Talent.com
Information Security Analyst
Information Security AnalystAnalysis Group • Boston, MA, US
Information Security Analyst

Information Security Analyst

Analysis Group • Boston, MA, US
[job_card.30_days_ago]
[job_preview.job_type]
  • [job_card.full_time]
[job_card.job_description]

Overview

Make an impact at Analysis Group, where we provide our clients with thoughtful, pragmatic solutions to their most challenging business and litigation problems. Analysis Group is one of the largest private economics consulting firms, with more than 1,200 professionals across 14 offices in North America, Europe, and Asia. Since 1981, we have provided expertise in economics, finance, health care analytics, and strategy to top law firms, Fortune Global 500 companies, and government agencies worldwide. Our internal experts, together with our network of affiliated experts from academia, industry, and government, offer our clients exceptional breadth and depth of expertise.

The Information Security Analyst will work with the Director of Information Security and Risk Management on the continuous improvement and development of the firm’s cybersecurity, compliance, and governance programs. As the Information Security Analyst, you are the organizing force responsible for providing oversight, coordination, and execution of the supporting activities for successful internal/external compliance and regulatory audits. This position will be responsible for collaborating with key stakeholders to ensure risks are managed effectively and efficiently in accordance with firm policies and applicable regulatory requirements.

Essential Job Function & Responsibilities:

  • Governance SupportManage the annual review process for policies, procedures, and standards.Develop and manage a security policy exception process.Develop and maintain Information Security and GRC metrics.Support the Information Security Steering Committee (ISSC) as needed.
  • GRC OperationsDevelop a solid foundation in Information Security GRC concepts and processes.Manage the selection, implementation, and operation of GRC tools.Automate the collection of control test and internal audit data with low-code tools.Drive continuous improvement of the InfoSec GRC program.
  • Risk Management SupportOrganize the Risk Management Committee (RMC) and coordinate risk management processes.Maintain the Risk Register.Manage the control test and reporting process.Develop and maintain risk management metrics, reports, and dashboards.Support control enhancement and/or gap remediation projects.
  • Compliance SupportDevelop a repeatable approach to managing NIST 800-53 and SOC 2 Type II audit requirements and testing procedures.Manage internal audit processes.Coordinate information security responses in support of external/third party audits.Manage Corrective Action Plans and/or Plan of Action & Milestones (POA&Ms).
  • Security Operations and ReportingMonitors, collects, and analyzes cybersecurity data and develops KPI and metrics reports.Performs vulnerability scans, conducts risk assessments, and oversees the vulnerability management remediation process.Perform cyber-security related tasks such as phishing analysis and access control reviews.
  • ISO 27001 Compliance:Proactively identify gaps or conflicts in existing policies and processes.Educate and train process/control owners to ensure understanding of the security controls framework and their responsibilities.Assist with and drive remediation of process and control deficiencies and gaps identified internally and externally.Assemble, organize, and implement applicable documentation (e.g. SOA, procedures).
  • Security Awareness and TrainingPartners with the stakeholders to improve security procedures, training, IT processes, and the security of existing systems.Manage phishing training campaigns and follow up / remedial training.Manage and support the effectiveness of the Data Security Awareness and Training program.

Qualifications:

  • Bachelor’s degree required. Degree in Information Systems Security or related field preferred.
  • Minimum of 2 years substantive relevant experience required.
  • An ideal candidate will have 2-5 years of experience in cybersecurity.
  • Knowledge of and experience in information security and monitoring systems.
  • Familiarity/comfort level working with IT Security software and hardware.
  • Strong writing / documentation / presentation skills.
  • Highly organized.
  • Strong communication skills.
  • Self-starter with the ability to work independently, while having good judgment as to when consultation is required.
  • Ability to work on multiple projects and perform well under deadlines.
  • Enthusiastic, flexible, willing to pitch in where needed.
  • Strong drive to learn and grow in the cyber security field.
  • Experience with control standards and frameworks such as FedRAMP, HIPAA, NIST 800-53, SOC 2, or ISO 27001. You have participated in various forms of internal controls review, testing, or internal audit.
  • Must be a natural collaborator, communicate effectively, and be flexible to changing business conditions.
  • An inclusive and growth-oriented mindset, strong interpersonal skills, and an ability to work across differences.
  • To the extent permitted by applicable law, eligible candidates must be authorized to work in the United States without sponsorship or restriction, now and in the future.

Analysis Group embraces diversity and equal opportunity in a deep and meaningful way. We are committed to building teams that represent a variety of backgrounds, perspectives, and skills. The more inclusive we are, the better our work will be.

We provide equal access and opportunities regardless of sex, sexual orientation, gender, gender identity, gender expression, age, religion, race, color, ethnicity, national origin, ancestry, mental and physical ability or disability, medical condition, genetic information, citizenship status, socioeconomic status, veteran and military status, or membership in any other class protected under applicable law. We encourage candidates of all backgrounds to apply.

