Job Description
We are seeking an Information Security Analyst for a 12-month contract opportunity in Nashville, TN. This role will work a hybrid schedule with remote and in-office responsibilities, so this role will require you to be located within a reasonable commuting distance of Nashville. This role will work Monday-Friday from 8:00 am- 4:30 pm.
In this role, you will be the “front line defense” by ensuring that security alerts are reviewed, remediated, or escalated with appropriate urgency and that all response actions are documented accurately. This is a fundamental role in protecting the information assets of the organization by effectively identifying and responding to potential indicators of compromise or attack.
Responsibilities and Duties
- Enforce policy, guidance, and training requirements according to Best Business Practices
- Ensure implementation of system updates, reporting, and compliance procedures
- Ensure users meet the requisite favorable security investigations, clearances, authorization, need-to-know, and security responsibilities before granting access to the department information
- Ensure users receive initial and annual Cyber Security Awareness training, as well as troubleshoot issues and repair systems
- Ensure log files and audits are maintained and reviewed for all systems and that authentication (for example, password) policies are audited for compliance
- Prepare, distribute, and maintain security plans
- Review and evaluate the effects on the security of system changes
- Ensure that all Systems within their area of responsibility are certified, accredited, and reaccredited
- Ensure system recovery processes are monitored and that security features and procedures are properly restored
- Maintain current software inventory and ensure security-related documentation is current and accessible to properly authorized individuals
- Monitor alerts, detections, or other indicators of compromise/attack from a variety of information security solutions.
- Investigate, contain, eradicate, and/or escalate security detections as appropriate
- Work closely with Cyber Security Architect and network security team to implement and maintain secure network design
- Provide information security expertise to system development teams
- Document and generate reports of detections and response actions for review by management and other stakeholders
- Assist in the analysis of vulnerabilities
- Monitor security platforms’ health for errors, misconfigurations, or performance alerts
- Leverage the SIEM platform by creating and executing search queries, dashboards, and alerts to identify threats and assist in investigations.
- Support end-users and other stakeholders’ requests related to information security service
- Perform control testing and other risk management activities
- Provide information in response to assessments and audits
- Maintain an understanding of the systems, solutions, and technologies deployed on the network
- Works with network monitoring and management applications and creates highly-reproducible configuration scripts and templates