Information security analyst jobs in Smithtown, NY - 32 jobs
All
Information Security Analyst
Security Engineer
Information Security Director
Senior Security Analyst
Securities Analyst
Cyber Security Engineer
Cyber Security Analyst
Information Security Officer
Network Security Analyst
Information Technology Analyst
Information Technology Security Manager
Senior Information Security Analyst
Cyber Security Specialist
Information Security Engineer
Network Security Analyst
Skadden 4.9
Information security analyst job in White Plains, NY
We invite you to review our current business services professionals openings to learn about the opportunities available across the firm.
About Us
Skadden, Arps, Slate, Meagher & Flom LLP has forged a reputation as one of the most prestigious law firms in the world. Relying on innovation, intellect, teamwork and tenacity, our lawyers deliver the highest quality advice and novel solutions to our clients' legal issues. We are known for handling the most complex transactions, litigation/controversy issues, and regulatory matters, as well as for the strong partnerships we build with clients and each other. Our attorneys, who reflect a broad range of experiences and perspectives, work together seamlessly across 50-plus practices and 21 offices in the world's major financial centers.
The Opportunity
We are seeking two Network SecurityAnalysts to join our Firm. These positions will be based in our White Plains office (hybrid), and please note the roles have different shift times, listed below. The Network SecurityAnalysts are responsible for implementing and supporting network security solutions for the Firm and, implementing and enforcing practical solutions to secure the Firm's internal and external network infrastructure.
Available Shift Times (EST- Hybrid)
1.) Saturday - Sunday: 7:00 a.m. - 8:00 p.m. EST & Monday 7:00 a.m. - 7:00 p.m.
2.) Monday - Friday: 2:00 p.m. - 10:00 p.m.
Note: The scheduled hours listed may be flexible and will be discussed during the interview process.
Responsibilities
Performs daily review of automated security reports and escalate as necessary.
Responds to system generated security alerts and coordinate responses.
Assists with internal audits, vulnerability scans and risk assessments.
Assists with annual penetration testing, review of findings and tracking issue resolution.
Participates in evaluating new technologies or new versions of existing products.
Works with project teams to implement secure network connectivity solutions.
Writes and maintains technical documentation including procedures and troubleshooting guides.
Demonstrates effective interpersonal, written and verbal communication skills to facilitate effective work relationships with others.
Manages Firm resources responsibly.
Complies with and understands Firm operation, policies and procedures.
Performs other related duties as assigned.
Qualifications
Knowledge of relevant firm computer software programs (e.g., Outlook, Excel, PowerPoint), with the ability to learn new software and operating systems
Proficient with Access, Project and Visio
Thorough knowledge of network management and security technologies and approaches
Thorough knowledge of security techniques, latest protocols and defenses
Proficient with Microsoft Active Directory and Operating Systems
Basic ability to program scripts and batch files
Demonstrates effective interpersonal and communication skills, both verbally and in writing
Demonstrates close attention to detail
Excellent analytical, troubleshooting, organizational, and planning skills
Ability to handle multiple projects and shifting priorities
Ability to handle sensitive matters and maintain confidentiality
Ability to organize and prioritize work
Ability to work well in a demanding and fast-paced environment
Ability to work well independently as well as effectively within a team
Ability to use discretion and exercise independent and sound judgment
Flexibility to adjust hours and work the hours necessary to meet operating and business needs
Education/Experience
Bachelor's degree or equivalent
Minimum of two years' experience in multi-national enterprise IT
Culture & Life at Skadden
What makes Skadden special is our people and the culture, community and spirit of collaboration we have created. We believe in teamwork and inspiring each other to be our best in an atmosphere that promotes professionalism and excellence in all that we do. We know that inclusion and drawing on the strength of a wide spectrum of talent only make us better and is vital to the firm's success. Our goal is for everyone at the firm to enjoy a challenging career with opportunities for development and growth and to support the well-being of our attorneys and business services professionals.
Benefits
The overall well-being of our team is important to us. We offer generous benefits to help you achieve wellness in all areas of your life.
Competitive salaries and year-end discretionary bonuses.
Comprehensive health care (medical, dental, vision), savings plan/401(k) and voluntary benefits.
Generous paid time off.
Paid leave options, including parental.
In-classroom, remote, and on-demand learning and professional development opportunities.
Robust well-being classes and programs.
Opportunities to give back and make an impact in local communities.
For further details, please visit: *******************************************************
Skadden is an Equal Opportunity Employer (Disability/Vet/other protected categories). For more information, please visit Skadden.com/careers.
The starting base salary for this position is expected to be within the range listed under Salary Details. Actual salary will be determined based on skills, experience (to the extent relevant) and other-job related factors, consistent with applicable law.
Salary Details
$125,000 -$140,000
EEO Statement
Skadden is an Equal Opportunity Employer. It does not discriminate against applicants or employees based on any legally impermissible factor including, but not limited to, race, color, religion, creed, sex, national origin, ancestry, age, alienage or citizenship status, marital or familial status, domestic partnership status, caregiver status, sexual orientation, gender, gender identity or expression, change of sex or transgender status, genetic information, medical condition, pregnancy, childbirth or related medical conditions, sexual and reproductive health decisions, disability, any protected military or veteran status, or status as a victim of domestic or dating violence, sexual assault or offense, or stalking.
Applicants who require an accommodation during the application process should contact Alex Taylor at **************.
Skadden Equal Employment Opportunity Policy
Skadden Equal Employment Opportunity Policy
Applicants Have Rights Under Federal Employment Law
Applicants Have Rights Under Federal Employment Law
In accordance with the Transparency in Coverage Rule,
click here to review machine-readable files made available by UnitedHealthcare:
Transparency in Coverage
$125k-140k yearly Auto-Apply 58d ago
Looking for a job?
Let Zippia find it for you.
Cyber Security Analyst - Information Security (Identity and Access Management)
Northwell Health 4.5
Information security analyst job in Melville, NY
**Req Number** 173348 + Document and analyze Identity and Access Management (IAM) processes, procedures, and controls to ensure accuracy, consistency, and alignment with organizational standards. + Troubleshoot and resolve identity-related issues identified through reports, alerts, or incident tickets.
+ Create and maintain detailed IAM system and workflow documentation based on business and technical requirements.
+ Collaborate with business stakeholders and IT leadership to design, develop, and enhance IAM operational workflows using existing technologies and services.
+ Develop, execute, and document test cases to validate IAM workflow enhancements and system changes.
+ Build and maintain business-facing reports and dashboards using Power BI, SQL queries, and LDAP queries across targeted identity repositories.
+ Communicate effectively with team members, cross-functional partners, and business units to ensure consistent understanding of IAM processes and initiatives.
+ Support the governance, maintenance, and execution of IAM operational workflows, including responding to and resolving team service requests and incidents.
+ Conduct data analysis to identify, investigate, and remediate user data inconsistencies, anomalies, and policy deviations.
+ Participate in on-call rotation as needed to support critical IAM functions and operational continuity.
Highly Preferred Skills:
+ 2-5 years of experience as an IAM Analyst, Business Analyst, or similar technical/functional role.
+ Strong business analysis skills, including requirements gathering, process mapping, and workflow design.
+ Experience writing and executing test cases, test scripts, and test plans.
+ Familiarity with IAM systems and concepts such as identity lifecycle management, authentication, authorization, roles, and entitlements.
+ Experience with IAM tools (e.g., Okta, SailPoint, Azure AD/Entra ID, Duo) is preferred but not required.
+ Working knowledge of SQL, Power BI, or other reporting tools is a plus.
+ Strong documentation skills using MS Word, Excel, Visio, or similar tools.
+ Excellent verbal and written communication skills; able to translate between business and technical language.
+ Detail-oriented, analytical thinker, and effective problem solver.
+ Willingness to participate in testing activities and occasional on-call or after-hours support if needed.
Job Description
Protects the organization's digital assets from unauthorized access. This includes securing both online and on-premise infrastructures, responding to alerts, mitigating risks before breaches occur and guiding the efforts to contain, triage and recover from cyber incidents when they occur.
Job Responsibility
Works on moderately complex assignments to protect computer systems, networks, and data from loss and potential service interruptions due to cyber incidents. Analyzes and documents security risks, breaches, and incidents using independent judgment within defined procedures to determine appropriate actions and approaches. Analyzes, reports, and responds to detected cyber incidents. Uses cybersecurity tools to proactively search for and identify threats to systems and networks. Installs and operates security software and measures to protect systems and information infrastructure. Collaborates with the security team and peers to perform tests and find network weaknesses which could lead to a cyber security incident. Makes decisions based on precedent, previous experience and professional guidelines. Researches and recommends cyber security enhancements and tools. Works with management to develop and enhance cyber security best practices. Researches and keeps current on the latest cyber security intelligence technologies, trends, and standards. Trains junior level staff on network and cyber security technologies and procedures. Performs related duties as required. All responsibilities noted here are considered essential functions of the job under the Americans with Disabilities Act. Duties not mentioned here, but considered related are not essential functions.
Job Qualification
Bachelor's degree in Computer Science, Cyber Security or related field, required.
Certifications including but not limited to Security+, CISSP, CISM, CEH, ISSAP, ISSEP, or GSEC, required.
2-4 years of related experience, required.
*Additional Salary Detail
The salary range and/or hourly rate listed is a good faith determination of potential base compensation that may be offered to a successful applicant for this position at the time of this job advertisement and may be modified in the future.When determining a team member's base salary and/or rate, several factors may be considered as applicable (e.g., location, specialty, service line, years of relevant experience, education, credentials, negotiated contracts, budget and internal equity).
