Software Guidance & Assistance, Inc., (SGA), is searching for a
Cyber/Cloud Security Analyst for a
REMOTE CONTRACT position with one of our premier
Healthcare Services clients. This position is fully remote however candidates should be located in
EST/CST time zones.
This is a good fit for you if you are a mid-to-senior level Information Security or Cyber Security Professional. As an Information Security Architect, you would hold an influential role. Your key responsibility would be to advise on the design and requirements for securing infrastructure and public cloud services. You would also play a pivotal role in reducing the likelihood of architectural or configuration-based vulnerabilities net new and existing public and private cloud services, thereby mitigating potential security risks. Your responsibilities will include collaborating with business and technical resources, reviewing project documentation, and referencing security policies/standards to offer recommendations and guidance. You will also have the authority to approve or reject project artifacts from a security perspective, ensuring the highest level of security for the organization's systems, processes, and services.
Responsibilities:
- Defining security requirements by evaluating business strategies and requirements; researching information security standards
- Providing consulting services and security support to internal business and technology customers
- Serving as the lead security liaison on assigned projects.
- Providing input and recommendations to the engineering teams related to the design, deployment, operations, and hardening elements that could impact the services or solutions from a security perspective.
- Reviewing service architecture and design from an information security perspective ensuring alignment with organization security standards and industry best practices.
- Serving as a subject matter expert (SME) for performing vendor risk assessments (including Cloud Services) to improve overall vendor risk program.
- Providing technical expertise on secure software development and support of all associated activities, processes, and tools for protecting technology-based information
- Validating controls for Encryption, Access Control, Web Application Vulnerability Detection, OWASP top 10 and other common web application security parameters.
- Reviewing, developing, testing, and implementing security plans, products, and control techniques
- Reviewing circumstances surrounding security gaps in and designs corrective actions
- Maintaining awareness of security and technology trends and shares that knowledge with others
- Evangelizing security policies, standards, and nonfunctional requirements where/when needed
- Daily and Weekly Status Reporting - for Work in Process and Planned and issues
- Documenting processes, procedures, assessment outputs, working papers documentation to support existing governance requirements
- Representing security and IT risks among other company risk departments and committees.
- Evaluating the effectiveness of awareness and training programs and makes recommendations for improvement.
- Mentoring less experienced team members and collaborating across Information Technology
What your background should look like:
- Bachelor's degree in computer science, Information Systems or other related field, or equivalent work experience
- 10-15 years of combined IT and security work experience with a broad range of exposure to systems analysis, application development, systems administration and over five years of experience designing and deploying security for infrastructure, cloud, and cybersecurity services at the enterprise level.
- Preferred Certification in one or more Information Security relevant areas such as Audit (CISA), Security Management (CISM), Security Professional (CISSP), Cloud Security (CCSP), CCSK, CEH, AZ500, SC100, CCNP, CCIE
- Hands on experience managing and securing public and private cloud services
- Requires in-depth knowledge of security issues, techniques, and implications across all existing computer platforms.
- Experience with evaluating and implementing security controls as related to Cloud based services including SaaS, PaaS, IaaS.
- Strong computer skills to operate effectively with company systems and programs
- Working knowledge of network solutions and systems
- Good analytical and critical thinking skills
- Ability to communicate effectively both orally and in writing
- Good interpersonal skills
- Ability to prioritize workload and consistently meet deadlines
- Strong organizational skills; attention to detail
- Ability to lead and provide direction to project/product teams
- Strong consultative skills: ability to interface effectively with technical and non-technical leaders.
- Understands Information Security as it relates to the business and other areas of IT; understands direct impacts and risks.
- Demonstrated sound understanding of at least 3 of the following control frameworks such as ISO 27001/27002, HITRUST, CMMC, NIST, CIS, GDPR and PCI
- Business experience in a matrix Organization required
SGA is a technology and resource solutions provider driven to stand out. We are a women-owned business. Our mission: to solve big IT problems with a more personal, boutique approach. Each year, we match consultants like you to more than 1,000 engagements. When we say let's work better together, we mean it. You'll join a diverse team built on these core values: customer service, employee development, and quality and integrity in everything we do. Be yourself, love what you do and find your passion at work. Please find us at .
SGA is an Equal Opportunity Employer and does not discriminate on the basis of Race, Color, Sex, Sexual Orientation, Gender Identity, Religion, National Origin, Disability, Veteran Status, Age, Marital Status, Pregnancy, Genetic Information, or Other Legally Protected Status. We are committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, and our services, programs, and activities. Please visit our company to request an accommodation or assistance regarding our policy.