General Dynamics is a global aerospace and defense company offering products designed to provide safety and security to people around the world. In the past, General Dynamics has p
Information Security Analyst Principal
Location
United States
Posted
69 days ago
Salary
$98.0K - $132.3K / year
Seniority
Lead
Job Description
Information Security Analyst Principal
General Dynamics
Role Description GDIT is your place. You make it your own. Bring your creativity to help us find simple solutions to complex problems. By owning your opportunity at GDIT, you’ll play an essential part in preparing our nation for the future. Our work depends on an Information Security Analyst Sr Advisor joining our team to support Indian Health Service (IHS). In this role, a typical day will include: - Provide support for DHHS information security. - Facilitate current security infrastructure and define future programs, design and implementation of fire-wall and other related security issues. - Analyze the information systems to ensure that appropriate security functions have been included in the systems design and architecture. - Participate in IHS development processes by providing assistance to developers and conducting security impact assessments for development changes. - Assist with implementation of counter-measures or mitigating controls. - Provide guidance in the creation and maintenance of Standard Operating Procedures and other similar documentation including System Security Plans, Security Manuals, etc. - Manage responses and/or remediation of POAMs related to government investment supported systems. - Maintain current knowledge of relevant technology as assigned. - Participate in special projects as required. - Stay informed as to current and emerging security requirements (e.g., zero trust, SBOM, etc.) and communicate impacts to the team. - Be the conduit between the GDIT team and customer security organizations. Qualifications - Bachelor’s Degree in IT Security, Computer Science, or a related technical discipline, and 10 years of related experience (or) Master's Degree and 8 years (or) PhD/Doctorate and 6 years of related experience. - IT Security implementation and monitoring required. - General knowledge of scientific processes, management structures, and technology programs/platforms. - Familiarity with Agile Software Development Lifecycle (SDLC) Methodology. - Expert knowledge of data security administration principles, methods, and techniques. - Familiarity with domain structures, user authentication, and digital signatures. - Broad knowledge of security (IA) practices and tools is required. - Understanding of network configuration and monitoring. - Understanding of federal security policies and procedures, including FIPS 199, FIPS 200, and NIST 800-53. - Security certification such as a CISSP or CISA. Requirements - Familiarity with Electronic Healthcare technology and operations. - Familiarity with Source Code Control/Version Management software. - Knowledge of the VistA electronic health record or Resource Patient Management System (RPMS). - Understanding of the Department of Health and Human Services (HHS) Enterprise Performance Life Cycle (EPLC). Benefits - Full-flex work week to own your priorities at work and at home, with core work hours Monday – Friday 9:00 AM ET – 3:00 PM ET. - 401K with company match. - Comprehensive health and wellness packages. - Internal mobility team dedicated to helping you own your career. - Professional growth opportunities including paid education and certifications. - Cutting-edge technology you can learn from. - Rest and recharge with paid vacation and holidays. - Challenging work that makes a real impact on the world around you. - Remote work.
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
AI Cybersecurity Analyst
Cyber Managed Services Inc. (CyberMSI)Cutting cyber risk and compliance costs for mid-sized organizations with managed protection, no extra headcount required
• Validate SecOps agent investigations by thoroughly reviewing the incident attack story, associated alerts, involved entities, and correlated signals to ensure accuracy and completeness. • Ensure SecOps agents and automated workflows executed correctly without technical issues, verifying that investigations ran smoothly and results are reliable. • Confirm the accuracy of incident verdicts by identifying false positives, incomplete investigations, or incorrect threat classifications. • Perform deeper analysis when required, including URL detonation or sandboxing, file analysis, and reviewing customer inventory and context to ensure findings are accurate and relevant. • Validate and apply Incident Management (IM) tags correctly, and approve, modify, or reject automated findings before escalation or response.
Senior Security Analyst
Stellus RxTrusted, pharmacist-led health support in every moment that matters.