The salary range for this position is $79880-$136340/year
It is Northwell Health's policy to provide equal employment opportunity and treat all applicants and employees equally regardless of their age, race, creed/religion, color, national origin, immigration status or citizenship status, sexual orientation, military or veteran status, sex/gender, gender identity, gender expression, disability, pregnancy, genetic information or genetic predisposition or carrier status, marital or familial status, partnership status, victim of domestic violence, sexual or other reproductive health decisions, or other characteristics protected by applicable law.
$79.9k-136.3k yearly 4d ago
Security Analyst
EY 4.7
Information security analyst job in Jericho, NY
At EY, we're all in to shape your future with confidence. We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. **The opportunity** As application senior security specialist for the Security Certification Team, candidate will be resposible to conduct application vulnerability assessment and penetration testing of EY applications before they move into production and support the team to meet overall security certification goals and client requirements.
**Your key responsibilities**
+ Capable of conducting application & network penetration testing and vulnerability assessments
+ Preparing detailed security review reports and remediation guidances
+ Researching new application security vulnerabilities and attack vectors
+ Leading strategic initiatives and mentoring new team members
+ Support the team in updating their skill and knowledge
**Skills and attributes for success**
+ Hands on experience of Web, thick client, Mobile, VOIP, Wireless application security testing.
+ Proficient in automated and manual application testing methodologies.
+ Expert in using manual testing tools such as Burp Professional, Nmap, Wireshark, Nessus, echomirage.
+ Expert in using automated application scan tool Webinspect / Qualys WAS, CheckMarx, WhiteSource etc..
+ Basic Knowledge of programming language like C/C++, C#, JAVA, ASP.NET and familiar with PERL/Python Scripting.
+ Familiar with OWASP and Secure SDLC standards
+ Knowledge of common security requirements within ASP.NET & Java application
+ Good Knowledge of TCP/IP, Network Security.
+ Knowledge / experience on code review
+ Good Technical aptitude, problem solving and ability to quickly learn and master new topics and domains.
+ Excellent communication skills; written and verbal.
**Supervision Responsibilities:** None
**Other Requirements:** Flexible work environment
**Education:**
+ Bachelor's degree in a technical discipline such as Engineering or Computer Science or equivalent work experience in IT and InformationSecurity.
**Experience:**
+ 4 - 6 yrs. experience in application security assessment
+ Hands on experience of Web, thick client, Mobile Application security reviews.
+ Exposure and good understanding of the various manual testing methodologies.
**Certification Requirements:**
+ Desirable: IT security Certifications (CEH. ECSA, OSCP etc..).
**What we offer you**
At EY, we'll develop you with future-focused skills and equip you with world-class experiences. We'll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more .
+ We offer a comprehensive compensation and benefits package where you'll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $76,400 to $138,600. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $91,700 to $157,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
+ Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
+ Under our flexible vacation policy, you'll decide how much vacation time you need based on your own personal circumstances. You'll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
**Are you ready to shape your future with confidence? Apply today.**
EY accepts applications for this position on an on-going basis.
For those living in California, please click here for additional information.
EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.
**EY | Building a better working world**
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.
EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY's Talent Shared Services Team (TSS) or email the TSS at ************************** .
$91.7k-157.5k yearly 60d+ ago
Sr. Security Analyst
Maximus 4.3
Information security analyst job in Bridgeport, CT
Description & Requirements Maximus is seeking a qualified Sr. Technical/SecurityAnalyst for multiple projects, current and upcoming. The qualified candidate will be involved in technical/security planning and assessment projects with potentially multiple state agencies. The position requires the candidate to produce/review security relevant documentation, such as system security plans, POA&Ms, assessment plans, etc., produce technical/security analyses, develop estimates, review and contribute to requirements for large systems-planning efforts in the Child Support, Child Welfare and/or Integrated Eligibility public-sector domains. The individual will report directly to a Senior Manager. Maximus is a matrix-managed organization, which means the individual will have secondary reporting relationships to one or more Project Managers, depending on which projects they are assigned.
*This role is remote but requires working standard business hours in the US time zone of the client. This position is contingent upon award. *
Essential Duties and Responsibilities:
- Collaborate with project managers on various initiatives and projects to track progress and provide support as necessary.
- Support leadership in ensuring that the project is delivered to specifications, is on time, and within budget.
- Work closely with management and work groups to create and maintain work plan documents.
- Track the status and due dates of projects.
- Manage relationships with project staff responsible for projects.
- Produce regular weekly and monthly status reports that could include; work plan status, target dates, budget, resource capacity, and other reports as needed.
- Facilitate regular meetings and reviews.
- Adhere to contract requirements and comply with all corporate policies and procedures.
Job Specific Duties and Responsibilities:
-Perform duties independently under the direction of their direct manager and/or Project Managers on specific projects.
-Review project documentation and client materials and provide analysis of technical and security related topics.
-Participate in client meetings and offer observations and insight on technical and security related topics.
-Identify risk areas and potential problems that require proactive attention.
-Review and author artifacts and other project documents and identify potential gaps, inconsistencies, or other issues that may put the project at risk. Such artifacts and documents may include but are not limited to:
*System Security Plan
*Plan of Action and Milestones (POA&M)
*Security Assessment Plan
*Risk Assessment reports
*CMS ARC-AMPE forms and documentation
*Data Conversion and Migration Management Plan
*Deployment and/or roll-out plans
-Perform security assessments, lead security audit and assessment activities, and provide direct security oversight support to assigned clients and projects.
-Identify and escalate to the Senior Manager / Project Manager risks, alternatives, and potential quality issues.
-Attend interviews, focus groups, or other meetings necessary to gather information for project deliverables in accordance with the project scope of work.
-Attend project meetings with the client, subcontractors, project stakeholders, or other Maximus Team members, as requested by the Senior Manager / Project Manager.
-Complete project work in compliance with Maximus standards and procedures.
-Support team to complete assigned responsibilities as outlined in the Project schedule.
-Support all other tasks assigned by Senior Manager / Project Manager.
Minimum Requirements
- Bachelor's degree in related field.
- 7-10 years of relevant professional experience required.
- Equivalent combination of education and experience considered in lieu of degree.
Job Specific Requirements:
-Be available to work during standard client business hours. Projects may involve clients from any US time zone, so it is possible that work outside of the individual's local business hours will be required.
-Bachelor's degree from an accredited college or university, or equivalent work experience.
-7+ years of experience in informationsecurity, with at least 3 years of security-compliance work in a regulated industry.
-5+ years of experience working with HIPAA, NIST 800-53 and/or CMS MARS-E or ARC-AMPE security frameworks.
-Familiar with operating systems: Windows, Linux/UNIX, OS/X.
-Familiar with AI tools, capabilities.
-Strong command of cloud computing topics.
-Strong command of agile software development practices as well as waterfall development practices.
-Strong desktop software skills: proficient in MS Office, Excel, Word, Project.
-Ability to explain and communicate technical subjects to non-technical audiences.
-Ability to develop advanced concepts, techniques, and standards requiring a high level of interpersonal and technical skills.
-Ability to work independently.
-Good organizational skills and the ability to manage multiple tasks and deadlines simultaneously.
-Strong interpersonal and team building skills, as well as an understanding of client relationship building are essential.
-Excellent verbal and writing skills and be comfortable working with customers.
-Ability to multi-task with supervision.
-Self-motivated fast learner.
Preferred Skills:
-Prefer a candidate with experience in the Health & Human Services industry, which may include working with programs such as Child Support, Child Welfare, or Integrated Eligibility (SNAP, TANF, and Medicaid).
-Preference for security related certifications, such as the CISSP (Certified Information Systems Security Professional).
EEO Statement
Maximus is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, age, national origin, disability, veteran status, genetic information and other legally protected characteristics.
Pay Transparency
Maximus compensation is based on various factors including but not limited to job location, a candidate's education, training, experience, expected quality and quantity of work, required travel (if any), external market and internal value analysis including seniority and merit systems, as well as internal pay alignment. Annual salary is just one component of Maximus's total compensation package. Other rewards may include short- and long-term incentives as well as program-specific awards. Additionally, Maximus provides a variety of benefits to employees, including health insurance coverage, life and disability insurance, a retirement savings plan, paid holidays and paid time off. Compensation ranges may differ based on contract value but will be commensurate with job duties and relevant work experience. An applicant's salary history will not be used in determining compensation. Maximus will comply with regulatory minimum wage rates and exempt salary thresholds in all instances.
Accommodations
Maximus provides reasonable accommodations to individuals requiring assistance during any phase of the employment process due to a disability, medical condition, or physical or mental impairment. If you require assistance at any stage of the employment process-including accessing job postings, completing assessments, or participating in interviews,-please contact People Operations at **************************.
Minimum Salary
$
120,000.00
Maximum Salary
$
140,000.00
$113k-154k yearly est. Easy Apply 6d ago
Senior Security Ops Analyst - Incident Response
Spartan Technologies
Information security analyst job in New Hyde Park, NY
We are seeking a Senior Security DevOps Engineer who will be responsible for a variety of objectives resulting in risk mitigation and remediation of internal & external security threats. This role performs advanced threat analysis, threat intelligence gathering & reporting, incident response activities, improves accuracy of security systems, improves existing processes, and works on Cybersecurity focused projects.
Contract to hire
Onsite 2 days a week located in New York
Cybersecurity - Cyber Intelligence & Incident Response
Responds to and remediates email, endpoint, threat intelligence, and network-based threats; provides forensic investigation and support.
Provides after-hours support as needed for response activities.
Integration experience.
