Apex Systems, an IT staffing and workforce solutions firm, provides recruiting and staffing services to large and small companies alike. Founded in 1995 by thre
IT Compliance & Security Risk Analyst
Location
North Carolina
Posted
68 days ago
Salary
$55 - $65 / hour
Seniority
Senior
Job Description
IT Compliance & Security Risk Analyst
Apex Systems
Title: IT Compliance & Security Risk Analyst Job Description: Job#: 3023139 Job Role: IT Compliance & Security Risk Analyst Location: Charlotte, North Carolina (Hybrid) Employment Type: Contract Contract Duration: 12 Months Role Overview This role is responsible for completing and tracking compliance deliverables to ensure applications adhere to applicable policies, standards, and local laws, rules, and regulations. The position involves supporting vendors, development teams, and technology managers to ensure technical security, risk, and other compliance activities are completed on-time and per requirements. The successful candidate will partner with control functions, risk management, and Global Information Security (GIS). Key Responsibilities - Complete administrative and non-technical tasks related to compliance deliverables, such as access reviews, assessments, and questionnaires. - