Information Security Analyst - W2

eTek IT Services, Inc.
Boston, MA, US
Full-time

Job Description

Job Description

Role : Information Security Analyst

Location : Boston, MA

Experience : 8+ years

W2 Contract

Required Skills

  • Professional certifications such as CISSP, CISM, CRISC, or similar are highly desirable.
  • Minimum of 3-5 years of experience in information security, risk management, or a related field.
  • Strong knowledge of security frameworks and standards (e.g., NIST, ISO 27001, COBIT).

Additional Skills

Job Description

Summary of the Position

This posting is for an Information Security Analyst to assist the Executive Office for Administration and Finance IT (A F IT).

A F IT is seeking a highly skilled and detail-oriented Information Security Analyst to join the Office of the Chief Information Security Office (CISO) team.

The ideal candidate will be responsible for coordinating internal and external audits, performing comprehensive risk assessments, and developing robust security policies.

This role requires a deep understanding of security frameworks, regulatory requirements, and best practices to ensure the organization's information assets are protected against potential threats.

Key Responsibilities :

  • Coordinate security audits between 3rd& party auditors and IT teams
  • Meet with auditors and confirm scope of engagements
  • Gather and organize responses and evidence
  • Consolidate materials and analyze content for completeness and accuracy
  • Solicit and coordinate reviews with security team SME(s)
  • Present information to auditors and other key stakeholders
  • Document and track progress of Corrective Action Plans
  • Policy and Procedure administration
  • Manage catalog of Information Security Policies and Procedures
  • Ensure annual reviews and updates are complete
  • Work with the Department of Revenue’s (DOR’s) Risk Management team to identify business impact of policies
  • Conduct Internal IT risk assessments
  • Interview SMEs and document in-place controls against NIST800-53
  • Identify control deficiencies
  • Drive remediation of deficiencies
  • Facilitate Risk assessments of 3rd& party vendors
  • Maintain schedule of assessments
  • Maintain 3rd& party vendor questionnaires
  • Coordinate assessments between vendor, business and
  • Collect and consolidate responses
  • Escalate 3rd& party vendor control weaknesses to security team SME(s)

Qualifications :

  • Professional certifications such as CISSP, CISM, CRISC, or similar are highly desirable.
  • Minimum of 3-5 years of experience in information security, risk management, or a related field.
  • Strong knowledge of security frameworks and standards (e.g., NIST, ISO 27001, COBIT).
  • Experience with risk assessment methodologies and tools.
  • Excellent analytical and problem-solving skills.
  • Strong written and verbal communication skills, with the ability to convey complex information to a non-technical audience.
  • Detail-oriented with strong organizational skills and the ability to manage multiple tasks simultaneously.

Key Competencies :

  • Proactive approach to identifying and mitigating security risks.
  • Ability to work independently and as part of a team.
  • Strong interpersonal skills and the ability to work effectively with stakeholders at all levels of the organization.
  • High level of integrity and ethical conduct.
  • Commitment to continuous improvement and staying updated with the latest security trends and technologies
  • 30+ days ago
Related jobs
Promoted
Ignyte AI
Canton, Massachusetts

This position is responsible for analyzing the information security environment for Point32Health and developing security measures to safeguard the confidentiality, integrity, and availability of corporate information and data. Reporting to the Cybersecurity Manager, the Security Analyst will work c...

Global Atlantic
Boston, Massachusetts

Global Atlantic is looking for an enthusiastic professional to join the Information Security Risk Management team as a Senior Security Analyst focusing on Governance, Risk, and Compliance (GRC). The Senior Security Analyst will work with minimal supervision and contribute to the development, mainten...

MIT
Cambridge, Massachusetts

REQUIRED: bachelor’s degree; five years of experience in cybersecurity or related field and at least three years’ information security experience; broad understanding of networking, security, and system administration concepts; experience with security tools (i. Information Systems and Technology (I...

Randstad
Woburn, Massachusetts

Under the supervision of the Head of Information Security, the Information Security Analyst is expected to perform and enhance user access rights reviews and monitoring, perform information asset risk assessments, perform additional periodic information security monitoring, and assist in business co...

Mass General Brigham
Somerville, Massachusetts

Information Security Analyst III Vulnerability Remediation Program Lead-(3290329). The Mass General Brigham (MGB) Information Security Analyst III Vulnerability Remediation Lead will be critical in developing and implementing vulnerability remediation procedures and prioritization to protect our hos...

RPMGlobal
Boston, Massachusetts

Additionally, the Information Security Operations Analyst assists in the response to business disruptions, security incidents and other control functions as necessary to satisfy the Information Security Team’s responsibilities. Familiar with basic information security concepts, including user accoun...

Analysis Group
Boston, Massachusetts

The Information Security Analyst will work with the Director of Information Security and Risk Management on the continuous improvement and development of the firm’s cybersecurity, compliance, and governance programs. As the Information Security Analyst, you are the organizing force responsible for p...

Point32Health, Inc.
Canton, Massachusetts

This position is responsible for analyzing the information security environment for Point32Health and developing security measures to safeguard the confidentiality, integrity, and availability of corporate information and data. Reporting to the Cybersecurity Manager, the Security Analyst will work c...

Abacus Technology Corporation
Hanscom Air Force Base, Massachusetts

Abacus Technology is seeking an Information Security Analyst to support security and information assurance activities for Hanscom AFB. Plan, implement, upgrade, or monitor security measures for the protection of computer networks and information. Ensure appropriate security controls are in place tha...

MORS
Somerville, Massachusetts

Responsibilities include: responding to suspicious cyber security activities, incidents, and tickets; analyzing information from a wide range of sources including logs and data from network devices, applications, and security tools, from other security and IT professionals, and from Internet sources...