Collaborates with cross divisional and Cybersecurity teams to continuously improve security capabilities and response to threats in the most efficient and effective manner.
Assists with projects to implement advanced technologies to prevent & identify malicious behavior within cloud environments, networks, endpoints, and email technologies.
Operates products such as SIEM, SOAR, threat intelligence platforms, advanced email protection, EDR, cloud security products, IDS/IPS, Zero Trust tooling, and other security technologies.
Scripting experience.
Implements and performs threat analysis utilizing industry standard frameworks (kill chain/diamond model) and techniques.
Proposes and helps review security plans and policies to improve environmental security.
Maintains and produces metrics, operational playbooks, process diagrams and documentation for the Cybersecurity program.
AWS and/or Azure knowledge.
Produces and distributes operational and tactical threat intelligence reports.
Other duties may be assigned as needed to address new security threats facing the enterprise.
Ability to:
Demonstrate great teamwork and partnership with internal teams for resolution of security-based issues.
Python programming tasks and understand of programming in general.
Perform security event correlation, triage, and analysis.
Apply security Threat Intelligence while responding to and investigating security events or Incidents.
Identify when an application, network, system, or user has been compromised by an internal or external threat.
Work on multiple projects to improve security capabilities.
Exercise strong understanding of defense-in-depth security best practices.
Apply security engineering and architecture concepts to best understand how to employ the most effective security monitoring, response, and threat reporting.
Demonstrate effective communication of security issues and topics to management and others.
Work well under pressure and within a high paced environment.
Maintain operational guidelines and standards for Cybersecurity.
$95k-130k yearly est. 60d+ ago
Information Security Engineer 3
Yale University 4.8
Information security analyst job in New Haven, CT
Working at Yale means contributing to a better tomorrow. Whether you are a current resident of our New Haven-based community- eligible for opportunities through the New Haven Hiring Initiative or a newcomer, interested in exploring all that Yale has to offer, your talents and contributions are welcome. Discover your opportunities at Yale!
Salary Range
$90,000.00 - $135,000.00
Overview
Conduct Incident Response Activities: Participates in security incident response efforts, managing assigned incidents through the full handling lifecycle including identification, containment, eradication, and recovery in coordination with other SOC and Security Engineering team members. Perform Detailed Incident Analysis: Analyzes host, network, and cloud telemetry to determine root cause, attack path, and impact of security events. Documents findings and maintains thorough incident records. Support Tier 2 SOC Operations: Responds to escalated alerts, security tickets, and service requests, ensuring timely investigation, documentation, and remediation of potential threats within established service levels. Develop and Maintain Response Playbooks: Contributes to the creation, refinement, and maintenance of incident response playbooks and procedures for various threat types to ensure consistent and effective handling of incidents. Enhance Detection and Response Capabilities: Collaborates with Security Engineering teams to identify detection gaps, improve alerting logic, and drive automation within response workflows.Participate in Post-Incident Reviews and Knowledge Sharing: Engages in lessons-learned activities, tracks remediation actions, and mentors SOC analysts to strengthen incident analysis and handling capabilities.
Skills & Abilities
1.Developed analytical, critical thinking and problem-solving skills.
2.Developed interpersonal, written, communication, presentation, and organizational skills.
3.Familiarity with systems analysis methods and techniques.
4.Project management skills.
Job Responsibilities
1.Responsible for routine to moderately complex event and incident monitoring, threat detection and data correlation.
2.Assist with collecting potential breach evidence, participate in network and host forensic analysis, participate with incident remediation activities.
3.Meet with stakeholders to assess departments security requirements.
4.Assist in the development of security standards and best practices.
5.Research the latest informationsecurity trends and emerging threats.
Principal Responsibilities
1. Responsible for routine to moderately complex event and incident monitoring, threat detection and data correlation. 2. Assist with collecting potential breach evidence, participate in network and host forensic analysis, participate with incident remediation activities. 3. Meet with stakeholders to assess departments security requirements. 4. Assist in the development of security standards and best practices. 5. Research the latest informationsecurity trends and emerging threats. Required Education and Experience Bachelor's Degree and four years of experience or equivalent education and experience. Skills and Abilities Developed analytical, critical thinking and problem-solving skills. Developed interpersonal, written, communication, presentation, and organizational skills. Familiarity with systems analysis methods and techniques. Project management skills.
Job Posting Date
01/15/2026
Job Category
Professional
Bargaining Unit
NON
Compensation Grade
GS-3
Compensation Grade Profile
GS-3h
Time Type
Full time
Duration Type
Staff
Work Model
Location
150 Munson Street, New Haven, Connecticut
Background Check Requirements
All candidates for employment will be subject to pre-employment background screening for this position, which may include motor vehicle, DOT certification, drug testing and credit checks based on the position description and job requirements. All offers are contingent upon the successful completion of the background check. For additional information on the background check requirements and process visit "Learn about background checks" under the Applicant Support Resources section of Careers on the It's Your Yale website.
Health Requirements
Certain positions have associated health requirements based on specific job responsibilities. These may include vaccinations, tests, or examinations, as required by law, regulation, or university policy.
Posting Disclaimer
Salary offers are determined by a candidate's qualifications, experience, skills, and education in relation to the position requirements, along with the role's grade profile and current internal and external market conditions.
The intent of this job description is to provide a representative summary of the essential functions that will be required of the position and should not be construed as a declaration of specific duties and responsibilities of the position. Employees will be assigned specific job-related duties through their hiring department.
The University is committed to basing judgments concerning the admission, education, and employment of individuals upon their qualifications and abilities and seeks to attract to its faculty, staff, and student body qualified persons from a broad range of backgrounds and perspectives. In accordance with this policy and as delineated by federal and Connecticut law, Yale does not discriminate in admissions, educational programs, or employment against any individual on account of that individual's sex, sexual orientation, gender identity or expression, race, color, national or ethnic origin, religion, age, disability, status as a special disabled veteran, veteran of the Vietnam era or other covered veteran.
Inquiries concerning Yale's Policy Against Discrimination and Harassment may be referred to the Office of Institutional Equity and Accessibility (OIEA).
Note
Yale University is a tobacco-free campus.
$90k-135k yearly 4d ago
Specialist Director, Cyber TSA
KPMG 4.8
Information security analyst job in Stamford, CT
KPMG Advisory practice is currently our fastest growing practice. We are seeing tremendous client demand, and looking forward we do not anticipate that slowing down. In this ever-changing market environment, our professionals must be adaptable and thrive in a collaborative, team-driven culture. At KPMG, our people are our number one priority. With a wealth of learning and career development opportunities, a world-class training facility and leading market tools, we make sure our people continue to grow both professionally and personally. If you're looking for a firm with a strong team connection where you can be your whole self, have an impact, advance your skills, deepen your experiences, and have the flexibility and access to constantly find new areas of inspiration and expand your capabilities, then consider a career in Advisory.
KPMG is currently seeking a Specialist Director, MAST Application Penetration Testing Lead to join our Managed Services practice.
Responsibilities:
* Lead the strategic delivery of Managed Application Security Testing (MAST) services, ensuring alignment with client objectives and industry best practices
* Execute go-to-market (GTM) strategies for MAST offerings, collaborating with cross-functional teams to drive market penetration and revenue growth
* Oversee the design and implementation of scalable security testing frameworks across diverse application environments, including cloud-native and hybrid architectures
* Provide subject matter expertise in application security, guiding clients through risk assessments, remediation planning, and secure development lifecycle integration
* Build and maintain strong client relationships, serving as a trusted advisor and ensuring high levels of satisfaction and retention
* Mentor and lead a team of security professionals, fostering a culture of innovation, accountability, and continuous improvement
* Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment
Qualifications:
* Minimum eight years of recent experience in application security, penetration testing, or related cybersecurity domains, with at least three years in a leadership or director-level role
* Master's degree from an accredited college or university in cybersecurity, computer science, or related field is preferred; Bachelor's degree from an accredited college or university is required
* Deep understanding of application security testing methodologies, tools (for example, DAST, SAST, IAST), and secure SDLC practices
* Proven experience developing and executing GTM strategies for security services or technology solutions
* Strong client-facing skills with the ability to communicate complex technical concepts to non-technical stakeholders
* Excellent verbal/written communication, presentation, and analytical skills
* Ability to travel as required
* Applicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future; KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa)
KPMG LLP and its affiliates and subsidiaries ("KPMG") complies with all local/state regulations regarding displaying salary ranges. If required, the ranges displayed below or via the URL below are specifically for those potential hires who will work in the location(s) listed. Any offered salary is determined based on relevant factors such as applicant's skills, job responsibilities, prior relevant experience, certain degrees and certifications and market considerations. In addition, KPMG is proud to offer a comprehensive, competitive benefits package, with options designed to help you make the best decisions for yourself, your family, and your lifestyle. Available benefits are based on eligibility. Our Total Rewards package includes a variety of medical and dental plans, vision coverage, disability and life insurance, 401(k) plans, and a robust suite of personal well-being benefits to support your mental health. Depending on job classification, standard work hours, and years of service, KPMG provides Personal Time Off per fiscal year. Additionally, each year KPMG publishes a calendar of holidays to be observed during the year and provides eligible employees two breaks each year where employees will not be required to use Personal Time Off; one is at year end and the other is around the July 4th holiday. Additional details about our benefits can be found towards the bottom of our KPMG US Careers site at Benefits & How We Work.
