Search jobs > Washington, DC > Information security

Information Security Analyst

MORS
United States - Nationwide
$90 an hour
Full-time

Details

Posted : 27-Aug-24

Location : United States - Nationwide

Type : Full Time

Currency :

United States, Dollar (USD)

Region : United States

United States

Salary Details :

Compensation Range : $90, - $, annual salary based on experience and geographic location

Preferred Education :

4 Year Degree / Bachelor Degree

Additional Information :

Telecommuting is allowed.

Internal Number : QSA-08-

Information Security Analyst

Information Security Analysts have an in-depth understanding of information security with the ability to quickly understand a client’s business environment and security requirements.

This knowledge must be coupled with an in-depth understanding of at least one of today's leading information security frameworks : PCI DSS, HIPAA / HITECH, GLBA, or ISO .

The Analyst must use this knowledge to audit and assess a client’s security posture as it relates to business drivers and ascertain compliance with established security and privacy requirements.

Analysts must present clear findings to the client in written and verbal form.

Compensation Range :

$90, - $, annual salary based on experience and geographic location

Benefits :

Dara offers a full benefits package. We pay % of employee premiums for healthcare insurance (medical, dental, vision), offer a k plan with company match, Profit Sharing Plan, certification / training bonuses, monthly internet expense reimbursements, well-being expense reimbursements, personal days off in addition to earned Paid Time Off, and opportunities to earn top-level industry certifications.

Work Authorization, Location and Schedule :

Candidates must be legally authorized to work in the United States and be able to pass a background check. This is not a position for which sponsorship will be provided.

This full-time position is % remote and requires the ability to work well independently to complete projects accurately & on time.

The role requires occasional travel to client locations both within and outside of the United States. Hours of work may vary and depend on the project assigned to the analyst.

Required Certifications (must be current and not expired) :

One of the following information security designations : (ISC)2 CISSP, ISACA CISM or ISO Lead Implementer

One of the following auditing designations : ISACA CISA, GIAC GSNA, ISO Lead Auditor, ISO Internal Auditor, IRCA ISMS Auditor (or higher), or IIA CIA

Education Requirements :

Bachelor's degree in Information Security, Cybersecurity, Information Technology, Computer Science or related field, or equivalent experience

Job Duties :

  • Conduct PCI assessments and gap analyses
  • Perform auditing techniques and procedures that support assessment findings
  • Create quality, customized reports that detail the client’s control environment and assessment findings
  • Formulate a roadmap of actionable steps for improving the client’s security posture and / or achieving compliance
  • Effectively communicate complex technical information to a variety of audiences, including executive level and technical decision-makers
  • Interact with customers to schedule and perform activities as detailed in SOWs
  • Consult with clients to help them understand assessment findings and remediation options
  • Work with Sales Professionals and customers to provide presales and scoping assistance as needed
  • Develop subject matter expertise across various industries focusing in information security and privacy requirements
  • Consistently update Dara Security’s CRM and work management platforms to ensure accurate tracking of project activities

Experience Requirements :

  • Minimum two years of recent experience in a role conducting internal IT audits, external IT audits or leading PCI DSS assessments
  • Minimum two years of recent experience in an information security role
  • Minimum one year of recent experience with Payment Card Industry (PCI) compliance activities
  • Demonstrated English language proficiency that enables clear written & speech expression, proficient reading, and verbal comprehension
  • Solid understanding and execution of audit procedures
  • Detail-oriented with excellent time management, organization, follow-up, and follow-through skills
  • Familiarity / general networking knowledge with various security control processes, technologies & solutions, including cloud security, vulnerability management, firewalls, IAM, SIEM, EDR, IDS / IPS, DLP, AV, FIM, WAF, cryptography, software development, networking, communication protocols, etc.
  • Proficient with MS Word, MS Excel, and PowerPoint
  • Ability to handle interruptions in a challenging environment
  • Team player with a positive attitude who can independently complete projects with minimal management oversight
  • Driven to learn new technologies and audit techniques

Preferred Qualifications :

  • Current (not expired) PCI QSA certification
  • Current PCIP certification

Required Certifications (must be current and not expired) :

One of the following information security designations : (ISC)2 CISSP, ISACA CISM or ISO Lead Implementer

One of the following auditing designations : ISACA CISA, GIAC GSNA, ISO Lead Auditor, ISO Internal Auditor, IRCA ISMS Auditor (or higher), or IIA CIA

Education Requirements :

Bachelor's degree in Information Security, Cybersecurity, Information Technology, Computer Science or related field, or equivalent experience

Job Duties :

