Job Closed

This listing is no longer active.

CivicPlus logo
CivicPlus

Powering and Empowering Government

Information Security Risk Analyst

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 501-1,000Since 2001H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

68 days ago

Salary

$80.2K - $117.1K / year

Seniority

Senior

Bachelor Degree4 yrs expEnglishCyber Security

Job Description

Information Security Risk Analyst

CivicPlus

• Identify and translate inherent and residual risk through likelihood, impact, treatment plans, and ownership. • Define and track risk and awareness key metrics to measure program effectiveness and communicate to leadership and governance committees. • Conduct and manage enterprise information security risk assessment through recognized frameworks (including NIST 800-30) and maintain an information security risk register. • Lead third-party security risk assessments for vendors, partners, and service providers through analysis of assurance documentation, security testing summaries, and security questionnaires. • Maintain the information security risk register and third-party vendor risk inventory to track and monitor ongoing risks and approved exceptions. • Develop and lead enterprise security awareness training, including phishing simulations and targeted role-based training for security education and reporting. • Support internal and external security and compliance assessments through risk evidence and documentation. • Partner closely with organizational functions and key stakeholders to understand and address organizational risks across systems and processes, and ensure security risks are understood, prioritized, and treated in alignment with organizational risk appetite.

Job Requirements

  • 4 – 6 Years of experience in information security, cybersecurity, risk management, or related field
  • Working experience managing enterprise/third-party risk assessments, risk registers, and security training programs.
  • Working experience supporting compliance audits and certifications, including NIST 800-53 (FedRAMP/GovRAMP), ISO 27001, PCI, and/or SOC 2
  • Certifications Security+, GSEC, or equivalent
  • Bachelor’s degree in Cybersecurity, Information Security, Information Systems, Risk Management, or a related field (preferred)

Benefits

  • Comprehensive health insurance
  • Dental insurance
  • Vision insurance
  • Flexible Time Off
  • 401(k) plan
  • and more.

Related Categories

Related Job Pages

More Security Engineer Jobs

Sprinto logo

Senior Manager, Information Security

Sprinto

Sprinto helps SaaS companies become info-sec compliant, unblock sales deals, and pass security reviews easily

Full TimeRemoteTeam 51-200Since 2020H1B No Sponsor

• Own end-to-end compliance strategy and build a comprehensive compliance roadmap aligned with business objectives • Conduct risk assessments and identify compliance risks specific to SaaS business models; develop mitigation strategies • Establish and maintain compliance processes, procedures, and documentation; ensure adherence to regulatory frameworks • Build compliance programs from ground up and coordinate compliance audits and assessments • Work closely with legal, engineering, product, and business teams to provide compliance guidance • Manage relationships with external compliance consultants and auditors • Lead compliance training initiatives across the organization • Provide insights and opinions on compliance risks and opportunities in the SaaS industry

India
Insider One logo

Information Security Specialist

Insider One

The #1 platform that brings everything marketing and customer engagement teams need in one place, to become unstoppable.

Full TimeRemoteTeam 1,001-5,000Since 2012H1B No Sponsor

• We are looking for a highly motivated and detail-oriented Information Security Specialist to join our growing security team. The ideal candidate will be responsible for ensuring the organization’s compliance with security standards such as ISO 27001 and SOC 2 Type 2, managing business continuity processes, and supporting security governance on AWS environments. This role requires a proactive mindset, strong technical knowledge, and a good understanding of both internal IT systems and regulatory frameworks like KVKK and GDPR. • Drive the implementation and continuous improvement of the ISO 27001 Information Security Management System (ISMS) • Conduct and document internal audits and follow up with action plans • Coordinate and enhance business continuity and disaster recovery processes • Support SOC 2 Type 2 compliance efforts and evidence collection • Provide governance support for AWS infrastructure and cloud security configurations • Collaborate with internal Red Team and Blue Team to follow up on technical findings • Maintain, update, and implement security policies, standards, and procedures • Plan and execute security awareness programs (training, campaigns, gamification, etc.) • Assess third-party security through security assurance reviews • Support security incident handling and security reporting processes • Provide input on privacy regulations (KVKK, GDPR) and ensure alignment with global policies • Act as a security consultant to business units and IT teams

Turkey
Insider One logo

Senior Security Engineer – Blue Team

Insider One

The #1 platform that brings everything marketing and customer engagement teams need in one place, to become unstoppable.

Full TimeRemoteTeam 1,001-5,000Since 2012H1B No Sponsor

• Management and Maintenance of SIEM Tools: Configuring, monitoring, and enhancing SIEM functionalities. • Rule Creation and Optimization: Developing rules, reports, dashboards, and use cases to detect threats and attacks. • Threat Analysis: Analyzing threats using logs, IPS/IDS, cyber intelligence reports, and other data sources. • MITRE ATT&CK Framework Integration: Reviewing existing rules and developing new attack detection scenarios. • Incident Response: Taking an active role in detecting, analyzing, and mitigating security incidents. • False Positive Reduction: Working with CDC Engineers to optimize detection logic and minimize false positives. • Log Management: Importing and troubleshooting logs from various security products and company-wide log sources. • Security Metrics & Reporting: Defining and monitoring key security metrics, creating dashboards and reports. • Database and EDR Tool Management: Maintaining, optimizing, and enhancing security configurations. • Cyber Intelligence & Threat Hunting: Staying updated with the latest cyber threats and integrating threat intelligence into security operations.

Turkey
Insider One logo

Senior Security Engineer – Red Team

Insider One

The #1 platform that brings everything marketing and customer engagement teams need in one place, to become unstoppable.

Full TimeRemoteTeam 1,001-5,000Since 2012H1B No Sponsor

• performs web, mobile application, and internal penetration tests, source code reviews, threat analysis, social-engineering assessments, • supports blue teams when needed, • researches new attack vectors and stays current with cybersecurity news and trends, • trains Quality Assurance and Development teams in standard security testing techniques and secure software development.

Turkey