Follow this link to obtain salary ranges by city outside of CA:
**********************************************************************
California Salary Range: $153700 - $319000
KPMG offers a comprehensive compensation and benefits package. KPMG is an equal opportunity employer. KPMG complies with all applicable federal, state and local laws regarding recruitment and hiring. All qualified applicants are considered for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, citizenship status, disability, protected veteran status, or any other category protected by applicable federal, state or local laws. The attached link contains further information regarding KPMG's compliance with federal, state and local recruitment and hiring laws. No phone calls or agencies please.
KPMG recruits on a rolling basis. Candidates are considered as they apply, until the opportunity is filled. Candidates are encouraged to apply expeditiously to any role(s) for which they are qualified that is also of interest to them.
Los Angeles County applicants: Material job duties for this position are listed above. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness, and safeguard business operations and company reputation. Pursuant to the California Fair Chance Act, Los Angeles County Fair Chance Ordinance for Employers, Fair Chance Initiative for Hiring Ordinance, and San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
$73k-96k yearly est. 60d+ ago
Workday Application Security Analyst
Us Tech Solutions 4.4
Information security analyst job in White Plains, NY
**Duration: 12 months contract (with possible extension)** ***Note: Open to candidates who are willing to relocate at their own expense.** + The Workday Application SecurityAnalyst is responsible for ensuring the confidentiality, integrity, and availability of data within the Workday system.
+ They design, implement, and maintain security configurations, including roles, permissions, and access controls, to protect organizational data and comply with company policies, industry standards, and regulatory requirements.
**Job Functions & Responsibilities**
+ Develop and implement security roles, domain security policies, data and business process security within Workday
+ Ensure secure integration with other on‐premise and cloud applications like GRC tools
+ Configure and manage access permissions to ensure users have the appropriate level of access to data and functionality
+ Ensure compliance with company policies, industry standards (like SOC 2), and regulatory requirements (like GDPR)
+ Conduct regular security audits and assessments to identify vulnerabilities and areas for improvement
+ Assist in investigating and responding to security incidents, identifying root causes, and implementing preventive measures
+ Collaborate with IT, HR, and other stakeholders to align security efforts with business needs and ensure effective communication of security policies and procedures
+ Create and maintain documentation for security policies, procedures, and configurations, and provide training to users on security best practices
+ Stay abreast of Workday updates, industry trends, and emerging security threats to continuously improve security configurations and processes
+ Familiarity with other ERPs like SAP is preferred
+ Familiarity with GRC and Workday SoD (Segregation of Duties) management is desired
**Skills**
+ SAP ERP (S/4 HANA is a plus)
+ Workday
+ Active Directory group management
+ GRC AC 10.1 and above
+ Microsoft Clienture
+ SuccessFactors
+ Applicable functional knowledge for SAP security areas like Finance, MM, ISU billing, etc.
+ SAP audit & compliance
**Education & Certifications**
+ Bachelor's degree in engineering, IT, or related field
+ 7-10 years of hands‐on industry experience in Workday Security implementation and administration
+ Strong ITGC compliance knowledge for Workday
+ Familiarity with Workday risk management and GRC integration
+ Ability to identify, analyze, and resolve complex security and compliance issues
+ Strong interpersonal and communication skills, with the ability to effectively collaborate with diverse teams
** About US Tech Solutions:**
US Tech Solutions is a global staff augmentation firm providing a wide range of talent on-demand and total workforce solutions. To know more about US Tech Solutions, please visit *********************** (*********************************** .
US Tech Solutions is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
$77k-108k yearly est. 60d+ ago
Senior Cyber Security Engineer
BIC 4.8
Information security analyst job in Shelton, CT
For over 75 years, BIC has been creating ingeniously simple and joyful products that are a part of every heart and home.
As a member of our team, you'll be a part of reigniting a beloved brand as we continue to reimagine everyday essentials in new, sustainable and responsible ways.
Our "roll up your sleeves and get the job done" approach to work creates an environment where self-starters, problem solvers and innovative thinkers thrive. BIC team members are empowered to take ownership of their careers and bring their unique perspectives to the table to make a meaningful impact on our mission.
It's a colorful world - make your mark by joining the BIC team today.
As Senior Cybersecurity Engineer, you will collaborate and partner with a global, cross-functional team to build cybersecurity capabilities and improve maturity. This role involves designing, implementing, and managing security technology to protect the company from cyber threats. Besides, you will support incident response, investigations, playbook development and efforts to identify and mitigate risk.
In this role you will:
Analyze, triage, and investigate alerts from various sources to determine the appropriate response or escalation
Document analysis, findings, and actions for case management and metrics
Support security incident response planning, procedure/playbook development and investigations
Participate in on-call rotation for off-hours escalations
Administer, optimize, and maintain the health of security tools, such as endpoint protection and response (EDR), network detection and response (NDR), and logging pipelines (Syslog/Cribl).
Assist with remediation of identified security risks
Minimum 6 years' experience in Information Technology or Cybersecurity
IT or cybersecurity certifications from industry recognized sources preferred
What you bring to BIC:
Minimum 6 years' experience in Information Technology or Cybersecurity
IT or cybersecurity certifications from industry recognized sources preferred
Prior experience interpreting or analyzing log data and working with log pipelines
Triaging alerts from various sources, following playbooks, and escalating legitimate issues
Knowledge of security tools such as endpoint protection, firewalls, intrusion prevention, SIEM and EDR (CrowdStrike)
Strong understanding of Windows server and desktop operating systems, networking fundamentals, security concepts, Active Directory, Microsoft Azure, Office 365.
In-depth analytical and problem-solving skills to resolve complex issues
BIC is an Equal Opportunity Employer. We strongly commit to hiring people with different backgrounds and experiences to help us build better products, make better decisions, and better serve our customers. We do not discriminate based upon race, religion, color, national origin, gender, sexual orientation, veteran status, disability status, or similar characteristics. All employment is decided based on qualifications, merit, and business need.
BIC is not seeking assistance or accepting unsolicited resumes from search firms for this employment opportunity. Regardless of past practice, all resumes submitted by search firms to any team member at BIC via email, or directly to a BIC team member in any form without a valid written search agreement in place for that position will be deemed the sole property of BIC, and no fee will be paid in the event the candidate is hired by BIC as a result of the referral or through other means.
$75k-93k yearly est. 60d+ ago
Cloud Security Engineer
UL, LLC 4.2
Information security analyst job in Melville, NY
This role is Hybrid, 3 days a week to any local, US based UL Solutions Office. We are seeking a highly skilled Cloud Security Engineer with strong Application Security expertise to join our security architecture team. This role will be responsible for designing, implementing, and maintaining secure cloud environments and applications across multi-cloud platforms, with a focus on Azure. The ideal candidate will have hands-on experience with cloud-native security tools, DevSecOps practices, and compliance frameworks such as NIST 800-53, SOC 2, and CIS Controls.
Cloud Security Engineering
+ Design and implement security controls for cloud infrastructure (Azure, AWS, GCP).
+ Develop and maintain security architecture patterns (e.g., hub-and-spoke, Zero Trust).
+ Integrate security tools such as Wiz, Microsoft Defender for Cloud, Silverfort, and Terraform.
+ Conduct threat modeling and risk assessments for cloud-native services.
+ Collaborate with IAM, SOC, and GRC teams to align cloud security with enterprise policies.
Application Security
+ Perform secure code reviews, static/dynamic analysis, and vulnerability assessments.
+ Integrate security into CI/CD pipelines using tools like Snyk, Checkmarx, or Veracode.
+ Guide development teams on secure coding practices and OWASP Top 10.
+ Design and implement API security strategies including OAuth2, OpenID Connect, and mTLS.
+ Support remediation of application vulnerabilities and provide technical guidance.
Compliance & Governance
+ Map cloud and application security controls to compliance frameworks (NIST 800-53, SOC 2, CIS).
+ Assist in audits and evidence collection for regulatory compliance.
+ Maintain documentation of security architecture, policies, and procedures.
+ Bachelor's degree in Computer Science, Cybersecurity, or related field.
+ 3-4 years of experience in cloud security engineering and application security.
+ Strong understanding of Azure security services and architecture.
+ Experience with infrastructure-as-code (Terraform, Bicep).
+ Familiarity with Snowflake security features and data protection strategies.
+ Knowledge of identity and access management (Azure AD, Conditional Access, MFA).
+ Hands-on experience with DevSecOps tools and practices.
Preferred Qualifications
+ Certifications: Azure Security Engineer Associate, CISSP, CCSP, OSCP, or GIAC.
+ Experience with multi-subscription Azure environments.
+ Familiarity with Zero Trust architecture and implementation.
+ Experience with security automation and orchestration.
Soft Skills
+ Strong analytical and problem-solving skills.
+ Excellent communication and collaboration abilities.
+ Ability to work independently and in cross-functional teams.
+ Passion for continuous learning and staying current with security trends.
What you'll experience working for ULS
UL Solutions has been pioneering change since 1894 and we're still leading the way. From day one, we've blazed a trail protecting the planet and everyone on it. Our teams have influenced billions of products, plus services, software offerings and more. We break things, burn things and blow things up. All in the name of safety science.
That's where you come in - because none of it could happen without you. It takes passion to protect people, problem-solving to safeguard personal data and conviction to make the world a more sustainable place. It takes bold ideas and brilliant minds to build a better world for future generations across the globe.
This is more than a job. It's a calling. A passion to use our expertise and play our part in creating a more secure, sustainable world today - and tomorrow. As a member of our safety science community, you'll use your ideas, your energy and your ambition to innovate, challenge and ultimately, help create a safer world.
Everyone here is unique. But we're also a global community, working together to help create a safer world. Join UL Solutions and you can connect with the brightest minds in the business, all bringing their distinct perspectives and diverse backgrounds together to deliver real change.
