Job Closed
This listing is no longer active.
Ivanti finds, heals and protects every device, everywhere – automatically.
Principal Security Analyst, Staff Security Analyst
Location
United States
Posted
159 days ago
Salary
0
Seniority
Lead
Job Description
Principal Security Analyst, Staff Security Analyst
Ivanti
• Promote, educate and present Security, Risk and Issue information to key stakeholders and the business in all departments to ensure sound risk principles and how they are applied are represented. • Maintain the risk artifacts (register, acceptances/exceptions, vendor onboarding and vendor risk profiles, evaluation SBARCs, reports, metrics). • Execute Corporate, Product, Business Impact and Emerging Tech risk assessments, some as large-scale projects to include interviews, data collection, parsing and analysis, and modeling. • Integrate with partners in Security, Audit and Compliance, Procurement and Legal by understanding the frameworks and vocabularies they are using. • Using deep experience, develop and/or execute logical risk, threat and/or probability models whether automated or manually run. • Develop and maintain human networks including major stakeholders to propagate risk program support; Socialize challenging or counterintuitive future insights into likely risk events to create general risk awareness and thoughtfulness. • Work with total honesty and integrity, declaring errors and proposing fixes immediately, recognizing escalation-worthy information and escalating appropriately, providing confidence levels as appropriate in results. • Be prepared to build things brand new to the organization, whether a special purpose model or new nascent program processes to fill a gap.
Job Requirements
- Minimum 8 years Security Risk Management
- Preferred 12 years of Security Risk Management (as distinct from Compliance, Audit, Governance, Vulnerability Management, or Third-Party Risk).
- Imagination, creativity, well-grounded logic.
- Program or model building experience in a senior role.
- Ability to differentiate progress versus using time management skills.
- Can evaluate, analyze, and interpret large quantities of data into high-quality intelligence products.
- Ability to go beyond framework, regulation, or best practices to think critically and engineer processes when concepts or demands are complex or not well-defined.
- High flexibility to change priorities or redefine work to meet short and or long-term requirements.
- Bachelor’s Degree in a related field. Does not need to be in Computer Science.
- Any related certifications is a plus.
Benefits
- Friendly flexible working model: Empower excellence whether you’re at home or in the office and support work-life balance
- Competitive compensation & total rewards: Including health, wellness, and financial plans tailored for you and your family.
- Global, diverse teams: Collaborate with talented people from 23+ countries.
- Learning & development: Grow your skills with access to best-in-class learning tools and programs.
- Equity & belonging: We value every voice. Your story helps inform our solutions for a changing world
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
• Analyze application architectures to identify security risks and potential attack paths • Perform secure code reviews and vulnerability assessments, recommending effective remediation • Integrate security tools and automated checks into CI/CD and DevOps pipelines • Use static and dynamic scanning tools to identify, prioritize, and track security findings • Partner with developers and operations teams to embed security throughout the SDLC • Document and report application security issues, including remediation guidance and validation • Support new application and technology launches to prevent misconfigurations and data exposure • Collaborate with red teams, threat intelligence, and risk teams to reduce overall attack surface • Communicate security risks clearly to both technical and non-technical audiences • Support internal and external audits focused on compliance and risk reduction • Help define metrics and KPIs that demonstrate the effectiveness of the application security program • Participate in change management discussions and continuous improvement initiatives
Security Analyst
Cedars-SinaiFounded in 1902, Cedars-Sinai is a nonprofit academic medical center located in Los Angeles, California. As an employer, the company offers many opportunities for career advancemen
• The Epic Security Analyst provides an intermediate level of operational and application build in completing routine and occasionally more sophisticated assignments to meet customer goals and desired outcomes. • Task and assignment focus are typically on medium to large projects, performing workflow analysis, build, and documentation in collaboration with internal and external team members. • Based on core knowledge of application and operational requirements can translate requirement/concepts into functionality. • Assigned to various work/projects and demonstrates an ability to successfully complete assigned tasks/assignments, proactively connect with manager to prioritize workflow and mitigate risks, track issues, provide solution-oriented escalation, and understand fundamental project management methodologies. • Participates in re-engineering of operational work-flow processes with end-users/business owners and maintains fundamental understanding of assigned departmental operations. • Facilitates end-user/business owner needs into system specifications and configuration requirements. • Manages navigation of migration paths, change control process/governance, and ticket management processes. • Maintains high standards for quality application design, build, testing, and other tasks; ensures adequate documentation is provided for support and end-user training.
