Cyber Risk & Compliance Analyst

Rockville, MD, US • Posted 1 day ago • Updated 1 day ago
Full Time
Part Time
On-site
USD $65-74/hr
Fitment

Dice Job Match Score™

👾 Reticulating splines...

Job Details

Skills

  • Three years of information security experience including conducting risk assessments/audits/reviews of information systems and assessing and/or mitigating information security threats/risk and/or Three years of working experience with security requirements
  • systems
  • security architecture
  • as related to risk management.
  • Hands-on experience of cyber security and privacy industry
  • including the technology used to protect the confidentiality
  • integrity and availability of sensitive information.
  • Hands-on experience working knowledge of security frameworks and regulatory requirements such as NIST SP 800-171
  • CIS Controls
  • FERPA
  • GLBA
  • PCI-DSS
  • and privacy standards.
  • Knowledge
  • appreciation and prioritization of principles and practices of project organization
  • planning
  • records management
  • and general administration.
  • Working knowledge of IT enterprise operations
  • architecture
  • and IT as a Service.

Summary

DatamanUSA is looking for a Cyber Risk & Compliance Analyst for our direct client based in MD. This is a great opportunity for someone who is a quick learner with excellent people skills.

Job Details:

Job Title: Cyber Risk & Compliance Analyst

Location: Rockville, MD

Duration: 6 months



Hands-on Knowledge, Skills and Abilities:

*) Hands-on experience of cyber security and privacy industry, including the technology used to protect the confidentiality, integrity and availability of sensitive information.

*) Hands-on experience working knowledge of security frameworks and regulatory requirements such as NIST SP 800-171, CIS Controls, FERPA, GLBA, PCI-DSS, and privacy standards.

*) Knowledge, appreciation and prioritization of principles and practices of project organization, planning, records management, and general administration.

*) Working knowledge of IT enterprise operations, architecture, and IT as a Service.

*) Hands-on experience of vulnerability management principles, methodologies, and tools

*) Hands-on experience with patch management processes, secure configuration standards, and system hardening practices.

*) Hands-on experience knowledge of common threat vectors, exploitation techniques, and the vulnerability lifecycle.

*) Hands-on knowledge of risk management concepts, risk scoring, risk registers, and POA&M tracking.

*) Hands-on experience with SOC reports, third-party risk assessments, and due diligence reviews.

*) Hands-on experience to analyze vulnerability data, correlate findings with threat intelligence, and assess potential business impact.

*) Hands-on experience in interpreting scan results, identifying false positives, and validating remediation actions.

*) Ability to perform root-cause analysis for recurring or high-risk findings.

*) Strong attention to detail when documenting risks, findings, or compliance gaps.

*) Ability to manage multiple assessments, findings, risks, and remediation efforts simultaneously.

*) Hands-on experience in writing policies, standards, processes and procedures.

*) Hands-on experience in leading and/or conducting audits, assessments or reviews of technical systems and processes.

*) Effective verbal and written communication skills, presentation, and public speaking skills.

*) Effective skills in developing and presenting educational or training programs.

*) Effective planning, organizational and multi-tasking skills with minimal supervision.

*) Ability to think critically and analyze information and situations; present findings and make recommendations.

*) Ability to identify compliance and security needs independent of management direction.

*) Ability to grasp technical concepts at all levels of computer systems, from system hardware components and architecture to system integration and implementations.

*) Ability to work independently and as part of a team.

*) Ability to advise, train, and motivate technical and non-technical individuals in regulatory compliance and information and systems security efforts.

*) Ability to work effectively with an array of constituencies in a community that is both demographically and technologically diverse.

*) Ability to communicate technical concepts and data to non-technical audiences.

*) Ability to achieve goals through influence, collaboration, and cooperation.

*) Ability to communicate complex information, concepts, or ideas in a confident and well-organized manner through verbal, written, and/or visual means.

*) Ability to produce technical documentation.

*) Ability to handle and maintain confidential information.

*) Ability to exercise judgment when policies are not well-defined.

*) Ability to think critically, analyze issues and solve sensitive and complex problems under pressure.

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10109429
  • Position Id: DatamanUSA - 9006-9012-1775492218
  • Posted 1 day ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Washington, District of Columbia

Today

Full-time

USD 113,000.00 - 188,000.00 per year

Bethesda, Maryland

Today

Full-time

USD 154,050.00 - 278,475.00 per year

Rockville, Maryland

Yesterday

Easy Apply

Contract

Depends on Experience

McLean, Virginia

Today

Contract

$50.00 - $113.29 hourly

Search all similar jobs