
  • Partners with multiple business stakeholders to drive work and monitor through completion
  • Analyze internal information security controls and convert control criteria and their severity into functional compliance scanning results
  • Create and support program governance documentation such as standard operating procedures, control assessments and training materials
  • Monitor industry security updates, technologies and best practices to improve security management
  • Generate metrics and reports in assigned functional business area to inform decisions on tactical issues that impact the business
  • Perform QA / QC activities to drive configuration management program maturity
  • Support remediation efforts through gap identification and action plan creation to operationalize scan results
  • Participates in various tool testing and validation efforts for on-prem and cloud scanning

Required Qualifications :

  • Bachelor’s degree in IT or Cybersecurity
  • Experience with developing, customizing, reviewing and updating a wide range of enterprise security configuration baselines, with input from subject matter experts
  • Experience interpreting and applying CIS Benchmarks, DISA STIGs, SRGs, and has an awareness of the National Vulnerability Database (NVD) and Common Vulnerability Enumeration (CVE)
  • year of direct experience working with teams in an agile and horizontal environment
  • Experience with remediation activities within Cybersecurity
  • Ability to translate the low-level security baseline requirements into security baselines
  • Ability to work independently to anticipate needs, support a changing landscape and willingness to act with minimal supervision

Preferred Qualifications :

  • Knowledge and understanding of technology operations / processes, as well as experience with evaluating technology-related risks and controls
  • Experience in working with the NIST Special Publication series and providing guidance for risk management and security control implementation, including - and others.
  • Experience with one or more of the following technologies : Networking (including CISCO or Palo Alto); Operating Systems (including Windows Server, RedHat, or Linux);

Cloud Services (including GCP, AWS, and Azure)

  • Ability to apply a technical skill set to research and document industry knowledge and best practices with established or newly released applicable security controls
  • Written and verbal communication skills : articulate and effective communicator and presenter, able to describe complex problems in both technical and business terms
  • Demonstrated experience learning new technologies
  • Experience with an Agile methodology
  • Knowledge of ServiceNow and Archer
  • 30+ days ago
Related jobs
Axelon Services Corporation
Charlotte, North Carolina

Job Title: Info Security Gov & Risk Specialist (Hybrid). Defines, enhances, and implements information security configuration controls, while ensuring consistent and effective information security administration procedures and processes. Analyze internal information security controls and convert con...

Promoted
Allied Universal®
Concord, North Carolina

Sworn Police Officer, Crowd Management, Access Control, Patrol, Emergency Response, Campus Police, School Resource Officers. Sworn Police Officer in North Carolina. Provide police services to our clients by carrying out safety and police procedures, and when appropriate, emergency response activitie...

Promoted
SPX Enterprises
Charlotte, North Carolina

As an IT Web and Content Specialist you will be responsible for SPX's enterprise web properties including the internet and intranet platforms, as well as working with key technology partners in the delivery of digital business initiatives. SPX is an affirmative action and equal opportunity employer ...

Promoted
Selective Insurance
Charlotte, North Carolina

Employees receive comprehensive total rewards packages - including competitive compensation and performance awards, health benefits, and retirement savings - and professional development opportunities and flexible schedules to support their health, wealth, and well-being. Consults with IT senior man...

Promoted
Innova Solutions
Charlotte, North Carolina

Sr Information security Analyst. Sr Information security Analyst. ...

Promoted
Allied Universal
Concord, North Carolina

Sworn Police Officer in North Carolina. Sworn Police Officer, Crowd Management, Access Control, Patrol,. Emergency Response, Campus Police, School Resource Officers. Provide police services to our clients by carrying out safety and police procedures, and when. ...

Promoted
Pinnacle Group, Inc.
Charlotte, North Carolina

Position: Sr Security Risk Analyst. In this role, you will:· Serve as an analyst in executing the risk management control for infrastructure vulnerability zero-day rated vulnerabilities. Information Security Analysis experience, or equivalent demonstrated through one or a combination of the followin...

Promoted
Mentra
Charlotte, North Carolina

The Advanced Cybersecurity Analyst will play a pivotal role in safeguarding the organization’s digital assets and sensitive information by identifying and mitigating cybersecurity threats. Advanced Cybersecurity Analyst. The role requires expertise in security protocols, advanced risk analysis, and ...

Promoted
Robert Half
Charlotte, North Carolina

Troubleshoot and resolve issues related to WAN/LAN connectivity, routers, firewalls, and network security. Educate and assist users on best practices for system usage, security, and IT processes. Proven experience in IT support, particularly with Microsoft technologies (Windows Server, Active Direct...

Promoted
Technical Source
NC, United States

Project Manager Process Engineering, Commissioning Qualification Validation (CQV), Process Engineer Pharmaceutical, Project Management in Biotech, GMP Compliance, FDA Regulatory Compliance, Validation Engineer, Equipment Qualification (IQ/OQ/PQ), Pharma Manufacturing Projects, Pharmaceutical Product...