Information Security Analyst - GRC

Phoenix, AZ, US • Posted 1 hour ago • Updated 1 hour ago
Full Time
On-site
USD 46.51 per hour
Fitment

Dice Job Match Score™

⭐ Evaluating experience...

Job Details

Skills

  • SAP GRC
  • Data Flow
  • Activity Diagrams
  • Requirements Elicitation
  • Risk Assessment
  • Reporting
  • Network
  • Documentation
  • Technical Drafting
  • Editing
  • Writing
  • Research
  • IT Security
  • HIPAA
  • Internal Auditing
  • Risk Management
  • Authorization
  • Auditing
  • Internal Control
  • Database Administration
  • Software Development
  • Computer Networking
  • Cyber Security
  • Privacy
  • Communication
  • Policies and Procedures
  • Management
  • Regulatory Compliance
  • Information Security Management
  • Information Security
  • IT Management
  • Leadership
  • Problem Solving
  • Conflict Resolution
  • Training
  • Customer Service
  • Information Systems
  • Data Analysis
  • NIST 800-53
  • Risk Management Framework
  • RMF
  • Microsoft Windows
  • Unix
  • Project Management
  • CISSP
  • Cisco Certifications
  • Technical Direction

Summary

Location: Phoenix, AZ (Hybrid)
Duration: Contract to Hire
Payrate: $46.51/HR


***(Need only W2 and Local Candidates in Phoenix, AZ)***

Job Summary:

We are seeking an experienced and highly motivated individual to join our team as an Information Security Analyst (ISA) contractor. This position will work on the Governance, Risk and Compliance (GRC) Team to communicate and engage with business units to develop a strong understanding of their reporting, data, and product needs.

The team member will work with other personnel across departments to define requirements for projects, identify data dependencies and relationships to develop logical and physical data models, data flows and system activity diagrams, and write specifications for managing enterprise information policies. The team member will help develop plans and materials to support user adoption, training, and customer service, working through direct and regular contact with users from other divisions, programs, and service units to provide regular insight and guidance in prioritizing enhancements for the data systems.

The team member will also support technical project managers to ensure that all aspects of the information analysis and requirements gathering process are completed with the highest degree of accuracy and quality, which includes developing and socializing key project artifacts.

Job Duties:
  • Perform risk assessments, audit reviews, generate findings reports, and make appropriate recommendations for improvement and track outcomes from those activities for reporting requirements. Develop and formulate comprehensive reports detailing the findings, areas of non-compliance, required POA&Ms (Plan of Action and Milestones), environmental observations, and incident reports.
  • Review, update, and manage security-related audit plans, security plans, and risk plan documentation for accuracy and consistency, proactively solving problems.
  • Evaluate data and formulate comprehensive reports detailing the findings, areas of non-compliance, required action plans, and environmental observations. Generate incident reports and investigate suspicious network activity.
  • Prepare audit documentation that supports audit results, drafting and editing audit findings to adhere to standards and the agency's writing style.
  • Research agency and industry IT security practices, standards, best practices, laws and regulations, and other applicable resources, and ensure compliance with standards.
Knowledge, Skills & Abilities:
  • Knowledge of security principles, policies, and procedures, and ability to develop effective security policies.
  • Knowledge of Information Security Risk Management.
  • Knowledge of laws, regulations, policies, principles, and ethics as they relate to cybersecurity and privacy. Required: NIST 800-53 R5, IRS Pub 1075, HIPAA/HITRUST, CJIS and MARS-E.
  • Expert knowledge of internal auditing, internal controls, and risk management practices and methods.
  • Knowledge of Selection/Approval, Implementation, and Assessment/Audit of Security and Privacy Controls.
  • Knowledge of Risk Management Framework (RMF) requirements.
  • Knowledge of Authorization/Approval of Information Systems.
  • Knowledge in conducting audits or reviews of technical systems.
  • Knowledge and comprehensive understanding of internal control environments within the IT function.
  • Knowledge in multiple technology domains, including aspects of Windows, Unix and/or database administration, software development, and networking.
  • Knowledge in identifying cybersecurity and privacy issues that stem from connections with internal and external customers and partner organizations.
  • Ability to produce high-quality work products for both IT groups and Senior Management.
  • Ability to demonstrate excellent interpersonal, written, and oral communication skills.
  • Ability to assess, manage, and improve security policies and procedures.
  • Ability to work collaboratively in teams and across organizations.
  • Ability to synthesize feedback and adjust plans accordingly, build strong relationships inside and outside the organization, and manage large teams.
  • Ability to ensure security practices are followed throughout all phases of the life cycle of every aspect of business and IT processes.
  • Ability to develop policy, plans, and strategy in compliance with laws, regulations, policies, and standards in support of organizational cyber activities.
  • Ability to exercise judgment when policies are not well-defined.
  • Ability to ensure information security management processes are integrated with strategic and operational planning processes.
  • Ability to ensure that senior officials within the organization provide information security for the information and systems that support the operations and assets under their control.
  • Ability to understand technology, management, and leadership issues related to organizational processes and problem solving.
  • Ability to understand the basic concepts and issues related to cyber and its organizational impact. Develop plans and materials to support user adoption, training, and customer service.
  • Ability to work collaboratively in teams and across organizations.
  • Develop plans and materials to support user adoption, training, and customer service.
  • Work directly with users from other divisions, programs, and service units to provide insight and guidance.
  • Identify risks and suggest improvements to information systems and processes.
  • Support technical project managers to fulfill information analysis requirements with the highest degree of accuracy and quality.
  • Develop and maintain key project artifacts.
Required Skills:
  • NIST 800-53 R5 (Must Have)
  • Risk Management Framework (RMF)
  • Windows/Unix experience
Preferred Skills:
  • Project Management experience
  • CISSP, CCSP, GSTRT, GSNA, or CAP certification

#LI-TD1
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: sharpdec
  • Position Id: 53235
  • Posted 1 hour ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Hybrid in Phoenix, Arizona

Today

Easy Apply

Contract

Depends on Experience

Hybrid in Phoenix, Arizona

Today

Full-time

Depends on Experience

Phoenix, Arizona

Today

Easy Apply

Contract

Remote or Phoenix, Arizona

Today

Full-time

USD 70,000.00 - 78,543.00 per year

Search all similar jobs