We're looking for a Senior Information Security Analyst to strengthen our organization's cybersecurity defenses. The ideal candidate will have extensive experience in information security, a solid understanding of a wide range of security technologies, and the ability to effectively communicate complex security risks to a variety of audiences. This role is crucial for conducting risk assessments, monitoring systems, and responding to security incidents.
Key Responsibilities
- Risk Assessment : Conduct regular assessments to identify vulnerabilities and risks within the organization's cybersecurity measures.
- Monitoring & Analysis : Use various tools to monitor networks and systems for security breaches. Analyze incidents to understand their root causes and assist with investigations and remediation efforts.
- Reporting : Prepare detailed reports on security issues, including breach incidents, current risk status, and recommendations for improvement.
- Policy & Training : Assist in developing and updating security policies. Conduct security awareness training programs, particularly those related to phishing campaigns .
- Cloud Security : Secure cloud environments such as Azure, AWS, and GCP .
Required Qualifications
Education : Bachelor's degree in Information Security, Computer Science, Computer Engineering, Information Technology, or a related field.Experience : A minimum of 8 years of experience in Information Security.Certifications : An Information Security certification such as CISSP, GSEC, or Security+ is required.Technical Skills :Expert knowledge of two or more security technologies, including EDR, IPS, SIEM, SOAR, CASB, CAASM, IAM, PAM, NAC, MFA, and DLP .A broad understanding of network and security protocols like DNS, SPF / DKIM / DMARC, SSL / TLS, TCP / UDP, and IPSec.Experience with frameworks such as CIS Critical Security Controls, OWASP Top 10, and MITRE ATT&CK .Knowledge of compliance frameworks like ISO 27001, SOC 2, and NIST .Soft Skills : Excellent oral and written communication skills with the ability to convey complex security concepts and risks to both technical and non-technical personnel.Skills Required
Information Security, Azure, Aws, Gcp, Communication Skills, EDR