Sr. Security Analyst
Javen Technologies
Client Location: Chicago, IL
Contract : 12+ Months (Long Term Contract)
Working Mode: Hybrid (2-3 Days in Office)
JOB DESCRIPTION :
ROLE OBJECTIVE (Manager Perspective):
- Add capacity to existing security analysts and assist with operational tasks
- Perform security risk assessments, quantify risk, facilitate risk decisions, and provide advisory services to business and technology stakeholders.
- Support existing team of security analysts with different types of vulnerability remediation and vulnerability functional process improvements: (Infrastructure, Container, SAST, DAST)
- Supporting miscellaneous project work supporting Cyber Risk Management, Security Awareness, and Vulnerability Management Programs
Contract Duration: 1-year
In-Office Requirement: We would require this candidate to be in the office 2-3 days a week, preferably on days when the rest of the team is also in the office for collaborative purposes. (Mon-Thurs)
Job Description Summary - We are seeking a skilled and motivated Sr. Security Analyst to join our team! The ideal candidate will be responsible for adding depth to the Cyber Risk Management Program, supporting the Bank's Vulnerability Management Program, Security Awareness Program, and provide hands-on support for day-to-day security operations to ensure a resilient and secure environment. The addition of this role will help establish a more mature cybersecurity risk management capability by enabling proactive security risk assessments, risk quantification, and consultation activities that complement our existing vulnerability management and operational security functions.
Requirements:
- 4-year college degree in information technology, cyber security or equivalent experience OR Security and technology certifications are preferred (Security+, Microsoft Azure, AWS, etc.).
- Security risk assessment experience.
- Understanding of NIST CSF, NIST 800-53, ISO 27001, CIS Controls, or similar frameworks.
- Experience evaluating technical and administrative controls.
- Risk scoring and risk quantification experience.
- Strong documentation and report-writing skills.
- Ability to communicate risk to non-technical audiences.
- 2-5 years of vulnerability management experience.
- Experience with vulnerability scanning tools such as Nexpose, Qualys or Nessus is a plus
- Experience with Servicenow Vulnerability Response Module is a plus
- Experience with Infrastructure, Container, SAST, DAST vulnerability remediation is a plus
- Excellent analytical and problem-solving skills.
- Demonstrated experience evaluating security statistics to identify patterns and produce metrics that can be used for strategic decision making.
- Be a clear and confident public speaker, able to tailor messaging around technical concepts to diverse audiences.
- Ability to quickly learn new processes and tools
- Naturally curious and driven to understand how technologies, applications, and business processes operate.
Key Responsibilities:
- Add depth to the Cyber Risk Management Function of the Team.
- Assist with efforts to quantify and analyze areas of risk in the environment.
- Design and operationalize a robust, actively maintained Security Risk Register that informs security priorities, drives risk based decision making, and directly supports the Bank's overall security strategy through improved processes, governance, and reporting.
- Demonstrates intellectual curiosity and a desire to continuously learn, investigate security concerns, challenge assumptions, and identify emerging risks, threats, and opportunities for security improvement.
- Work with existing staff to identify and create process improvements to the existing vulnerability management and security awareness programs
- Work with remediation teams to create and track plans to address discovered vulnerabilities.
- Identify and evaluate vulnerability metrics to determine areas of concern and improvement.
- Creating and adhering to procedure documents.
- Perform Vendor Security and Software Risk Assessments.
- Contribute to Security Awareness efforts on an as needed basis.
- Support Misc. operational tasks
- Manage and resolve incoming service requests and incidents through a ticketing system.
- Evaluate new technologies and solutions to ensure alignment with organizational security policies, standards, and risk tolerance before adoption.
- Review and assess SOC2 reports as part of vendor security evaluations.
- Review and respond to phishing emails reported by users, and escalate if necessary.
Enhancing Qualifications:
- Familiarity of Infrastructure, Container, SAST, DAST vulnerability remediation concepts from a vulnerability management remediation perspective is a plus. This role will work with existing application security resources to enhance the existing vulnerability management program.
- Experience conducting risk assessments is a plus
- Self-starter who can work independently as well as in a team setting
- Experience with Data Visualization Tools
- Ability to think critically, ask thoughtful questions, and challenge assumptions in a constructive manner.
1640 - Information Security Analyst
Sigma Defense
Sigma Defense is currently seeking an Information Security Analyst to work in support of the Army for the Network Modernization & Mission Network Technical Service Support program (NetMod). NetMod sets forth the work efforts required to provide product technical support services for systems and equipment being produced, fielded, modified, or supported by PdM Network Modernization (NetMod) and PdM Mission Network of the Project Manager (PM) Tactical Network (TN) of the Program Executive Office for Command Control and Communications-Tactical (PEO C3T). This support may also include future systems and equipment that is acquired for the Army to maintain its technological advantage.
Equal Opportunity Employer/Veterans/Disabled: Sigma Defense Systems is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against on the basis of disability.
Requirements
- 5+ years of relevant experience.
- 3+ years in the Department of Defense contracting market of major weapon systems product development and acquisitions.
- Familiarity with cybersecurity compliance tools such as STIG Viewer and eMASS.
- Must be able to remain in a stationary position 50% of the time.
- Needs to occasionally move about inside the office to access file cabinets, office machinery, etc.
- Must be a U.S. citizen.
Education Requirements:
- Bachelor's degree from an accredited college or university in Information Security or related field of study.
- Formal education may be waived on a case by case basis depending on certification and relevant work/military experience.
Personnel Clearance Level:
- Candidate must possess or have the ability to obtain an active Secret security clearance or higher.
- A clearance will not be sponsored.
Essential Job Duties (not all-inclusive):
- Provide network environment and advanced level computing environment support.
- Pay special attention to intrusion detection, finding and fixing unprotected vulnerabilities, and ensuring that remote access points are well secured.
- Collect data from a variety of Computer Network Defense (CND) tools (including data from approved information assurance (IA) tools to include intrusion detection system alerts, firewall and network traffic logs, and host system logs) to analyze events that occur within their environment.
- Apply analytical skills to this data and all compliance with relevant non-technical controls, such as physical security and configuration management, to perform an audit function for the Agent of the Certification Authority (ACA) or other government Information Assurance (IA) Manager for mitigation of risks and reporting to include report generation for certification and accreditation packages or Certification of Net worthiness efforts.
- Conduct vulnerability assessments, risk analysis, and incident responses.
- Actively monitor network traffic for suspicious activity and potential security breaches.
- Identify weaknesses in systems and applications to proactively address security risks.
- Frequently communicate with co-workers, management, and customers, which may involve delivering presentations.
Salary Range: $85,000 - $101,000 annually.
Benefits
- Dental and Vision Insurance
- Medical Insurance to Include HSA, FSA, and DFSA Plans
- Life and AD&D coverage
- Employee Assistance Program (EAP)
- 401(k) Plan with Company Matching Contributions
- 160 Hours of Paid Time Off (PTO)
- 12 (Floating) Holidays
- Educational Assistance
- Highly Competitive Salary