Empowering our customers to keep the world safe means thinking ahead. It means investing in training and empowering our people to learn and innovate. At UL Solutions, we help build a better future - one where everyone benefits.
Join UL Solutions to be at the center of safety. To learn more about us and the work we do, visit UL.com
Total Rewards: We understand compensation is an important factor as you consider the next step in your career. The estimated salary range for this position is $95,000 to $120,000 and is based on multiple factors, including job-related knowledge/skills, experience, geographical location, as well as other factors. This position is eligible for annual bonus compensation with a target payout of 10% of the base salary. This position also provides health benefits such as medical, dental and vision; wellness benefits such as mental and financial health; and retirement savings (401K) commensurate with the standard rewards offered in each individual location or country. We also provide full-time employees with paid time off including vacation (15 days), holiday including floating holidays (12 days) and sick time off (72 hours).
#LI-SG2
#LI-Hybrid
UL LLC has been and will continue to be an equal opportunity employer. To assure full implementation of this equal employment policy, we will take steps to assure that:
Persons are recruited, hired, assigned and promoted without regard to race, color, age, sex or gender, sexual orientation, gender identity, gender expression, transgender status, religion, creed, national origin, ethnicity, citizenship, ancestry, disability, genetic information, military or veteran status, pregnancy, marital or familial status, or any other protected category under applicable law.
$95k-120k yearly 60d+ ago
NYPA IT-1322 Cyber Security Program Manager
Gcom Ondemand
Information security analyst job in White Plains, NY
Outcomes. Delivered.
Voyatek delivers outcome-driven technology solutions to public sector agencies and higher education institutions nationwide.
For example, our technology:
· Facilitates access to nutritious food for children of mothers participating in the WIC program
· Supports first responders in reducing opioid overdoses within their communities
· Empowers colleges and universities to identify and thwart financial aid fraud
· Equips teachers with valuable insights to identify students requiring additional support
· Enhances efficiency for state tax agencies, leading to 99% faster return processing and quicker refunds for taxpayers
With a focus on Tax & Revenue, Health & Human Services, and Justice & Public Safety, Voyatek combines the scale to support large complex projects with the agility and accessibility of a boutique solutions provider. Together, Voyatek and its customers work to improve population wellbeing, create safer communities, and foster a thriving economy.
We're more than a technology company -- we're an outcomes company.
We encourage our employees to think differently, ask tough questions, and relentlessly pursue what's best for our customers and the residents they serve.
We believe that the value of technology is defined by its human impact. If you agree, you've come to the right place.
Voyatek is seeking applicants to occupy the position of Cyber Security Program Manager within our team. Please note that this position requires a commitment to full-time employment and is not open to contractors.
Key Responsibilities:
We are in search of a seasoned Cyber Program Manager to lead and oversee IT initiatives within our cybersecurity program. The ideal candidate will have substantial experience in IT project management, cybersecurity technologies, cloud platforms, and governance frameworks. This role involves ensuring the seamless execution of projects by coordinating cross-functional teams, managing timelines, budgets, and resources, and ensuring alignment with organizational goals.
• Oversee and manage projects, ensuring alignment with business and IT objectives and strategic goals.
• Define program and project scope, goals, and deliverables in collaboration with senior management and stakeholders.
• Develop and manage detailed program and project plans, including timelines, milestones, and resource allocation.
• Collaborate with cross-functional teams to define requirements and design solutions.
• Lead and manage IT projects, ensuring alignment with both business and IT objectives and strategic goals.
• Define the scope, objectives, and deliverables of programs and projects in collaboration with senior management and key stakeholders.
• Develop and maintain comprehensive project plans, including timelines, milestones, and resource allocation.
• Engage with stakeholders and work with cross-functional teams to gather requirements and design optimal solutions, provide updates, and ensure alignment with organizational objectives.
• Ensure seamless integration of cybersecurity measures, data protection protocols, and other critical components.
• Monitor project progress and address any issues or risks throughout the project lifecycle.
• Manage the RFP process, including issuing bids, evaluating proposals, and selecting the most suitable solutions.
• Coordinate with vendors and internal teams to build, test, and implement project deliverables.
• Communicate project status, risks, and issues to senior management and stakeholders.
• Lead and mentor project teams, offering guidance and support to ensure successful project execution.
• Foster a collaborative, high-performance team environment.
• Oversee and manage project budgets, ensuring they align with program requirements.
• Monitor and control project expenditures to stay within budget constraints.
• Identify and manage project risks, developing strategies to mitigate potential challenges.
• Ensure compliance with relevant regulations, standards, and best practices.
• Promote continuous improvement by identifying opportunities for process enhancements and implementing best practices.
• Ensure the seamless integration of AI models, data platforms, and other necessary components.
• Monitor progress and manage any issues or risks that arise during the project lifecycle.
• Coordinate the RFP process, including going out to bid, evaluating proposals, and selecting the best solution.
• Coordinate with vendors and internal teams to build, test, and implement the projects.
• Support the establishment of an AI Center of Excellence (CoE) to drive AI strategy, standards, and best practices.
• Engage with key stakeholders to gather requirements, provide updates, and ensure alignment with organizational objectives.
• Communicate program status, risks, and issues to senior management and other stakeholders.
• Lead and mentor project teams, providing guidance and support to ensure successful project execution. • Foster a collaborative and high-performing team environment.
• Develop and manage program budgets, ensuring efficient use of resources.
• Monitor and control project expenditures to stay within budget.
• Identify and manage program risks, developing mitigation strategies to address potential challenges.
• Ensure compliance with relevant regulations, standards, and best practices.
• Promote a culture of continuous improvement by identifying opportunities for process enhancements and implementing best practices.
Qualifications:
· Bachelor's degree in Computer Science, Information Technology, or a related field; Master's degree preferred.
· PMP, PgMP, or similar project/program management certification.
· Minimum of 8-10 years of experience in IT project/program management, with a focus on AI and cloud platforms.
· Bachelor's degree in Computer Science, Information Technology, or a related field; a Master's degree is preferred.
· PMP, PgMP, or equivalent project/program management certification.
· 8-10 years of experience in IT project/program management, with a focus on cybersecurity and cloud platforms.
· Proficiency in cybersecurity technologies, including threat detection, vulnerability management, and incident response.
· Excellent leadership, communication, and stakeholder management skills.
· Strong analytical and problem-solving capabilities.
· Ability to manage multiple projects and priorities in a dynamic environment.
· Knowledge of Azure and AI technologies, including large language models and modern data platforms.
· Experience with AI governance frameworks and AI Centers of Excellence.
· Excellent leadership, communication, and stakeholder management skills.
· Strong analytical and problem-solving abilities.
· Ability to manage multiple projects and priorities in a fast-paced environment.
· Bachelor's degree in Information Technology, Computer Science, Business, or a related field.
· Certification in project management (e.g., PMP) is preferred.
· Industry certifications relevant to cybersecurity, data protection, and other related fields are advantageous.
The wage range for this role reflects the wide array of factors considered in compensation decisions. These factors include, but are not limited to, skill sets, experience, training, licensure and certifications, and geographic location. Compensation decisions are based on the unique facts and circumstances of each case. A reasonable estimate of the hourly range is $59.00 - $61.00.
At Voyatek, we believe in supporting our employees with a comprehensive benefits package designed to enhance their well-being and professional growth. Please note that eligibility for certain benefits may vary based on your role and employment status.
· Flexible Work Schedules
· Health, Dental, and Vision Insurance
· Medical, Limited, & Dependent Flexible Spending Accounts (FSA)
· Health Savings Account (HSA) with Employer Contributions
· Company-Paid and Voluntary Life Insurance
· Long and Short-Term Disability Insurance
· Accident, Critical Illness, & Hospital Indemnity Insurance
· 401(k) Retirement Plan with Company Match and Immediate Vesting
· Wellhub Fitness and Wellness Platform
· Pet Insurance
· Training Opportunities
· Employee Referral Bonus Program
We are committed to fostering a workplace that supports both your personal and professional aspirations.
As part of our commitment to maintaining a compliant workplace, all final candidates will undergo and must successfully pass a pre-employment (post offer) background check. The background check may include, but is not limited to, verification of employment history, education, criminal records, and other relevant checks. Background check results will be evaluated in accordance with applicable law. For certain positions, additional client-specific background screenings may be required at the time of hire or in the future, in accordance with client requirements.
If you think you are a good fit for us, we encourage you to apply. Check out our career website for all open positions!
Voyatek provides equal employment opportunities to all employees and applicants for employment. Voyatek will make employment decisions without regard to race, color, creed, ancestry, national origin, citizenship, sex or gender (including pregnancy, childbirth, and pregnancy-related conditions), gender identity or expression (including transgender status), sexual orientation, marital status or domestic violence victim status, religion, age, disability, genetic information, service in the military, or any other characteristic protected by applicable federal, state, or local laws and ordinances. Employment decisions include all terms and conditions of employment, including recruitment and hiring, job assignment/ placement, promotion, upgrading, demotion, termination, layoff, recall, transfer, leave of absence, rates of pay or other compensation, internship, and training.
$59-61 hourly 34d ago
Senior Information Security Analyst (NOT Remote)
Saint Francis Health System 4.8
Information security analyst job in New Haven, CT
Current Saint Francis Employees - Please click HERE to login and apply. Full Time Days PLEASE NOTE: Due to the nature of this role, candidates must be either local to the area or willing to relocate, as this position requires full-time onsite presence. Job Summary: As a member of the InformationSecurity team, responsibilities include manages and mitigates informationsecurity risk by identifying, evaluating, assessing, designing, monitoring, administering, reporting and implementing systems, policies and processes. Provides informationsecurity risk insight and guides management on informationsecurity risk issues and serves as advisor to peers, team members and management.