­

  • Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities.
  • Please view Equal Employment Opportunity Posters provided by OFCCP .
  • The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor's legal duty to furnish information. 41 CFR 60-1.35(c)
[job_alerts.create_a_job]

Information Security Analyst • Boston, MA, US

[internal_linking.similar_jobs]
Hybrid Information Security Engineer & Analyst

Hybrid Information Security Engineer & Analyst

Search Services • Boston, MA, United States
[job_card.full_time]
A leading energy management firm is looking for an Information Security Analyst and Engineer in Boston, MA.This hybrid role involves enhancing security programs, monitoring systems, and collaborati...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Manager of Information Security

Manager of Information Security

Granite Telecommunications • Quincy, Massachusetts, United States
[job_card.full_time]
Granite delivers advanced communications and technology solutions to businesses and government agencies throughout the United States and Canada.We provide exceptional customized service with an emp...[show_more]
[last_updated.last_updated_30] • [promoted]
Advisory Compliance Analyst

Advisory Compliance Analyst

Victory Capitel • Boston, MA, United States
[job_card.full_time]
Victory Capital (NASDAQ: VCTR) is a diversified global asset management firm.We serve institutional, intermediary, and individual clients through our Investment Franchises and Solutions Platform, w...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Information Security Analyst

Information Security Analyst

TradeJobsWorkForce • 02475 Arlington Heights, MA, US
[job_card.full_time]
Monitor their organization’s networks for security breaches and investigate a violation when one occurs Install and use software, such as firewalls and data encryption programs, to protect sensitiv...[show_more]
[last_updated.last_updated_30] • [promoted]
Manager, Security Posture Management Innovation Engineer

Manager, Security Posture Management Innovation Engineer

KPMG • Boston, MA, United States
[job_card.full_time]
Known for being a great place to work and build a career, KPMG provides audit, tax and advisory services for organizations in today's most important industries.Our growth is driven by delivering re...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Compliance Analyst

Compliance Analyst

Hometap • Boston, MA, United States
[job_card.full_time]
Here at Hometap, we're collaborative, passionate, and always ready to roll up our sleeves to create solutions that help people get more out of homeownership and out of life.Our first product, a hom...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Compliance Analyst

Compliance Analyst

Weiss Asset Management LLC • Boston, MA, United States
[job_card.full_time]
Weiss Asset Management (WAM), a Boston-based investment firm, is seeking a Trade Compliance Analyst to join our Compliance team.The ideal candidate is detail-orientated, analytical, and comfortable...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Senior Information Security & Cloud Risk Leader

Senior Information Security & Cloud Risk Leader

Highmark Health • Boston, MA, United States
[job_card.full_time]
A leading healthcare organization is seeking a qualified candidate to manage Information Security and Risk Management services.This role involves leading security personnel, overseeing project mana...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Federal Information Security Training Specialist (*ISSM experience req'd) - 1 yr contract, 100%[...]

Federal Information Security Training Specialist (*ISSM experience req'd) - 1 yr contract, 100%[...]

Jobot Consulting • Boston, MA, United States
[job_card.full_time]
Federal Information Security Training Specialist (*ISSM experience req'd) - 1 yr contract, 100% REMOTE.Looking for an Information Security Training Coordinator with a well-known and well-establishe...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Threat Intelligence & Security Risk Analyst

Threat Intelligence & Security Risk Analyst

Kroll • Boston, MA, United States
[job_card.full_time]
A leading risk management firm in Boston seeks an Analyst to join their Security Risk Management practice.The successful candidate will monitor real-time data and research emerging threats while as...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
M4-14Lead Security Analyst 141809

M4-14Lead Security Analyst 141809

FHR • East Boston, MA, US
[job_card.full_time]
[filters_job_card.quick_apply]
Our direct client has a new opening for a Lead Security Analyst 141809.This job is 14 months to start, and the client is located in Augusta, ME.Please send your rate and resume.Regulatory complianc...[show_more]
[last_updated.last_updated_30]
Intelligence Analyst with Security Clearance

Intelligence Analyst with Security Clearance

Contact Government Services, LLC • Boston, MA, United States
[job_card.full_time]
Intelligence Analyst Employment Type: Full-Time, Experienced Contact Government Services is hiring an Intelligence Analyst ready to be a member of a dynamic and fast paced intel analysis program fo...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
CISO: Strategic Information Security Leader

CISO: Strategic Information Security Leader

SHI • Boston, MA, United States
[job_card.full_time]
A global IT solutions provider in Boston is seeking a Chief Information Security Officer.The CISO will develop and implement a comprehensive information security strategy while managing incident re...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Senior Workday Security Architect & Analyst

Senior Workday Security Architect & Analyst

Northeastern University • Boston, MA, United States
[job_card.full_time]
A leading educational institution is seeking a Senior Business Systems Analyst for Workday Security in Boston.This role focuses on managing the security lifecycle for Workday's HCM, Payroll, and Fi...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Information Security Analyst and Engineer

Information Security Analyst and Engineer

Search Services • Boston, MA, United States
[job_card.full_time]
Information Security Analyst and Engineer.Get AI-powered advice on this job and more exclusive features.Our Client is a leader in energy management and power trading, leveraging cutting‑edge platfo...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Remote Trading Analyst - FX & Digital Assets | Brockton, MA

Remote Trading Analyst - FX & Digital Assets | Brockton, MA

Maverick Currencies • Brockton, MA, United States
[filters.remote]
[job_card.full_time]
Want to trade forex and crypto full-time from Brockton, MA? Maverick Currencies gives you the capital, coaching, and community to make it happen.Maverick Currencies is seeking disciplined traders w...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Intelligence Analyst

Intelligence Analyst

Contact Government Services LLC • Boston, MA, United States
[job_card.full_time]
Contact Government Services is hiring an Intelligence Analyst ready to be a member of a dynamic and fast paced intel analysis program for a federal agency supporting the US Government's threat watc...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Specialist - Defense and Security

Specialist - Defense and Security

McKinsey & Company • Boston, MA, United States
[job_card.full_time]
Specialist - Defense and Security.Do you want to work on complex and pressing challenges-the kind that bring together curious, ambitious, and determined leaders who strive to become better every da...[show_more]
[last_updated.last_updated_variable_days] • [promoted]