Security Analyst – Bug Bounty
NCC GroupA global team at the heart of cyber innovation, together we create a more secure digital future
• Analyze and fully reproduce potential security findings reported to our clients • Communicate with the global researcher community to gather information and inform them of triage analysis outcomes • Author and deliver NCC-quality vulnerability reports to the specifications of individual clients • Drive or contribute to projects that improve Bug Bounty Services’ tooling, operational processes, and delivery quality
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description DecisionPoint Corporation is seeking an Information Security Analyst to join our team! This role will support the design and implementation of a comprehensive approach to securing government networks and applications while ensuring compliance with federal security and oversight requirements. This position is fully remote. This requisition is contingent upon additional funding. Duties & Responsibilities - Provide guidance to ensure project compliance to the United States Government Baseline (USGCB) for IT Security, taking into account agency policies, default configurations and settings, IPv6 security capabilities, and any other potential IPv6 requirements. - Provide technical expertise of computer security laws, mandates, standards and policies in accordance with the Federal Information Security Management Act (FISMA) as amended, National Institute of Standards and Technology (NIST) Special Publications (SPs), Office of Management and Budget mandates, the Department of the Treasury policies for information security requirements and Federal Risk Management Program (FedRAMP) authorization process. - Utilize technical expertise of computer theories, principles, practices and industry standards to complete computer security related functions that include certification and accreditation of government information and telecommunications system, IT disaster recovery and business continuity planning, and risk management activities. - Represent the project in internal and external meetings, working groups, and integrated project teams to provide IT security compliance requirements. - Help in evaluating relevant global standards, compliance frameworks and regulations to analyze existing controls; identify areas for improvement; and design control growth. - Participate in internal security and compliance program and track recurring controls. - Help support customer security reviews, RFPs and external security and privacy inquiries. - Help support internal/external audits and evidence collection. - Document new and update existing policies, procedures, standards and resources. - Participate in Security awareness program, train personnel on data security & privacy related processes and responsibilities. - Participate in defining, collecting and tracking various Security Metrics. - Support vendor management, including vendor risk assessments and security reviews. - Ability to prioritize in a highly dynamic work environment. Qualifications - Ability to obtain a Public Trust and EOD. - Bachelor and three (3) years' or Master and (2) years' experience. - Three (3) years of experience working in information security or compliance, NIST, FISMA, ATO experience. - Technical understanding of IPv6 security requirements and associated network protocols. - Expert-level knowledge of Zscaler security solutions and their implementation in enterprise environments. - Ability to work closely with cross-functional stakeholders. - Ability to communicate effectively, in writing and verbally, to target audiences, including customers, partners, auditors, executive management, vendors, and peers. Desired Skills & Abilities - Work experience with ISO 27001 compliance standard. - Experience working with Security Controls across at least some of the following domains: Access Management, Encryption, Risk Management, Network Security, Configuration Management, Patch Management, Change Management, Awareness & training, BC/DRP, etc. - Ability to balance risk, potential impact, resourcing, business drivers, and timelines. - Advanced degree in computer science, information technology or Information security. - Ability to prioritize in a highly dynamic work environment. Our Equal Employment Opportunity Policy DecisionPoint Corporation is an Equal Employment Opportunity and Affirmative Action employer. It is the policy of DecisionPoint Corporation to provide equal employment opportunity in accordance with all applicable Equal Employment Opportunity/Affirmative Action laws, directives and regulations to all employees and qualified applicants without regard to race, ethnicity, color, religion, national origin, sex, age, disability status, pregnancy, sexual orientation, gender identity, genetic information, protected veteran status, or any other protected status under Federal, State or Local laws. Pay Transparency Policy In accordance with Presidential Executive Order 13665, DecisionPoint Corporation will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor's legal duty to furnish information. Authorization to Share Resume and Personal Information By expressing your interest and submitting your resume for this position, you authorize DecisionPoint Corporation to share your resume, as well as personal information included on the resume, with its subsidiaries, affiliates and teaming partners for the purpose of considering you for this position and other available positions requiring comparable skills, education and experience. Should DecisionPoint Corporation or its affiliates and teaming partners wish to initiate pre-employment discussions, you will be asked to complete an employment application and related employment documents.