Minimum Education: Bachelor's degree in Computer Science, MIS, Computer Engineering, Cyber Security or related discipline.
Licensure, Registration and/or Certification: None. One or more of the following certifications are preferred: Certified Information Systems Security Professional (CISSP), or Certified in Risk and Information Systems Control (CRISC) or Certified Information Systems Auditor (CISA).
Work Experience: 3 - 4 years related experience inclusive of two years working directly in an Information Services department and previous experience with HIPAA/PHI compliance programs, policies, procedures, risk assessments and audits.
Knowledge, Skills and Abilities: In-depth knowledge of cyber security methodology and security practices. Knowledge of HIPAA, PCI, SOX, ISO and NIST cybersecurity frameworks. Knowledge of intrusion detection and intrusion prevention systems, penetration and vulnerability testing. Knowledge of data loss prevention, anti-virus and anti-malware software tools. Knowledge of computer networking, TCP/IP, routing and switching, network protocols and packet analysis tools. Knowledge of Windows, UNIX and Linux operating systems. Excellent problem solving and analytical skills. Excellent written and oral communication skills. Excellent organizational and interpersonal skills. Ability to work independently as well as in a team setting.
Essential Functions and Responsibilities: Define, implement, and enforce informationsecurity policies, strategies, and procedures that align with healthcare laws and regulations, such as HIPAA. Conduct and/or support targeted risk assessment. Determine significant risk points and exercise process for risk assessment and risk acceptance. Review assessment results for vulnerabilities, gaps, control deficiencies, and work with key stakeholders to establish plans for sustainable resolution. Maintain an effective informationsecurity awareness program and educate internal teams on best practices. Ensures that business and clinical software applications include adequate information and security controls. Establish and maintain metrics based on the informationsecurity framework used at SFHS.
Decision Making: Independent judgment in making decisions from many diversified alternatives that are subject to general review in final stages only.
Working Relationships: Works directly with patients and/or customers. Works with internal customers via telephone or face to face interaction. Works with external customers via telephone or face to face interaction. Works with other healthcare professionals and staff. Works frequently with individuals at Director level or above.
Special Job Dimensions: None.
Supplemental Information: This document generally describes the essential functions of the job and the physical demands required to perform the job. This compilation of essential functions and physical demands is not all inclusive nor does it prohibit the assignment of additional duties.
Information Technology - InformationSecurity - Yale Campus
Location:
Tulsa, Oklahoma 74136
EOE Protected Veterans/Disability
$82k-110k yearly est. Auto-Apply 60d+ ago
Strategic IT Analyst/Internal Consultant
Twiceasnice Recruiting
Information security analyst job in Stamford, CT
Salary: $90,000-$130,000 + 5% Annual Bonus + Benefits Benefits: Medical, Dental, Vision, Life & Disability, 401K w/ 4% Match, PTO Job Type: Full-Time, 2-3 days on site in Stamford, CT
Core Hours: Monday-Friday, 8:00am-5:00pm
Start Date: ASAP
Sponsorship: Not available
Relocation Assistance: Not Available
Travel: Up to 15% Domestic
Strategic IT Analyst/Internal Consultant Description
Our client in the manufacturing industry is seeking a Strategic IT Analyst to join their team in Stamford, CT, supporting the company's ongoing growth and digital transformation. This is an excellent opportunity for a candidate with a growth mindset and strong interest in technology who can bring curiosity, flexibility, and problem-solving skills to a wide variety of projects. Under the guidance of the Director of Business Applications, you will be supported as you take on initiatives such as streamlining and automating processes, evaluating technology tools to drive efficiency across the business, and interfacing with stakeholders to identify pain points and craft technology solutions. To succeed, you must be comfortable stepping into unstructured problems, asking thoughtful questions, considering dependencies and impacts, and proposing creative solutions. Prior IT or consulting experience is a plus, but openness, adaptability, and motivation are even more important. This is a great opportunity to play a key role in the digital transformation of a profitable and growth-focused organization.
Strategic IT Analyst/Internal Consultant Responsibilities
• Collaborate with business users to capture pain points and requirements
• Document current and future-state business processes for digital transformation initiatives
• Explore new technology tools and develop business cases for their implementation
• Translate requirements into clear functional specs for software and data teams
• Facilitate discussions to align business and technical stakeholders
• Identify gaps and recommend process and system improvements
• Support continuous improvement efforts for the corporate technology organization
• Assist with user acceptance testing and validate business needs
• Prepare training materials and support user onboarding
Strategic IT Analyst/Internal Consultant Qualifications
• Bachelor's degree is required
• 1+ years of strategic problem-solving experience is required
• Strong interest in technology and willingness to take on a broad range of projects is required
• Solid skills in documentation and stakeholder communication are required
• Ability to work on-site in Stamford, CT (2-3 days per week) and travel up to 15% is required
$90k-130k yearly 60d+ ago
Firewall Security Engineer
Comprehensive Resources
Information security analyst job in Stamford, CT
Duration: 6+ Months
Experienced Firewall administrator for operational implementation, maintenance and configuration of firewalls.
Key Responsibilities:
Performs maintenance and changes in firewalls as required.
Implementation of new firewalls as required
Assists with troubleshooting network connectivity as it relates to firewalls
Utilizes change management, request, and ticketing systems, documents status updates and problem resolutions
Complete All assignments in a timely manner with an acceptable level of quality
Maintains documentation related to work area
Completes network change requests
Follows documented processes, procedures and policies
Performs customer service duties and responds to customer and project requests as defined by management
Other related duties assigned as needed.
Qualifications/Requirements:
Bachelor's degree and with 3 to 4 years of operational experience administering Firewalls
4 or more years networking/firewall background
Must have networking TCP/IP routing protocol experience
Desired Characteristics:
In-depth experience in security aspects of multiple platforms, operating systems, software, communications and network protocols is desired
Competency in verbal, written, and presentation communications and interpersonal understanding
Ability to understand customer's business needs.
Leadership of work teams/groups
Ability to work with all levels of employees
Highly motivated and able to work effectively under minimal supervision in a fast-paced environment
Team-oriented, placing priority on quality and the successful completion of team goals
Organization and planning skills that include: time management, project coordination and management, and the ability to handle multiple deadlines and associated pressures.
Competency in developing effective solutions to business problems
Ability to analyze problems and to make decisions
REQUIRED SKILLS
YEARS OF EXPERIENCE
WHEN THE SKILL WAS LAST USED
Expert knowledge of Cisco Security products, ASA and Firepower
Expert knowledge of NSX
Expert knowledge of Palo Alto systems
Security Certifications a Plus
Must have networking TCP/IP routing protocol experience
Networking/firewall background
Operational experience administering Firewalls
Additional Information
All your information will be kept confidential according to EEO guidelines.
$83k-114k yearly est. 60d+ ago
Data Security Engineer
Cloud Peritus
Information security analyst job in Stamford, CT
What you'll do
• Design and implement comprehensive data security architectures, with particular focus on database platforms (primarily SQL Server) • Develop and maintain enterprise-wide encryption strategies for securing structured and unstructured data both in transit and at rest, both and both on-premise and in the cloud
• Enhance logging, monitoring and SecOps capabilities of enterprise databases and other data stores
• Configure and optimize Identity and Access Management (IAM) solutions across data platforms and repositories to align to least privilege principles
• Implement Data Loss Prevention (DLP) strategies and controls
• Implement and maintain Information Rights Management (IRM) and Digital Rights Management (DRM) solutions
• Design and implement data tokenization strategies where appropriate
• Secure data processing pipelines and ensure appropriate controls for data workflows
• Create and maintain data security documentation, including policies, procedures, and standards
• Collaborate with development teams to ensure security best practices in data handling
• Conduct vulnerability assessments of the firm's database architecture and associated data storage and processing systems
• Assist in monitoring and managing security patching and upgrade processes for database platforms
What's required
• Bachelor's degree in computer science, cybersecurity, or related technical field
• 6+ years of experience in data/database security engineering and governance
• Deep expertise in database security, particularly SQL Server
• Comprehensive understanding of data warehouse/data lake architectures and tools, particularly Databricks (required)
• Subject matter expertise in Object Storage (eg: S3, Azure Blob, etc) and related security
• Understanding of Active Directory Delegation (constrained vs. unconstrained) and associated best practices
• Experience with 3rd-party SQL Server security governance and monitoring products (eg: Idera, Solarwinds)
• Extensive knowledge of encryption technologies for both structured and unstructured data
• Broad knowledge of secure data/file sharing solutions and ETL workflows
• Experience designing and implementing data tokenization solutions
• Experience with data classification and DLP technologies
• Scripting/automation capabilities (eg: SQL, PowerShell, Python)
• Commitment to the highest ethical standards
Qualifications
Ivy league colleges education preferred or huge plus.
Additional Information
All your information will be kept confidential according to EEO guidelines.
