Search jobs > Chicago, IL > Security and risk analyst

Security and Risk Analyst

Taft Stettinius & Hollister LLP
Chicago, IL, United States
Full-time

Taft is seeking a Security and Risk Analyst to support our Information Technology team in our Chicago, Cincinnati, Cleveland, Columbus, Dayton, Detroit, Indianapolis or Minneapolis office.

Job Summary :

The Security and Risk Analyst is responsible for ensuring Taft's digital assets and those of our clients are protected from unauthorized access through a multi-discipline approach, actively identifying and mitigating suspicious activity while evaluating and updating policy and conducting and analyzing security assessments at the direction of the Security and Risk Manager.

Duties / Responsibilities :

  • Responds to security alerts, indications of compromise and helpdesk security incident tickets in real time, gathering information and taking action to protect the firm and communicating findings.
  • Assists the Security and Risk Manager in performing and analyzing the results of internal and external security audits, security assessments, vulnerability testing and risk analysis.
  • Assists the Security and Risk Manager in developing and deploying end user training programs and working with users on compliance.
  • Assist IT and teams in verifying the security of third-party vendors, collaborating with them to meet security requirements.
  • Monitoring security access, vendor access, remote access, and anomalies.
  • Supports periodic reviews by internal audit, compliance teams and other risk-related functions as required.
  • Adhere to all IT Department standards and Firm Information Security Policies, including but not limited to change control and maintenance windows.
  • Adhere to IT ITIL (Information Technology Infrastructure Library) disciplines and processes, including, but not limited to : ITSM (IT Service Management);

Incident Management; Change Management and Problem Management.

  • Obtains, maintains, and applies knowledge of relevant areas (attends seminars; reads periodicals; participates in outside organizations).
  • Works with the firm's MSSP to ensure network is secure.
  • Monitors network for security related issues including, but not limited to, abnormal access attempts, suspected malware, and possible breaches and ANY potential weaknesses.
  • Works with helpdesk to identify and resolve possible security events and incidents, providing timely and relevant in-house escalation support, adhering to ticketing procedures and SLA requirements.
  • Researches new software applications intended to make the Firms' system more secure.
  • Drafts documentation as requested for security related policies and procedures
  • Assists training team with preparing relevant security training plans and materials and assessing their adoption rate and effectiveness.

Knowledge, Abilities, Skills, Other Requirements

  • Proficiency and understanding of current cyber security technologies encompassing perimeter / edge next generation security, endpoint security, heuristic security, and security related monitoring.
  • Ability to be available after hours and remotely to respond to threat alerts and possible attacks.
  • Ability to write reports, knowledge base articles and short procedures
  • Clear thinking in a crisis or stressful situation.
  • Travel is not required on a regular basis, although some out-of-the-area and overnight travel may be expected.
  • Background in Cybersecurity principles and best practices.
  • Proficiency in Windows operating systems as it pertains to security threats.
  • Proficiency in Firewalls, application monitoring, securing the network perimeter.
  • Demonstrates teamwork (is receptive to and acts upon input from others, is willing and able to compromise as needed, displays willingness to work with all Firm employees, willingly assists others).
  • Demonstrates initiative (contributes new ideas, is self-motivated).
  • Demonstrates organizational skills and effective use of time (ability to plan, set priorities and manage time to ensure work is timely and efficiently completed per department plan and budget parameters).
  • Demonstrates flexibility (willing to adjust to changes, able to work with all levels of Firm employees).
  • Exhibits dependability (maintains presence in all office locations as appropriate).
  • Adheres to strict confidentiality standards (keeps confidential all information concerning firm matters and clients).

Education and Experience :

  • Bachelor's degree or equivalent work experience.
  • Three plus years Cybersecurity-related work experience.
  • Security or Microsoft certifications desired.
  • Familiarity with helpdesk ticketing systems such as Service Desk Plus or ServiceNow.
  • Law firm experience preferred.

Candidates interested in the Chicago office should apply here .

Candidates interested in the Cincinnati office should apply here .

Candidates interested in the Cleveland office should apply here .

Candidates interested in the Columbus office should apply here .

Candidates interested in the Dayton office should apply here .

Candidates interested in the Detroit office should apply here .

Candidates interested in the Indianapolis office should apply here .

Candidates interested in the Minneapolis office should apply here .

Taft is a State of Minnesota and City of St. Paul Affirmative Action Employer as required in those jurisdictions. Taft is an Equal Opportunity Employer.

The information in this posting presents general duties, tasks, and responsibilities but is not intended to be an exhaustive listing.

Taft Stettinius & Hollister LLP participates in E-VERIFY .

Less than 1 hour ago
Related jobs
Promoted
The AZEK Company
Chicago, Illinois

Develop, enhance, and operationalize enterprise-wide cyber security policies, standards, and controls to mitigate risks and comply with applicable laws and regulations. Develop and operationalize a cyber security risk management program to identify risks across the organization, provide recommendati...

Promoted
Bank of America Corporation
Chicago, Illinois

Evaluates and supports the risk identification documentation, validation, assessment, and/or mitigation processes necessary to ensure that existing and new systems and processes meet Enterprise information security requirements and risk appetite. We hire individuals with a broad range of backgrounds...

Promoted
PayPal
Chicago, Illinois

The PayPal People & Places (P&P) Business Risk and Control team is seeking a highly engaged and dynamic risk analyst to be a critical part of the P&P Business Risk & Controls team, a global front-line team responsible for managing and executing day-to-day risk management activities a...

Promoted
Northern Trust
Chicago, Illinois

Collaborate with Information Security, Privacy, and Risk Management teams to provide continuous improvement to Information Security and Technology Risk Policies and frameworks. Ensure that risk management programs communicate security policies and requirements so people know, understand and can foll...

Promoted
Ernst & Young
Chicago, Illinois

If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for ...

Buckingham Search
Chicago, Illinois

Provide risk guidance in developing, reviewing and maintaining operational risk and compliance policies and procedures as it relates to Information Technology and Information Security. Proficiency in information technology concepts and process flows and a general understanding of IT controls around ...

Dahl Consulting
Chicago, Illinois

Familiarity working with Risk Management Information Systems, implementation and data integrity, and use of system for data management and reporting. This company is hiring a Senior Insurance and Risk Management Analyst for a contract position! Interested? Get more details below!. What you will do a...

Northern Trust Corporation
Chicago, Illinois

Assists in the Third-Party Risk governance framework in the 1LOD, with oversight and reporting to C&IS and Global Services Leadership on related risk and control profile, issues / incidents and any relevant emerging risks. The Analyst will work within the team to closely interact with different stak...

BDO
Chicago, Illinois

The Manager, Data Risk & Security is responsible for supervising a team of RAS professionals in the review, documentation, evaluation and testing of general controls in a wide range of technology environments to analyze system security and access controls, backup recovery procedures and IS organizat...

CIBC
Chicago, Illinois

The role will report directly to the Director, Cybersecurity and Technology within (G&O) and support Information Technology (IT) and Information Security (IS) Management and work closely with 2nd and 3rd lines of defense (Risk, Compliance, and Internal Audit). Provide risk guidance in developing, re...