Summary:
We’re in search of Information
Security Analyst to monitor networks, manage SIEM, investigate breaches,
perform audits, and ensure compliance. Candidate should have strong
cybersecurity skills, experience with firewalls, encryption, vulnerability
testing, and knowledge of IT security frameworks. A degree in computer science
(or equivalent experience) plus certifications like Security+, CySA+, or OSCP
are preferred.
Here
are some of the specific details:
Job Title: IT Security Analyst
Location:
Frankfort, KY
Duration:
Long-term Indefinite Contract
NOTE: It’s a remote job
Job Description:
The Office of Application and
Technology Services (OATS) is seeking a highly motivated candidate for the role
of Security Analyst for the client reporting to the Chief Information Security
Officer. The Security Analysis responsible for reporting on security breaches,
installing software to protect sensitive information, monitoring the Client
network to watch for and prevent breaches, creating, and implementing a
security plan, as well as running regular simulated cyber-attacks to assess the
strength and vulnerability of computer systems. This job is a mid-level
position that requires an extremely responsible candidate to perform the
duties. Other responsibilities include:
Responsibilities:
·
Monitor
network resources for security issues.
·
Monitor
a Security Information and Event Management (SIEM)system to enhance the overall
cybersecurity of CHFS: Data Collection, Event Correlations, Incident Detection,
Investigation and Analysis, Response and Mitigation, Tuning and Optimization,
Compliance Monitoring
·
Investigate
security breaches and other cybersecurity incidents.
·
Develop
an audit to determine whether information systems are protected, controlled,
and provide value to the organization.
·
Conduct
audit follow-up to evaluate whether risks have been sufficiently addressed.
·
Install
security measures and operate software to protect systems and information
infrastructure, including firewalls and data encryption programs.
·
Communicate
audit progress, findings, results, and recommendations to stakeholders.
·
Document
security breaches and assess the damage they cause.
·
Work
with the security team to perform tests and uncover network vulnerabilities.
·
Fix
detected vulnerabilities to maintain a high-security standard
·
Develop
cabinet-wide best practices for IT security.
·
Help
colleagues install security software and understand information security
management.
·
Research
security enhancements and make recommendations to management.
·
Stay
up to date on information technology trends and security standards.
·
Maintain
and update relevant system and process documentation and develop ad-hoc reports
as needed.
·
Assist
in the development of security tool requirements, trials, and evaluations, as
well as security operations procedures and processes.
·
Provide
off-hours support on an infrequent, but as-needed basis.
·
Work
trouble tickets in the ticketing system
·
Conduct
meetings and work closely with system owners and departmental leads in all
business areas where ePHI and other confidential system data is found.
·
Assist
with continuous monitoring activities documenting within the eGRC tool whether
security and other related activities are consistently performed.
·
Perform
various support activities for other projects including obtaining information
and documentation to demonstrate policies, procedures, and
·
operational
processes that adhere to various regulations, policies, standards, and other
compliance requirements.
·
Collaborate
with OATS Departmental and other cross-agency staff to disseminate and engage
appropriate OATS Security Teams for any new projects, tasks, and/or
initiatives.
·
Lead
and coordinate any special projects and/or tasks as directed by management.
·
Prepare
reports for management.
Preferred Education & Experience:
·
Bachelor’s
degree in computer science, Software Engineering, or a related field
(equivalent professional experience may be considered for substitution for the
required degree on an exception basis).
Candidates with one or more of the
following certifications is a plus:
·
Offensive
Security Certified Professional (OSCP)
·
Offensive
Security Defensive Analysis (OSDA)*
·
Cybersecurity
Analyst (CySA+)
·
CompTIA
Security+
·
CompTIA
Advanced Security Practitioner (CASP+
·
CompTIA Pen
Test+
·
Certified
Network Defender (CND)
·
GIAC Security
Essentials (GSEC)
·
System Security
Certified Practitioner (SSCP) Knowledge, Skills & Abilities.
This is a partial listing of the
necessary knowledge, skills, and abilities required to perform the job
successfully. It is not an exhaustive list.
·
Ability to set
the tone for the organization and motivate management and team.
·
Understanding
of information security regulations, including the Federal Information Security
Management Act (FISMA), Federal Risk and Authorization Management Program
(FedRAMP), ISO 27001, COBIT NIST, and ITIL.
·
Maintaining
security, assessing and evaluating security, and doing security incident
forensic work. Knowledge of vendors and their products including:
·
Experience with
Government agencies, particularly the Department of Defense (DoD) on
information security matters. Experience with Government Classified systems and
the associated security requirements.
·
Updates job
knowledge by tracking and understanding emerging security practices and
standards; participating in educational opportunities; reading professional
publications; maintaining personal networks; and participating in professional
organizations.
·
Proficiency in
Microsoft Office Suite (Word, Excel, Outlook, etc.)
·
Innovative and
creative mindset
·
Basic network
security knowledge (general principles)
·
Excellent
documentation and communication skills.
·
Ability to
organize tasks into milestones and successfully execute to project completion.
·
Can work
independently with little direct supervision.
·
General
cyber-security understanding
Let
me know if you are interested in this job and/or if
you can assist us by referring someone who is interested in this job, since we
offer the lucrative referral bonuses.
Benefits will also
be available, and details are available at the following link: Harvey Nash Benefits
I am looking forward to speaking with you today.
About us:
Harvey Nash is
a national, full-service talent management firm specializing in technology
positions. Our company was founded with a mission to serve as the talent
partner of choice for the information technology industry.
Our company
vision has led us to incredible growth and success in a relatively short period
of time and continues to guide us today. We are committed to operating with the
highest possible standards of honesty, integrity, and a passionate commitment
to our clients, consultants, and employees.
We are part of
Nash Squared Group, a global professional services organization with over forty
offices worldwide.
For
more information, please visit us at https://www.harveynashusa.com/