$83k-114k yearly est. 60d+ ago
Director of Information Security
Hofstra University 4.5
Information security analyst job in Hempstead, NY
About Hofstra Hofstra University is nationally ranked and recognized as Long Island's largest private university located in Hempstead, N.Y. When you work at Hofstra, you join a team of talented professionals committed to preparing students for the challenges of tomorrow, in an environment that cultivates learning through the free and open exchange of ideas for the betterment of humankind. The work we do at Hofstra supports the education and well-being of our students, and the workforce of the future. While working towards this mission, employees can take advantage of many enriching experiences on campus. Whether it's a lunchtime lecture, a Division I NCAA athletics game, a musical concert, a theatre performance, or a visit to one of our two accredited museums, there is always something exciting to do at Hofstra. Enjoy the ease of going to the fitness center, taking a swim, or grabbing a bite to eat without having to leave our beautiful campus! Hofstra University is dedicated to recruiting and retaining a highly qualified and diverse academic community of students, faculty, staff, and administrators respectful of the contributions and dignity of each of its members. We welcome applications from individuals of all backgrounds and experiences and are committed to building a diverse and inclusive community.
Position Title Director of InformationSecurity Position Number 896570 Position Category Administration School/Division ITS InformationSecurity (division) Department ITS InformationSecurity Full-Time or Part-Time Full-Time Description
Reporting to the Chief Information Officer (CIO), the Director of InformationSecurity is a member of the ITS senior leadership team and works closely with the campus community, including academic and administrative departments. The Director is an advocate for the University's informationsecurity needs and is responsible for the development and delivery of a comprehensive informationsecurity strategy to optimize the informationsecurity posture of the University.
The Director leads the development and implementation of a security program that leverages collaborations and campus-wide resources, facilitates informationsecurity governance, advises senior leadership on security direction and resource investments, and designs appropriate policies to manage informationsecurity risk. The complexity of this position requires a leadership approach that is engaging, imaginative, and collaborative, with a sophisticated ability to work with other leaders to set the best balance between security strategies and other priorities at the campus level.
InformationSecurity Program Leadership
* Responsible for the strategic leadership of the University's informationsecurity program.
* Provide guidance and counsel to the CIO and key members of the University's leadership team, working closely with senior administration, academic leaders, and the campus community in defining objectives for informationsecurity, while building relationships and goodwill.
* Manage institutional informationsecurity governance processes.
* Lead informationsecurity planning to establish an inclusive and comprehensive informationsecurity program for the entire institution in support of academic, research, and administrative information systems and technology.
* Establish annual and long-range security and compliance goals, define security strategies, metrics, reporting mechanisms and program services, and create maturity models and a roadmap for continual program improvements.
* Stay current with informationsecurity issues and regulatory changes affecting higher education at the state, national, and global levels. Participate in policy and practice discussions and communicate to campus on a regular basis about those topics. Engage in professional development to maintain continual growth in professional skills and knowledge essential to the position.
* Provide leadership philosophy for the ITS InformationSecurity team (currently two staff, in addition to the director), create and maintaining strong working relationships with other teams, build respect for the contributions of all and bring groups together to share information and resources and create better decisions, policies, and practices for the University.
* Provide mentorship to InformationSecurity team members and implement professional development plans for all members of the team.
* Special projects and other duties as assigned.
Policy, Compliance, and Audit
* Participate in the development and implementation of effective and reasonable policies and practices to secure protected and sensitive data and ensure informationsecurity and compliance with relevant legislation and legal interpretation.
* Lead efforts to internally assess, evaluate and make recommendations to management regarding the adequacy of the security controls for the University's information and technology systems.
* Work with Internal Audit, outside auditors, and other consultants as appropriate to complete security assessments and audits.
* Coordinate and track all information technology and security related audits including scope of audits, units involved, timelines, participants, and outcomes. Work with auditors as appropriate to keep audit focus in scope, maintain excellent relationships with audit entities and provide a consistent perspective that continually puts the institution in its best light. Provide guidance, evaluation, and advocacy on audit responses.
* Work with University leadership and relevant responsible compliance department leadership to build cohesive security and compliance programs for the University to effectively address applicable statutory and regulatory requirements.
Outreach, Education, and Training
* Work closely with other ITS leaders, technical experts, and academic and administrative leaders across campus on a wide variety of security issues that require an in-depth understanding of the IT environment in their units, as well as the research landscape and regulations that pertain to their unit's research areas.
* Create education and awareness programs and advise academic and administrative units at on security issues, best practices, and vulnerabilities.
* Work with campus groups to build awareness and a sense of common purpose around informationsecurity.
* Pursue student security initiatives to address unique needs in protecting identity theft, mobile social media security, and online reputation program.
Risk Management and Incident Response
* Keep abreast of security incidents and act as primary control point during significant informationsecurity incidents. Convene a Security Incident Response Team (SIRT) as needed, or requested, in addressing and investigating security incidences that arise.
* Develop, implement, and administer technical security standards, as well as a suite of security services and tools to address and mitigate security risk.
* Provide leadership, direction, and guidance in assessing and evaluating informationsecurity risks and monitor compliance with security standards and appropriate policies.
* Examine impacts of new technologies on the University's overall informationsecurity. Establish processes to review implementation of new technologies to ensure security compliance.
Qualifications
* Bachelor's degree required.
* Minimum five years of full-time professional experience in information technology, including evidence of successful and progressively responsible roles in informationsecurity or related area (including growth in levels of responsibility, complexity of work, numbers, and sophistication of employees) related to the essential responsibilities listed.
* Demonstrated fluency in written and spoken English with the sophistication necessary to effectively communicate technical details to both technical and non-technical individuals.
* Demonstrated willingness and ability to carry out the essential responsibilities listed with humility, grace, and optimism.
* Demonstrated understanding of, sensitivity to, and respect for the academic, cultural, and social diversity in the Hofstra University community.
Preferred Qualifications
* Advanced degree in computer science, computer engineering, informationsecurity, or related field strongly preferred.
* One or more relevant professional certifications (e.g., CISSP, CISM/A, etc.) strongly preferred.
* Experience with state and federal informationsecurity regulatory requirements (GLBA, FERPA, HIPAA, etc.) and other compliance requirements (PCI, etc.).
* Knowledge of and experience applying industry-standard IT security frameworks (NIST, IHECF, etc.).
* Significant experience in computing and informationsecurity, network security issues, and security incident response and recovery in a higher education environment.
* Significant experience in communicating informationsecurity principles and concepts to non-technical stakeholders, and success in improving cybersecurity awareness in a higher education environment.
* Working knowledge of the informationsecurity policy and regulatory environment of informationsecurity, particularly in higher education.
* Demonstrated experience and success in advising and collaborating with key stakeholders relevant to the essential responsibilities listed, including senior leadership, Internal Audit, outside auditors, and consultants.
* Professional experience in a leadership role in a higher education institution.
Special Instructions Deadline Open Until Filled Date Posted 09/18/2023 EEO Statement
Hofstra University is an equal opportunity employer and is committed to extending equal opportunity in employment to all qualified individuals without regard to race, color, religion, sex, sexual orientation, gender identity or expression, age, national or ethnic origin, physical or mental disability, marital or veteran status or any other characteristic protected by law.
Salary/Salary Range $160,000 - $170,000
Additional Information
Hofstra University provides the above salary* as a good faith estimate of the starting pay range which considers factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience and education. In addition to the salary offered, we offer a collegial and inclusive culture, and a benefits program which includes generous paid time off, paid holidays, tuition remission for employees and eligible dependents, and a retirement plan with University contributions.
* Salary ranges indicated for positions covered under a Collective Bargaining Agreement are in accordance with the CBA.
$160k-170k yearly 60d+ ago
Chief Information Security Officer
Subway 4.2
Information security analyst job in Shelton, CT
Title - Chief InformationSecurity Officer Region: Shelton, CT Ready for a fresh, new career? Look no further because one of the world's most iconic brands can help you get there. Why Join Us? At Subway, "better" is baked into our DNA. We are a brand that believes in continued improvement … in our lives, our businesses, and our planet. From the handshake that started our very first sandwich shop to earning our position as one of the world's leading restaurant brands, we've always embraced change and the path ahead. And today, we're making better living way easier.
Our purpose is more than the food we serve in our restaurants. It's centered on fueling healthy businesses and healthier lives. It is one of the most exciting times to join the Subway team and contribute to our transformational journey.
About the Role:
The Chief InformationSecurity Officer is responsible for leading the organization's cybersecurity strategy and operations. This role is focused on protecting company data, systems, and networks from cyber threats, ensuring the confidentiality, integrity, and availability of critical information assets. The CISO develops and implements cybersecurity policies, technologies, and incident response plans to defend against evolving threats and vulnerabilities and drives continuous improvement in the organization's cyber defense posture.
Responsibilities:
Develop and implement a comprehensive cybersecurity strategy aligned with the organization's business goals, focusing on the protection of data, systems, and networks.
Establish and enforce informationsecurity policies, standards, and procedures to ensure compliance with relevant laws, regulations, and industry best practices.
Develop and oversee incident response plans for operational risks.
Oversee incident response plans to effectively address and mitigate the impact of security incidents.
Oversee the monitoring of networks and systems for security breaches, vulnerabilities, and suspicious activity; coordinate rapid response to cyber incidents.
Continuously assess and prioritize cybersecurity risks, considering emerging threats, vulnerabilities, and technology trends.
Select and implement appropriate security controls and technologies to defend against cyber threats.
Regularly report on the organization's informationsecurity risk posture to executive leadership and relevant stakeholders. Collaborate with IT and business leaders to integrate cybersecurity considerations into technology projects and business processes
Manage third-party risk as it relates to cybersecurity, ensuring vendors and partners adhere to company security standards.
Foster an informationsecurity aware culture by promoting best practices and proactive security/risk management behaviors.
Develop and deliver training programs to enhance operational informationsecurity awareness across the organization. Implement programs to raise awareness of informationsecurity risks among employees and stakeholders.
Ability to align cybersecurity with business objectives.
Deep expertise in cybersecurity technologies, threat intelligence, and incident response.
