Senior Information Security Analyst

Senior Information Security Analyst

28 May 2024
Maryland, Rockville, 20847 Rockville USA

Senior Information Security Analyst

Vacancy expired!

Job Description

Overview
The Senior Information Security Analyst is a member of the IT Operations team and works closely with the other members of the IT team and other business areas to develop and implement a comprehensive information security program. This includes defining security policies, processes, and standards. The security analyst works with the IT department and managed service providers to select and deploy technical controls to meet specific security requirements and defines processes and standards to ensure that security configurations are maintained.

Primary Responsibilities

  • Works with the company’s business units and with other risk functions to identify security requirements, using methods that may include risk and business impact assessments.
  • Collaborates on critical IT projects to ensure that security issues are addressed throughout the project life cycle.
  • Researches, evaluates, and recommends information-security-related solutions, including developing business cases for security investments.
  • Liaisons with the vendor management team to conduct security assessments of existing and prospective vendors, especially those with which the organization shares intellectual property, PII, ePHI, regulated or other protected data, including: SaaS provider, Cloud as a service (IaaS/PaaS) providers, and managed service providers.
  • Evaluates the statements of work from these providers to ensure that adequate security protections are in place. Assesses the providers’ SSAE 16 SOC 1 and SOC 2 audit reports (or alternative sources) for security-related deficiencies and required “user controls,” and report any findings.
  • Oversees the installation and configuration management of security systems and applications, including policy assessment and compliance tools, network security appliances and host-based security systems by managed service providers.
  • Liaisons with the business continuity management team to validate security practices for both disaster recovery planning (DRP) and business continuity management (BCM) testing and operations when a failover occurs.
  • Researches threats and vulnerabilities and, where appropriate, coordinates action to mitigate threats and remediate vulnerabilities.
  • Participates in security investigations and compliance reviews, as requested by internal or external auditors.
  • Tracks developments and changes in the digital business and threat environments to ensure that these are adequately addressed in security strategy plans and architecture artifacts.
  • Validates that security and other critical patches to firmware and operating systems are configured and deployed in a timely fashion.
  • Facilitates threat modeling of services and applications that correlates to the risk and data associated with the service or application.
  • Ensures that a complete, accurate and valid inventory of all systems, infrastructure and applications is conducted that for assessment an included in security event monitoring solutions.
  • Coordinates with the Legal and Compliance team to document data flows of sensitive information within the organization (e.g., PII or ePHI) and recommends controls to ensure this data is adequately secured.
  • Coordinates security assessments of internal systems, applications, and IT infrastructure as part of the overall risk management practice of the organization.
  • Supports e-discovery processes to include identification, collection, preservation and processing of relevant data.


Qualifications

  • Degree/Diploma in an information system and/or information security related discipline.
  • 8+ years of progressive experiencing in information security roles involved with assessment, response, eradication, and recovering from security attacks.
  • Experience in SaaS system environments, particularly Microsoft 365, NetSuite ERP and Veeva Systems (QualityDocs, Training, QMS, PromoMats, CRM).
  • Working knowledge of the Microsoft Advanced Threat Protection platform.
  • Experience working in a public life sciences company supporting GxP and business systems.
  • Experience in developing, documenting, and maintaining security programs, policies, processes, procedures, and standards.
  • In-depth knowledge and understanding of information risk concepts and principles, as a means of relating business needs to security controls.
  • In-depth knowledge of risk assessment methods and technologies.
  • Proficiency in performing risk, business impact, control and vulnerability assessments.
  • Strong understanding of business applications, including ERP and financial systems.
  • Demonstrated experience in creating and maintaining strong relationships and accountability with external service providers.
  • Strong verbal and written communication skills
  • Wholistic, logical, and analytical thinker.
  • Validated Systems (e.g., Good Automated Manufacturing Practice [GAMP], Computer Software Assurance)
  • Working knowledge of Sarbanes-Oxley Act
  • National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) knowledge
  • Working knowledge of General Data Protection Regulation (GDPR)


Preference will be given to candidates with the following certifications: CISSP, CRISC, CISM, CISA, GIAC, or CIPT.

We appreciate flexibility at Aurinia. This role is posted as Rockville, MD but as a distributed organization, we are open to fill this role in a remote capacity or out of our Victoria, BC location.

Additional Information

All candidateinformation will be kept confidential according to EEO guidelines

Related jobs

  • Sr. Financial Analyst | Rockville, MD

  • Syms Strategic Group (SSG)  is seeking a talented Senior Database Architect

  • Description

  • Bausch + Lomb (NYSE/TSX: BLCO) is a leading global eye health company dedicated to protecting and enhancing the gift of sight for millions of people around the world—from the moment of birth through every phase of life. Our mission is simple, yet powerful: helping you see better, to live better.

