Search jobs > Boca Raton, FL > Security analyst

Security Analyst (GRC Analyst) (Advanced)

V2Soft
Boca Raton, FL
Full-time

Summary :

The management, assessment, and mitigation of risks are fundamental components of our information assurance and cyber security program at the client.

This position leads the IT security risk and audit program for information systems security using generally accepted standards and frameworks for IT audit and risk management (, NIST, ISO, PCI, and ISACA).

The position is responsible for the development and implementation of the IT security risk and audit strategy that perform information systems and business process risk assessments and evaluate the effectiveness of technical, physical, and administrative controls to identify control weakness.

This individual will interface with the Security Operations, IT Operations, and various business units to :

  • Perform PCI, SOC, ISO, and applicable client cybersecurity controls-related reviews to ensure that current, new, and technology infrastructure complies with these standards and Department's security policies.
  • Plan and perform IT security controls effectiveness. Manage remediation efforts for the identified gaps including assessment of new or enhanced implemented controls.
  • Maintain IT security risk and compliance matrix and performs management reporting. This will include IT systems controls, and business process risks to meet compliance requirements.

Provide risk mitigation strategies

  • Maintain Third Party Risk Management Program (TPRM) and analyze SOC- and other reporting including mapping to key IT security and compliance controls such as NIST, PCI, and COBIT.
  • Manage IT security vulnerabilities management program aligned with PCI and NIST standards.
  • Identifying and ranking the value, sensitivity, and criticality of the operations and assets that could be affected should a threat materialize in order to determine which operations and assets are the most important.
  • For the most critical and sensitive assets and operations, estimating the potential losses or damage that could occur if a threat materializes, including recovery costs.
  • Identifying cost-effective actions to mitigate and reduce risk. These actions can include implementing new organizational policies and procedures as well as the design of technical or physical controls.
  • Coordinating, tracking, and verifying remediation of audit findings.
  • Documenting the results and developing a plan of action and milestones for mitigating any identified risk.
  • Produce formal audit reports based on ISACA Audit Standards.
  • Promotes compliance with regulatory requirements ( PCI DSS) and IT best practices.

GRC Risk Analyst Skills & Requirements :

  • years of IT Audit experience (CISA certified preferred)
  • years of IT Risk Management lifecycle experience
  • years of hands-on technical experience ( developer, system administrator)
  • Experience working with NIST - Risk Assessment Standard
  • Extensive experience with IT General Controls evaluation and design
  • Advanced skill level in business process mapping and documentation as well as policy and procedure development
  • Recent experience in Information Security with up-to-date knowledge of the current threat landscape.
  • Solid understanding of PCI DSS standards

Education and Certifications :

  • Bachelor's Degree in Computer Science, Information Systems, Business Administration, or other related field and / or equivalent work experience.
  • CISA and CISSP certifications (preferred).
  • 23 days ago
Related jobs
Promoted
VirtualVocations
Tamarac, Florida

A company is looking for a Security Operations Analyst to analyze and respond to security threats. Cyber Security, Data Analytics, Computer Science, or related fieldWorking knowledge of SQL and basic programming/scripting skillsProven experience with log querying and analysis using industry-standard...

V2Soft
Boca Raton, Florida

This position leads the IT security risk and audit program for information systems security using generally accepted standards and frameworks for IT audit and risk management (, NIST, ISO, PCI, and ISACA). Perform PCI, SOC, ISO, and applicable client cybersecurity controls-related reviews to ensure ...

Promoted
VirtualVocations
Tamarac, Florida

A company is looking for a Senior Cyber Security Analyst to join their Information Security team. ...

Promoted
MotionPoint
Coconut Creek, Florida

This person will be responsible for analyzing and managing overall information security across various aspects, including technical, organizational, and policy-based components. Conduct Risk assessments to identify and evaluate potential security risks and impact on the organization. Assist in devel...

Promoted
VirtualVocations
Tamarac, Florida

A company is looking for a Business Analyst ADM with experience in security projects and project management. ...

Promoted
CyberTec
Boca Raton, Florida

Job Title: Security Manager, functioning as Senior Security PCI Compliance Analyst Job #: 6800. Certified Information Security Manager (CISM) or Certified Information Security Auditor (CISA). Job Family: Security Management. This position reports to the Security Risk and Compliance Office (SRCO) Man...

Brooksource
Boca Raton, Florida

This position leads the IT security risk and audit program for information systems security using generally accepted standards and frameworks for IT audit and risk management (e. Perform PCI, SOC2, ISO, and applicable State of Florida cybersecurity controls-related reviews to ensure that current, ne...

Motionpoint Corp
Coconut Creek, Florida

Key Competencies Experience with data protection, disaster recovery, business continuity and implementation Strong analytical skills, as well as written and verbal communication skills Detailed knowledge of IT controls, including security concepts and terminology related to applications, databases, ...

Lockheed Martin
Florida

Complete an information system security course of instruction appropriate to level of responsibilities. Familiar with information system security architectural documentation standards. Able to apply information assurance / cyber security standards, directives, guidance and policies to an architectur...

FIS
Virtual from Any State, FL , United States of America

Primarily responsible for API application security but with a good working knowledge of other security domains (Cryptography, Identity and Access Management, Threat and Vulnerability Management). Hands-on experience performing application API security assessment, static and dynamic security assessme...