Information Systems Security Officer
Job description
About the role
As an , you will play a crucial role in safeguarding the organization's information systems and data integrity. This position is designed for a proactive individual who possesses a deep understanding of cybersecurity principles and practices. You will work collaboratively with various teams to implement security measures, conduct risk assessments, and ensure compliance with industry standards. Your expertise will help shape the security posture of the organization, making it a safer place for both employees and clients.
Key facts
What you'll do
- Develop and implement comprehensive security policies and procedures to protect the organization's information systems from unauthorized access and cyber threats.
- Conduct regular security assessments, including vulnerability scans and penetration testing, to identify potential weaknesses in the system.
- Collaborate with IT teams to ensure that all systems are configured securely and that security best practices are followed during the development and deployment of new applications.
- Monitor network traffic and system logs for unusual activities and respond promptly to security incidents, ensuring minimal disruption to business operations.
- Provide training and awareness programs for employees to promote a culture of security within the organization.
- Stay updated on the latest cybersecurity trends, threats, and technologies, and recommend improvements to enhance the organization's security posture.
- Prepare and present detailed reports on security incidents, risk assessments, and compliance audits to senior management.
- Liaise with external auditors and regulatory bodies to ensure compliance with relevant laws and standards, such as GDPR, HIPAA, and NIST.
- Manage security incidents and breaches, including the investigation, documentation, and remediation of security events.
- Assist in the development of disaster recovery and business continuity plans to ensure the organization can respond effectively to security incidents.
- Evaluate and recommend security tools and technologies to enhance the organization's security infrastructure.
- Work with cross-functional teams to integrate security into the software development lifecycle (SDLC) and ensure that security considerations are part of every project.
Requirements
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- A minimum of 5 years of experience in information security or a related field, with a strong focus on risk management and compliance.
- Proven experience with security frameworks such as NIST, ISO 27001, or CIS Controls.
- Strong understanding of network protocols, firewalls, intrusion detection systems, and encryption technologies.
- Experience with security assessment tools and methodologies, including vulnerability management and penetration testing.
- Excellent analytical and problem-solving skills, with the ability to think critically and make informed decisions under pressure.
- Strong communication skills, both verbal and written, to effectively convey complex security concepts to non-technical stakeholders.
- Relevant certifications such as CISSP, CISM, or CEH are highly desirable.
- Familiarity with cloud security principles and technologies, particularly in AWS or Azure environments.
- Ability to work independently and as part of a team in a fast-paced environment.
Nice to have
- Experience in a government or defense contracting environment is a plus.
- Knowledge of programming languages such as Python, Java, or C++ for security automation tasks.
- Familiarity with security information and event management (SIEM) solutions.
- Experience with incident response and forensics tools and techniques.
- Understanding of data privacy regulations and compliance requirements.
Skills & tools
- Proficient in security assessment tools (e.g., Nessus, Qualys, Burp Suite).
- Familiarity with SIEM tools (e.g., Splunk, LogRhythm).
- Knowledge of endpoint protection solutions and threat intelligence platforms.
- Strong grasp of operating systems (Windows, Linux) and their security configurations.
- Experience with scripting languages for automation (e.g., PowerShell, Bash).
Practical notes
- The specific location for this position is currently unknown, but it may involve remote work or travel based on project needs.
- The salary for this role is competitive and will be determined based on the candidate's experience and qualifications.
- Visa sponsorship is available for candidates who meet the necessary requirements.
If you are passionate about cybersecurity and want to make a significant impact in a dynamic organization, we invite you to apply for the Information Systems Security Officer position at Prominentedge. Join us in our mission to protect vital information and ensure the safety of our systems and data.