  • Summary This position is located in the Office of the Chief Financial Officer (OCFO), Division of the Comptroller (DOC), Labor Administration & Fee Billing Branch (LAFBB), Fee Billing Team. The supervisor is Regina Revinzon. This position is Bargaining Unit with the National Treasury Employees Union, Chapter 208. The position is not subject to Confidential Financial Disclosure or security ownership restriction reporting requirements. Responsibilities As a Senior Financial Management Specialist, you will be responsible for assisting with the coordination of agency license fee billing including analyzing, monitoring, and timely recording of financial information into the Agency\'s accounting system and the review and oversight of the accounting data related to fee billing. Responsible for providing quality assurance oversight and conducting quality assurance activities over the Part 170 and Part 171 license fee billing programs to ensure invoicing accuracy and providing technical and analytical support for invoicing activities. Provides oversight of the Financial and Accounting Integrated Management Information System (FAIMIS) data integrity and consistency, conducts reconciliation activities between the Web-Based Licensing (WBL) system and FAIMIS, and performs general oversight of interfacing systems to support the billing program (WBL, EDMS, CACS, HCM, eBilling). Proactively handles and investigates potential fee-related issues, and prioritizes issues in terms of risk and importance, and develops work plans that detail a schedule to complete corrective actions as well as resources needed for completion. Assesses functions within the branch for automation eligibility and leads efforts to develop and implement process enhancements and improvements to increase the efficiency and accuracy of fee billing activities. Requirements Conditions of Employment U.S. Citizenship Required This is a Drug Testing position. Background investigation leading to a clearance is required for new hires. You must meet the qualifications for this position by no later than 30 calendar days after the closing date of this announcement and before placement in the position. Qualifications In order to qualify for this position, you must have at least one year of specialized experience at the next lower grade level in the Federal service or equivalent experience in the private or public sector. The ideal candidate will be able to demonstrate the following: Experience planning, developing, and coordinating the agency’s license fee billing policy and guidance for financial management improvements as required by the CFO’s ACT, FMFIA, GPRA, OMB Circulars, JFMIP requirements and NRC Management Directives and appropriate parts of Title 10 of the Code of Federal Regulations (CFR). In-depth knowledge of 10 CFR Parts 170, 171 and 15.31, and relevant Management Directives or similar Federal regulations. Extensive knowledge of computer systems and software sufficient to provide oversight of fee billing programs. Knowledge in the application of Robotic Process Automation (RPA) and skill in identifying functions for automation. Extensive skill in presenting information, ideas and advice in a clear, concise, and logical manner, both orally and in writing. Extensive ability to establish and maintain effective work relationships with all levels of personnel. SPECIALIZED EXPERIENCE is defined as: Demonstrated extensive knowledge and understanding of financial systems, financial management policies, theories, concepts, principles and standards, and performing billing related transactions and activities in agency enterprise resource planning core financial systems, including overseeing data integrity and consistency and performing system reconciliation activities; performing quality assurance oversight over billing activities, in accordance with Federal regulations and directives; conducting technical analyses and preparing reports using data visualization tools; analyzing internal controls; and reviewing, analyzing, and resolving moderately complex issues that may affect billing activities. Specialized experience includes progressively responsible experience that is in, or closely related to, the work of the position that has provided the particular knowledge, skills, and abilities to successfully perform the duties of the position at the GG-14 grade level. Education Additional Information The duty location of this position is Rockville, Maryland. In general, employees are expected to be in the office at a minimum of 4 days per pay period. Telework schedules, including full-time telework, are approved, on a case-by-case basis. If selected, telework will be determined in accordance with Agency policy and the Collective Bargaining Agreement, if applicable.

  • We understand that the world we want tomorrow starts with how we do business today, and that’s why we’re inspired to make A Better World for Pets. Antech is comprised of a diverse team of individuals who are committed to each other’s growth and development. Our culture is centered on our guiding philosophy, The Five Principles: Quality, Responsibility, Mutuality, Efficiency and Freedom. Today Antech is driving the future of pet health as part of Mars Science & Diagnostics, a family-owned company focused on veterinary care.

  • Position Objective: Provide services as a Computer Systems Analyst in support of the overall functions of the National Institute of Mental Health (NIMH) within the National Institutes of Health (NIH). Contractor will independently provide support services to satisfy the overall operational objectives of the National Institute of Mental Health (NIMH).

Job Details

  • ID
    JC14542787
  • State
  • City
  • Job type
    Full-time
  • Salary
    N/A
  • Hiring Company
    NXTThing RPO, LLC
  • Date
    2021-05-20
  • Deadline
    2021-07-19
  • Category

Jocancy Online Job Portal by jobSearchi.