Information Security Analyst
Los Angeles, CA
Open to Remote
Full Time
$100k - $120k
A Global Enterprise company we are working with is looking for an Information Security Analyst. This person is a professional responsible for ensuring the security of an organization's information systems and data within the context of GEI. Their primary role is to identify, analyze, and mitigate security risks and threats to protect the confidentiality, integrity, and availability of information assets.
Role and Responsibilities:
Role and Responsibilities:
- Conduct regular assessments of the organization's information systems, networks, and applications to identify vulnerabilities, weaknesses, and potential security risks.
- Develop and implement security measures, policies, procedures, and standards to safeguard the organization's information assets and ensure compliance with relevant regulations and industry best practices.
- Monitor and analyze security logs, alerts, and incidents to detect and respond to security breaches, intrusions, and unauthorized access attempts.
- Investigate security incidents and perform root cause analysis to determine the impact, extent of damage, and necessary remediation steps.
- Perform regular security audits and risk assessments to evaluate the effectiveness of existing security controls and identify areas for improvement.
- Participate in incident response activities, including incident handling, containment, eradication, and recovery.
- Contribute to the development and maintenance of disaster recovery and business continuity plans, ensuring the availability and resilience of critical systems and data.
- Assist in conducting internal and external security audits and regulatory compliance assessments.
- Bachelor's degree in Computer Science, Information Technology, or a related field. Relevant certifications (e.g., CISSP, CISM, CEH) are highly desirable.
- Proven experience in information security roles, preferably in large enterprise environments.
- In-depth knowledge of information security principles, concepts, standards, and best practices, such as ISO 27001, NIST Cybersecurity Framework, and CIS Controls.
- Strong understanding of networking protocols, architectures, and infrastructure components.
- Familiarity with security technologies, including firewalls, intrusion detection/prevention systems, antivirus/anti-malware solutions, data loss prevention, and identity and access management systems.
- Experience in security incident response, including incident investigation, containment, eradication, and recovery.
- Proficiency in security assessment tools and techniques, vulnerability scanning, and penetration testing.
Posted by: Amanda Oliver