Assists and/or leads various information security projects and initiatives throughout the year, which may include scoping, execution, documentation, and reporting, and reviewing the work of other project team members from an information security perspective.
Provide consultative support on behalf of InfoSec to other department s security-related efforts and projects, as needed. This includes assisting IT as well as the broader organization with helping them understand how to implement security controls, procedures, and standards.
Support the Information Security team s risk management efforts by performing security-related risk and control assessments, developing mitigation strategies and recommendations, and managing and tracking security issues to ensure they are appropriately addressed.
Assist our Encore entities with achieving and maintaining compliance with various information security frameworks (i.e., NIST Cybersecurity Framework, FFIEC, ISO 27001, etc.) and with industry and government rules and regulations as they relate to IT/security (e.g., SOX, PCI DSS). MINIMUM REQUIREMENTSField of Study : Graduation+. Computer Science, Information Systems, Information Security
ATTRIBUTES:
Knowledge of countermeasures against common attacks on web applications, app servers, databases, wireless & wired networks, and related cloud technologies.
Working knowledge of cybersecurity technology evaluation and provide feasibility assessments.
Knowledge of security frameworks such as NIST 800-53, ISO 27001, NIST Cybersecurity Framework, CIS Critical Controls
Knowledge in application of threat modeling or other risk identification techniques
Experience and technical knowledge in security engineering, system and network security, authentication and security protocols, cryptography, and application security
Ability to provide technical direction and act as a subject matter expert as it relates to information security engineering for IT, to include but not limited to Network, Cloud, Applications, and Infrastructure
Able to articulate threat and risk modeling and able to communicate technical concepts in simple terms both verbally and in written reports.