- Company Name
- VARITE INC
- Job Title
- Information Security Analyst
- Job Description
-
**Job Title**
Information Security Analyst
**Role Summary**
Interpret and enforce information security policies, standards, and regulatory requirements within internal information systems. Lead the redesign and reengineering of processes to protect data from unauthorized disclosure, use, modification, deletion, and downtime. Conduct risk assessments, vulnerability analysis, penetration testing, and develop mitigation plans. Manage and support security tools, patching, and incident tracking, and prepare system security plans for certification and accreditation.
**Expectations**
- Minimum 5 years overall security experience, with at least 3 years in security analysis.
- Proven expertise in NIST 800‑53, risk assessment, vulnerability analysis, gap analysis, and mitigation strategy development.
- Ability to execute standard certification and accreditation methodologies.
- Demonstrated track record in penetration testing, password & application security testing, and incident management.
**Key Responsibilities**
- Analyze and interpret security policies and standards for internal systems.
- Redesign information handling processes to meet protection requirements.
- Perform vulnerability scans, penetration tests, and security audits.
- Develop and maintain system security plans, certification, and accreditation documentation.
- Assess and mitigate security threats and risks; provide strategic recommendations.
- Manage security tools, install and configure security solutions, monitor patches, and track incidents.
**Required Skills**
- In-depth knowledge of NIST guidelines and security frameworks.
- Experience with vulnerability assessment, penetration testing, and gap analysis.
- Strong analytical, problem‑solving, and documentation abilities.
- Familiarity with security tool management and patch lifecycle.
- Effective communication skills for cross‑functional collaboration.
**Required Education & Certifications**
- Bachelor’s degree in IT, Computer Science, Engineering, or related field (or equivalent experience).
- Security certifications: Security+, Certified Ethical Hacker (CEH), Cloud Security Professional, CISSP, or equivalent.