Description : About the Role
We are seeking a highly experienced and dedicated IT Security Analyst 3 to join our security team in a fully remote capacity.
This senior role requires extensive experience in defending critical infrastructure, with a specific focus on environments that include Azure, Active Directory, and specialized operational technology (OT) systems like tolling and traffic management infrastructure.
The ideal candidate will leverage 9+ years of professional experience to perform security monitoring, incident response, vulnerability management, and contribute significantly to compliance efforts, particularly those involving PCI DSS 4.0+.
This position requires a strong technical background, exceptional analytical capabilities, and the ability to operate independently in a complex, hybrid IT / OT environment.
Key Responsibilities :
Security Monitoring & Incident Response :
- Conduct advanced analysis of security logs and events from SIEM tools to identify potential threats, vulnerabilities, and indicators of compromise (IOCs).
- Lead and execute the incident response workflow, including containment, eradication, and recovery for complex security incidents affecting critical infrastructure, cloud (Azure), and on-premises systems (IIS, SQL, Active Directory).
- Develop and maintain incident response playbooks and runbooks.
Vulnerability & Threat Management :
Perform security assessments and vulnerability scans on IT and OT assets, prioritizing remediation efforts based on risk and regulatory requirements (e.g., PCI DSS, NIST).Ensure robust system hardening and configuration standards are applied across servers, network devices, and specialized roadside equipment.Compliance & Audit Support :
Serve as a key resource for maintaining adherence to security frameworks, with a deep understanding of PCI DSS 4.0+ security requirements.Contribute to audits and assessments by providing evidence, documentation, and technical expertise related to security controls.Architecture & Operations Security :
Provide security guidance and support for operational environments, including systems related to tolling systems, traffic management infrastructure, or roadside equipment.Manage and secure environments that involve both state-managed and vendor-managed components, effectively collaborating with third-party vendors to ensure security standards are met via contracts and regular reviews.Maintain an accurate and complete asset inventory of all critical systems(ref : hirist.tech)