Technical or audit experience in core infra & cyber security fields such as IAM, vulnerability/threat management, Pen-Testing, Data Protection, IH/IR, AppSec, Network/Endpoint Security, System Administrator, GRC, ITSM, Infra Platform/Servers & Controls, Cloud Operations, IT Resiliency
Understanding of Technology Risk & Controls across domains
Knowledge of performing risk management and industry standards (e.g., NIST)
Ability to proactively assess issues, identify solutions, and problem solve
Ability to understand and interact with technology subject matter experts regarding technology topics
Analytical, consultative, and communication skills with ability to communicate control requirements to partners in terms easily understood
Organized and time management skills, with ability to produce high quality timely deliverables
Flexible approach towards changing work methods, deadlines, and variable workloads
Ability to adapt and react timely and positively in a changing and dynamic work environment
Knowledge of Microsoft Office Suite and ability to learn new tools as needed
Applicable industry standard certification(s) desired
Bachelor degree
Responsibilities
Provides technical expertise and support to client, IT management, and staff in risk assessments and implementation
Identifies, evaluates, conducts, schedules, and leads technical analyses functions to ensure all applicable IS security requirements are met
Participates in the evaluation, development, implementation, communication, monitoring, and maintenance of information technology security policies and procedures
May act as Project Member and conducts preliminary analysis and reviews work of others
May be involved in providing assistance and training to lower level specialists
Keeps abreast on the direction of emerging industry standards
Provides technical analysis of requirements necessary for the protection of all information processed, stored, or transmitted by systems
Serves as a resource or go-to person within a group
Participates in the development and maintenance of tech & cyber security standards in line with industry best practices
Supports technical engagements around security threats & vulnerabilities and software security testing
Supports risk and control assessments for core cyber tech domains and remediation of infra & cyber tech findings from various sources
Solves problems and timely manages open risk and control gaps