drjobs
Cloud Security Analyst
drjobs Cloud Security Analyst العربية

Cloud Security Analyst

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs

Job Location

drjobs

Metro - Indonesia

Monthly Salary

drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

Req ID : 2656035

Role: Cloud Security Analyst (MidLevel)

Location: Hybrid DC Metro

Employment Requirements: US Citizen

Role Summary:

This role serves as a handson midlevel security analyst who will be responsible for interfacing with the security engineering operations architecture and build teams assisting with the development and/or maintenance of various System Security Plans (SSP) and associated documentation for multiple environments gathering the security control implementations information for the security controls and documenting their implementation in the SSP as well as updating associated security document.Security Analyst (MidLevel)

This role serves as a handson midlevel security analyst who will be responsible for interfacing with the security engineering operations architecture and build teams assisting with the development and/or maintenance of various System Security Plans (SSP) and associated documentation for multiple environments gathering the security control implementations information for the security controls and documenting their implementation in the SSP as well as updating associated security documentation as needed (i.e. plans procedures processes). Additionally this role will assist with the security assessments (i.e. IRS specific security control implementation etc.) to include supporting collection of evidence.

The Security Analyst will be responsible for maintenance of the security documentation for various environments; but concentrating on the SAP HANA Cloud tenants and IRS customer. This position may include development of the security documentation use of RegScale assisting with the IRS FedRAMP SOC or FISMA authorization/assessment processes to include prep of the operations team and documentation summary and update as required. This role serves as a mid level security analyst who assists with the security documentation and can provide thoughtful recommendations on processes and procedures as well as implementation of security controls. This role must communicate between security architecture engineering development and operations teams as required and be able to interpret and document the results of data gathering. Key deliverables for success will be participation and/or facilitation of assessments development and maintenance of security documentation that is current and useful ensuring processes and procedures are current and up to date and assists with assurance that all appropriate IRS and other framework security controls are successfully implemented and associated security documentation is developed and implemented.

This position will also assist with various assessments as a team member or as a lead. This will include scheduling of the interviews collection of evidence working with third party assessors in tracking evidence update of security documentation in preparation of the assessment and other duties as assigned. Customer interaction is also required with clear and concise oral / written responses.

GENERAL RESPONSIBILITES:

  • Gather information architecture diagrams and implementation of the security controls through interfacing with the security engineering operations and build teams.
  • Develop security documentation such as but not limited to System Security Plans (SSP) security plans procedures and processes.
  • Maintain via review and update of all security documentation.
  • Understand the intent of the IRS and FedRAMP security controls FISMA security controls and communicate as needed.
  • Assist with the FedRAMP FISMA PCI ISO SOC etc authorization to include but not limited to prep of operations team through training and mock interviews update documentation as required and support FedRAMP PMO/ Agency / CISO requests.

GENERAL QUALIFICATIONS:

  • Bachelors Degree in Computer Science / MIS / Information Technology or equivalent experience in Information Security Information Technology or related technical discipline.
  • Minimum 7 years Information Technology experience.
  • Experience with Cloud technologies especially AWS Azure and/or Goggle Cloud desirable.
  • Experience with FedRAMP and/or other authorization processes and NIST risk management framework.
  • Experience in developing evaluating and implementing information security architectures technologies standards and practices to secure applications and IT systems desirable
  • Experience in development of security documentation such as SSP policies procedures etc.
  • Flexible selfmotivated and able to work independently in a fast paced environment
  • Excellent communication skills and the proven ability to work effectively with all levels of IT and business management.
  • Familiarity with Testing Development Staging and preproduction environment requiring cyber security support.
  • Knowledge of Privacy Act GDPR and other data privacy frameworks.
  • Experience in writing or executing system security documentation authorization to operate packages POA&Ms and policies.
  • Experience in reviewing/editing/writing technical documents
  • Skill in preparing and making written and oral presentations of complex technical nature.
  • Demonstrated ability to coordinate multiple tasks

SPECIFIC TECHNICAL SKILLS DESIRED:

  • Professional industry certifications in area of expertise.
  • Knowledge of Best Practice and security guides (ex. NIST 80053 rev 4 NIST 80053 FedRAMP)
  • Knowledge of security frameworks to include RMF ISO HIPAA FedRAMP and HIPAA
  • ISC CISSP or ISACA CISM or equivalent certification.

Employment Type

Full Time

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.