• Use AI-enhanced SIEM, XDR, and threat intelligence platforms to continuously monitor security events across cloud and on-premises environments. • Analyze security alerts, logs, and threat data using AI-assisted tools to rapidly distinguish true positives from noise. • Proactively hunt for threats and anomalies using AI-informed behavioral analytics. • Lead and support security incident response activities; use AI tools to accelerate root cause analysis. • Conduct and support vulnerability assessments across cloud, application, and infrastructure environments; use AI tools to prioritize remediation efforts. • Support compliance activities across relevant frameworks (e.g., HIPAA, SOC 2, NIST); use AI tools to monitor for policy drift.
• Configure, troubleshoot, and maintain security infrastructure. • Respond to security alerts through investigation, documentation, and taking action as needed. • Provide audit support through evidence collection and implementing security controls. • Perform security assessments to support risk assessment and management activities. • Identify opportunities to improve security infrastructure and configurations. • Work cross-functionally with other teams on security initiatives.
Sr Analyst, Governance, Risk & Compliance (GRC), Information Security
Mondelēz InternationalWe’re a house of incredible brands providing people with the right snack, for the right moment, made the right way.
Job Description Are You Ready to Make It Happen at Mondelēz International? Join our Mission to Lead the Future of Snacking. Make It Uniquely Yours. As an individual contributor, the successful candidate will be proficient at managing risk assessments of both third parties and internal technologies. In addition, the candidate will be performing compliance activities related to technology assurance areas around access management, vulnerability management and configuration management. Candidate will also demonstrate ability and experience in governance related activities including administrative management of risk and control registers as well as policies and standards. How you will contribute Risk Management Responsibilities - Execute risk assessment testing supporting the Risk Manager. - Document risk assessment results. - Support Risk Manager in drafting risk assessment reports. - Perform administrative management of risk register (additions/editions/deletions, etc). - Document risk acceptance/exemptions that have been approved per the program. - Manage quarterly/annual review of risk acceptance/exceptions. - Manage risk assessment results in relevant dashboards. - Document Issues and Remediation activities for all exceptions noted during risk assessments. Compliance Responsibilities - Perform quarterly compliance assurance testing. - Document compliance testing results. - Maintain Management Action Plan (MAP) catalog with due dates. - Manage monthly audit MAPs. Includes the timely communication of open MAPs an escalation as needed of risks to completing MAPs at their agreed delivery dates. - Perform administrative activities in GRC Solution for compliance related activities. - Provide administrative support for ad-hoc external audits. - Provide administrative support for internal audits. - Support compliance program reporting activities. Requirements - 3 years in Information Security field, with at least 2 years working in GRC. - Experience with GRC tools (e.g., Archer). - Knowledge of security concepts and methodologies such as risk assessments, risk & controls, policies & standards, enterprise security strategies, network, and cloud security. - Knowledge of security frameworks such as CIS and NIST. - Excellent written and verbal communications skills, including presentational skills and able to clearly communicate issues to management and other key stakeholders. Business Unit Summary At Mondelēz International, our purpose is to empower people to snack right by offering the right snack, for the right moment, made the right way. That means delivering a broad range of delicious, high-quality snacks that nourish life's moments, made with sustainable ingredients and packaging that consumers can feel good about. We have a rich portfolio of strong brands globally and locally including many household names such as Oreo, belVita and LU biscuits; Cadbury Dairy Milk, Milka and Toblerone chocolate; Sour Patch Kids candy and Trident gum. We are proud to hold the top position globally in biscuits, chocolate and candy and the second top position in gum. Our 80,000 makers and bakers are located in more than 80 countries and we sell our products in over 150 countries around the world. Our people are energized for growth and critical to us living our purpose and values. We are a diverse community that can make things happen-and happen fast. Mondelēz International is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, gender, sexual orientation or preference, gender identity, national origin, disability status, protected veteran status, or any other characteristic protected by law. Job Type Regular Information Security Technology & Digital