Strong understanding of network, system, and application security
Experience with security operations centers (SOC), vulnerability management, and penetration testing.
Leadership and team management skills.
In-depth knowledge of cybersecurity technologies and trends.
Leadership and team management capabilities.
Knowledge of relevant regulatory requirements and industry best practices. (e.g., NIST, ISO 27001, GDPR).
Strong knowledge of industry regulations, standards, and best practices.
Qualifications:
Bachelor's Degree Business, Finance, Risk Management, InformationSecurity, Computer Science, or a related field.
15 or more Extensive experience in cybersecurity, informationsecurity, or related technical fields, with a proven track record in leadership roles.
Demonstrated experience in designing and managing enterprise cybersecurity programs, incident response, and security operations
What do we Offer?
Insurance Plans (Medical/Life)
Pension/401K/RSP (country specific)
Competitive Bonus
Mobility Allowance
Tuition Reimbursement
Company Holidays
Volunteering time
And Many More…..
Actual pay is determined based on several job-related factors including skills, education, training, credentials, qualifications, scope and complexity of role responsibilities, geographic location, performance, and working conditions.
$140k-177k yearly est. 44d ago
OT Security Engineer
Crane Co 4.3
Information security analyst job in Stamford, CT
The OT Security Engineer, Global InformationSecurity (GIS) will have primary responsibility for Crane's Operational Technology security solutions that protect Crane's manufacturing environments. You will implement OT and IoT security solutions throughout the enterprise and ensure that OT/IoT security solutions identify threats, uncover vulnerabilities, and measure risks of operational equipment.
Coordinating with both IT and OT teams at all manufacturing sites, you will define and develop security standards and technical solutions. As a subject matter expert in the hardening and defense of OT, you will work with business units to implement security standards, securely modify systems, and implement secure network architectures during implementations of OT related projects to ensure secure system deployments.
You will work closely with other GIS functional areas, supporting security engineering, administration, operations, and incident response. You will integrate the OT/IoT security solutions with other GIS and business unit tools such as SIEM, SOAR, AD, and other tools to gain a unified view of security events and respond more effectively to security incidents both for OT and IT.
Responsibilities and Duties:
Support and maintain OT/IoT security tool set and associated integrations with other systems
Collaborate with the manufacturing function across lines of business to develop and define security requirements
Design OT security controls for architectures, systems and networks ensuring that alerting to threats is efficient and effective.
Identify and implement supporting security technologies for the identification of threats and defense of OT systems and provide secure methods for remote access.
Work directly with plant leaders, process engineers, and support/system vendors to ensure OT security controls are implemented
Develop and implement standard work supporting the Global OT security function and supporting solutions
Develop and maintain security models, templates, standards and procedures that can be used to leverage security capabilities in projects and operations
Assist in the identification, response, investigation, and remediation of OT security events and incidents as needed
Ensure security best practices are identified and integrated into all approaches and methodologies.
Define requirements and design standards to protect Crane's OT solutions from security threats and for mitigating the impacts of these threats.
Define reference network architectures based on industry best practices and work with business units to implement for OT solutions
Consult on business unit OT projects and provide cybersecurity expertise
Qualifications and Competencies:
2yrs experience with securing Operational Technology and related systems environments
Strong understanding and prior experience with the application of securing OT and related systems
Current deep technical understanding of common OT systems such as PCS, SCADA, PLCs, RTUs, HMIs, CNC
Deep technical understanding of TCP/IP Networking and Firewalls
Deep technical understanding of system integration methods including API's and authentication methods
Knowledgeable in NIST CSF, NIST 800-82, Purdue Model, IEC 62443 standards
Solid foundation cybersecurity domains such as network security, EDR, anomaly detection
Understanding of common OT communications protocols such as MQTT, MODBUS, DNP3, S7, G-code
Comfortable with designing and overseeing the implementation of secure OT architectures
Prior experience in the direct remediation of vulnerabilities or compensating controls within OT environments
Commitment to security training and earning corresponding certifications
Highly motivated with passion for solving complex problems
Excellent verbal and written communication skills, comfortable with presenting to Operational Teams
Flexibility to work outside regularly scheduled/normal business hours as required
Ability and desire to travel both domestically and internationally
Required: Degree in a related field or at least 4 years relevant professional experience
Required: Mobility and ability to be on your feet for long periods in a manufacturing setting
Required: Technical professional security certification such as GICSP, GRID, OSCP, CEH or similar
US Person as defined under EAR PART 772 AND ITAR 120.15
This description has been designed to indicate the general nature and level of work being performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of employees assigned to this job.
Crane Company. is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment and will not be discriminated against on the basis of race, color, religion, gender, sexual orientation, general identity, national origin, disability or veteran status.
$64k-91k yearly est. Auto-Apply 39d ago
Senior Cyber Security Engineer
BIC Corporation 4.8
Information security analyst job in Shelton, CT
For over 75 years, BIC has been creating ingeniously simple and joyful products that are a part of every heart and home. As a member of our team, you'll be a part of reigniting a beloved brand as we continue to reimagine everyday essentials in new, sustainable and responsible ways.
Our "roll up your sleeves and get the job done" approach to work creates an environment where self-starters, problem solvers and innovative thinkers thrive. BIC team members are empowered to take ownership of their careers and bring their unique perspectives to the table to make a meaningful impact on our mission.
It's a colorful world - make your mark by joining the BIC team today.
As **Senior Cybersecurity Engineer,** you will collaborate and partner with a global, cross-functional team to build cybersecurity capabilities and improve maturity. This role involves designing, implementing, and managing security technology to protect the company from cyber threats. Besides, you will support incident response, investigations, playbook development and efforts to identify and mitigate risk.
**In this role you will:**
+ Analyze, triage, and investigate alerts from various sources to determine the appropriate response or escalation
+ Document analysis, findings, and actions for case management and metrics
+ Support security incident response planning, procedure/playbook development and investigations
+ Participate in on-call rotation for off-hours escalations
+ Administer, optimize, and maintain the health of security tools, such as endpoint protection and response (EDR), network detection and response (NDR), and logging pipelines (Syslog/Cribl).
+ Assist with remediation of identified security risks
+ Minimum 6 years' experience in Information Technology or Cybersecurity
+ IT or cybersecurity certifications from industry recognized sources preferred
**What you bring to BIC:**
+ Minimum 6 years' experience in Information Technology or Cybersecurity
+ IT or cybersecurity certifications from industry recognized sources preferred
+ Prior experience interpreting or analyzing log data and working with log pipelines
+ Triaging alerts from various sources, following playbooks, and escalating legitimate issues
+ Knowledge of security tools such as endpoint protection, firewalls, intrusion prevention, SIEM and EDR (CrowdStrike)
+ Strong understanding of Windows server and desktop operating systems, networking fundamentals, security concepts, Active Directory, Microsoft Azure, Office 365.
+ In-depth analytical and problem-solving skills to resolve complex issues
BIC is an Equal Opportunity Employer. We strongly commit to hiring people with different backgrounds and experiences to help us build better products, make better decisions, and better serve our customers. We do not discriminate based upon race, religion, color, national origin, gender, sexual orientation, veteran status, disability status, or similar characteristics. All employment is decided based on qualifications, merit, and business need.
BIC is not seeking assistance or accepting unsolicited resumes from search firms for this employment opportunity. Regardless of past practice, all resumes submitted by search firms to any team member at BIC via email, or directly to a BIC team member in any form without a valid written search agreement in place for that position will be deemed the sole property of BIC, and no fee will be paid in the event the candidate is hired by BIC as a result of the referral or through other means.
$75k-93k yearly est. 60d+ ago
Director of Information Security
Hofstra University 4.5
Information security analyst job in Hempstead, NY
Qualifications Bachelor's degree required. Minimum five years of full-time professional experience in information technology, including evidence of successful and progressively responsible roles in informationsecurity or related area (including growth in levels of responsibility, complexity of work, numbers, and sophistication of employees) related to the essential responsibilities listed. Demonstrated fluency in written and spoken English with the sophistication necessary to effectively communicate technical details to both technical and non-technical individuals. Demonstrated willingness and ability to carry out the essential responsibilities listed with humility, grace, and optimism. Demonstrated understanding of, sensitivity to, and respect for the academic, cultural, and social diversity in the Hofstra University community.
Preferred Qualifications
Advanced degree in computer science, computer engineering, informationsecurity, or related field strongly preferred. One or more relevant professional certifications (e.g., CISSP , CISM /A, etc.) strongly preferred. Experience with state and federal informationsecurity regulatory requirements ( GLBA , FERPA , HIPAA , etc.) and other compliance requirements ( PCI , etc.). Knowledge of and experience applying industry-standard IT security frameworks ( NIST , IHECF , etc.). Significant experience in computing and informationsecurity, network security issues, and security incident response and recovery in a higher education environment. Significant experience in communicating informationsecurity principles and concepts to non-technical stakeholders, and success in improving cybersecurity awareness in a higher education environment. Working knowledge of the informationsecurity policy and regulatory environment of informationsecurity, particularly in higher education. Demonstrated experience and success in advising and collaborating with key stakeholders relevant to the essential responsibilities listed, including senior leadership, Internal Audit, outside auditors, and consultants. Professional experience in a leadership role in a higher education institution.
$102k-130k yearly est. 60d+ ago
Learn more about information security analyst jobs
How much does an information security analyst earn in Smithtown, NY?
The average information security analyst in Smithtown, NY earns between $71,000 and $138,000 annually. This compares to the national average information security analyst range of $71,000 to $135,000.
Average information security analyst salary in Smithtown, NY