Sault Ste Marie, MI
1 day ago
Govt. IT - Security Analyst

POSITION SUMMARY:

The Security Analyst, under the direction of the Director of IT Security, is responsible for monitoring and safeguarding the organization's IT systems, data, communications, operations and networks from cyber security breaches and cyber threats. Working with IT security hardware, software and processes that they help to implement and maintain, the Security Analyst continually monitors all systems and communications for threats and potential threats. Works Security team and other IT team members to implement and configure firewalls, network segmentation, internet traffic monitoring, data encryption and all other cyber security best practices.

ESSENTIAL FUNCTIONS: (includes, but is not limited to, the following)

●       Security Monitoring:

-          Monitor and analyze security alerts and incidents.

-          Conduct regular security assessments and audits.

●       Incident Response:

-          Participate in all incident response testing and plans.

-          Investigate and respond to all security incidents.

●       Vulnerability Management:

-          Identify and assess vulnerabilities in systems and applications.

-          Coordinate and track the remediation of vulnerabilities.

●       Security Policies and Procedures:

-          Recommend and assist with new security policies and procedures.

-          Ensure compliance with policies and regulatory requirements.

●       Security Awareness:

-          Participate in creating and providing security awareness training for employees.

-          Promote a security-conscious culture within the organization.

●       Network Security:

-          Work closely with the IT team and IT Security to install, configure and maintain firewalls, intrusion detection/prevention systems, and other security hardware and software.

-          Monitor network traffic for unusual activity.

●       Security Technologies:

-          Deploy and maintain security technologies on endpoint and network devices (antivirus, encryption, etc.).

-          Evaluate and recommend new security solutions.

●       Security Documentation:

-          Maintain documentation related to security configurations and processes.

●       Collaboration:

-          Work closely with IT teams to implement security best practices.

-          Collaborate with external vendors on security-related matters.

 

ADDITIONAL RESPONSIBILITIES: (includes, but is not limited to, the following)

●                   All other job-related duties as assigned.

CONTACTS:

Immediate peers, peers in other departments, immediate supervisor/manager, managers in other departments, executives, Board of Directors, customers and outside vendor/service providers.

PHYSICAL REQUIREMENTS:

Position medium with lifting of 50 pounds maximum. Physical factors include constant use of near vision and typing; frequent walking, sitting, kneeling, use of midrange/color vision; and occasional standing carrying, lifting, pushing/pulling, climbing, stooping, crawling, reaching, manual handling, use of hearing, smell and far vision, depth perception and field of vision, typing and bending. Working conditions include occasional exposure to extreme cold and noise. Potential hazards include frequent computer and equipment use and occasional exposure to moving mechanic parts, electric shock, client contact and medical equipment.

REQUIREMENTS:

Education: Associate’s Degree in Computer Science, Computer Information Systems Management or Technology related field required or three years of experience in IT security may be considered in lieu of a degree.

Experience: Two years of experience in a technical IT support or cybersecurity support position in a large business environment required in addition to the above-stated education requirements.

Certification/License: Must undergo a Criminal Background Investigation done under the rules of the National Indian Gaming Commission.  Must have a valid driver’s license and be insurable by the Sault Tribe Insurance Department. Must comply with annual driver’s license review and insurability standards with the Sault Tribe Insurance Department. Will be required to complete and pass pre-employment drug testing.

 

Knowledge, Skills and Abilities: Broad understanding of common business software, hardware and operations required.  Knowledge of IT networks, databases, wide-area-networking, internet connectivity and backup and storage of systems and data.  Knowledge of Microsoft Active Directory, Microsoft Windows, file servers, databases and communication systems preferred. Knowledge of IP based networks hardware and communication preferred. Knowledge of cybersecurity best practices, business continuity and incident response planning required. Knowledge of PERL, Java, HTML, MySQL, python, Web Application Programming and Linux preferred. Understanding of fundamental concepts in information security including confidentiality, integrity, and availability (CIA triad), risk assessment methodologies, threat modeling, and defense-in-depth strategies. Knowledge of current and emerging cyber threats, attack vectors, and malware trends. Understanding of threat actors, their motivations, and tactics, techniques, and procedures (TTPs). Familiarity with relevant regulatory requirements such as GDPR, HIPAA, PCI-DSS, MICS, CJIS and industry standards like ISO 27001/2. Understanding of legal and compliance frameworks applicable to data protection and privacy. Proficiency in risk assessment methodologies such as NIST SP 800-30, FAIR (Factor Analysis of Information Risk), and OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation). Knowledge of vulnerability assessment tools and techniques. Understanding of common vulnerabilities and exposures (CVEs), vulnerability databases, and patch management processes. Familiarity with various security technologies including firewalls, intrusion detection/prevention systems (IDS/IPS), antivirus solutions, encryption techniques, secure network architecture, and security information and event management (SIEM) systems. Must have organizational skills and be able to plan, prioritize and manage workload to meet goals in a timely manner. Must have excellent communication skills and be able to communicate clearly in person, in writing, and by telephone and email. Strong problem-solving skills required. Must be able to establish and maintain effective communication with co-workers, supervisors and the general public. Must be able to use word processing, spreadsheet and database software. Must be able to work extended hours when needed. Must be flexible and available to work various shifts, including nights, weekends and holidays. Position required being on-call based on business needs. Must maintain confidentiality. Native American preferred.

Confirmar seu email: Enviar Email