MUST RESIDE IN INDIANAPOLIS, IN
Short Description :
Resource will work as an Information Security Analyst responsible for auditing and monitoring systems containing confidential information.
Complete Description :
Local candidates only (Indianapolis, IN).
The resource will serve as an Information Security Analyst responsible for auditing and monitoring systems that contain confidential information. This position helps the organization manage risk by monitoring IT systems for inefficiencies, inaccuracies, mismanagement, and related issues. Responsibilities include assisting with configuration of data, application, network, and IAM logs; supporting log reporting tools; and monitoring systems for potential security concerns.
The position participates in all aspects of technology audit and monitoring, including planning, control analysis, testing, issue development, and reporting. The role will also participate in federal and state audits related to the agency's technology systems. The employee works within the Information Technology Division of a state agency under the guidance of the Security Manager.
Essential Responsibilities :
- Monitor and keep supervisor informed of information security and confidentiality conditions, including problem areas and recommended enhancements.
- Interface with internal users to understand security needs and assist in implementing appropriate procedures, including training and assessments.
- Assist with preparation for security audits (e.g., IRS, SSA, OCSE, FBI, SBOA) and support remediation of audit findings; assist with creating and submitting audit-related reports.
- Develop information security policies and standards to protect information systems in alignment with state and federal requirements (e.g., IRS, SSA, OCSE, FBI, statewide IT policies) and guidelines (e.g., NIST SP 800-53).
- Develop Standard Operating Procedures (SOPs) for implementing security policies.
- Recommend appropriate security safeguards during the development of new and existing information technology systems.
- Ensure optimal use of hardware and software security features to protect automated systems and associated data.
- Develop and implement procedures for using information security management software.
- Recommend enhancements to information security software and tools.
- Conduct periodic audits to verify security policies and standards are being followed and remain effective.
- Develop recommendations for improvements and prepare related reports.
- Stay informed of new laws and changes affecting privacy standards, network security, cloud security, remote access, and physical security.
- Mentor and provide guidance to new or existing staff as needed.
- Perform related duties as assigned.
- Assist with additional tasks as required.
Knowledge, Skills, and Abilities :
Thorough knowledge of information security management tools, policies, and standards.Thorough knowledge of state and federal legislation and regulations related to information system security and privacy.Thorough understanding of software vulnerabilities, scanning tools, and remediation processes.Familiarity with domain structures, user authentication, and digital signatures.Ability to develop and maintain information security standards.Ability to understand and apply complex computer logic to daily work.Ability to work effectively with a broad range of IT professionals, including system administrators, technical support staff, application developers, end users, and management.Experience assessing team security needs and assisting with security training.Strong oral and written communication skills.Ability to function effectively as both a team member and a team leader, depending on the situation.Degree in information security or technology preferred.Security-related certifications preferred (e.g., CISSP).Network administration experience preferred.REQUIREMENTS :
Degree in Information Security or Technology3 years' experience with wide range of information technologists; including systems administrators, technical support, application development, end users, etc.3 years' experience with network adminAt least 3 years holding a Security certification (ex. CISSP, CRISC)1 years' experience developing and maintaining information security standards1 years' experience understanding and applying complex computer logic to workFamiliarity with cybersecurity security framework (ex. NIST, ISO, SOC 2, CIS, Cobit, Etc.)Experience with computer security compliance and auditingIRS, SSA computer security compliance and audit experienceHIPAA experienceSupervisory Responsibilities :
This role does not provide direct supervision.