  • Conduct PCI assessments and gap analyses
  • Perform auditing techniques and procedures that support assessment findings
  • Create quality, customized reports that detail the client’s control environment and assessment findings
  • Formulate a roadmap of actionable steps for improving the client’s security posture and / or achieving compliance
  • Effectively communicate complex technical information to a variety of audiences, including executive level and technical decision-makers
  • Interact with customers to schedule and perform activities as detailed in SOWs
  • Consult with clients to help them understand assessment findings and remediation options
  • Work with Sales Professionals and customers to provide presales and scoping assistance as needed
  • Develop subject matter expertise across various industries focusing in information security and privacy requirements
  • Consistently update Dara Security’s CRM and work management platforms to ensure accurate tracking of project activities

Experience Requirements :

  • Minimum two years of recent experience in a role conducting internal IT audits, external IT audits or leading PCI DSS assessments
  • Minimum two years of recent experience in an information security role
  • Minimum one year of recent experience with Payment Card Industry (PCI) compliance activities
  • Demonstrated English language proficiency that enables clear written & speech expression, proficient reading, and verbal comprehension
  • Solid understanding and execution of audit procedures
  • Detail-oriented with excellent time management, organization, follow-up, and follow-through skills
  • Familiarity / general networking knowledge with various security control processes, technologies & solutions, including cloud security, vulnerability management, firewalls, IAM, SIEM, EDR, IDS / IPS, DLP, AV, FIM, WAF, cryptography, software development, networking, communication protocols, etc.
  • Proficient with MS Word, MS Excel, and PowerPoint
  • Ability to handle interruptions in a challenging environment
  • Team player with a positive attitude who can independently complete projects with minimal management oversight
  • Driven to learn new technologies and audit techniques

Preferred Qualifications :

  • Current (not expired) PCI QSA certification
  • Current PCIP certification
  • 30+ days ago
Related jobs
Promoted
RAND Corporation
Washington, District of Columbia

As an AI and Information Security Analyst, you'll directly impact AI and cybersecurity policy at the highest levels of government and industry, contributing to the security and integrity of powerful AI systems. A master's degree in Computer Science, Computer Engineering, Electrical Engineering, Cybe...

Promoted
Chenega Corporation
Washington, District of Columbia

Implement and Manage Security Monitoring Tools: Oversee the implementation and management of SIEM (Security Information and Event Management) systems to monitor network and system activity for signs of suspicious behavior, anomalies, and potential security incidents. Information Security Analyst II....

Promoted
Mathematica Policy Research
Washington, District of Columbia
Remote

Possession of or ability to obtain professional certifications in information security or risk management, such as Certified Information System Security Professional (CISSP), CGRC – Governance, Risk and Compliance Certification, Certified Information Security Manager (CISM) or other relevant certifi...

Promoted
Avert Staffing
Washington, District of Columbia

Minimum of 2 years of experience in IT security, including intrusion detection and prevention, vulnerability scanning, reporting, incident response and forensics, malware analysis, security awareness. Respond to security incidents, including investigations and forensics. Track and report on all secu...

Promoted
A1fed
Washington, District of Columbia
Remote

Develop and maintain security documentation related to configuration management, including System Security Plans (SSPs), security configurations, and configuration management policies. Bachelor’s degree in Information Security, Computer Science, or related field (or 8+ years of relevant experience)....

Promoted
Course Advisor
Washington, District of Columbia

What Do Information Security Analysts Do?. Life As an Information Security Analyst. What an Information Security Analyst Should Know. When polled, Information Security Analysts say the following skills are most frequently used in their jobs:. ...

Promoted
Chenega Corporation
Washington, District of Columbia

Information System Owner (ISO) Support including planning and execution of Systems Engineering Life Cycle (SELC) processes, providing information security expertise, preparing SELC security documents, ensuring appropriate security controls are applied, and continuous monitoring during operations and...

ST2 ManTech Advanced Systems Intl
Washington, District of Columbia

Knowledge and experience with information network security equipment. Provides information to management regarding the negative impact caused by theft, destruction, alteration or denial of access to information. Provides recommendations on information assurance engineering standards, implementation ...

Chenega Corporation
Washington, District of Columbia

Information System Owner (ISO), including planning and execution of security processes within the Systems Engineering Life Cycle (SELC), preparing SELC security documents, ensuring appropriate security controls are applied, providing continuous monitoring during operations, and reviewing and providi...

General Dynamics Information Technology
Washington, District of Columbia

Department of State are seeking a Program Advisor oversee international capacity-building trainings aimed at addressing pressing nuclear security, proliferation, safety, and sovereignty challenges posed by aggressive civil nuclear reactor exports. Establish a civil nuclear power program under the hi...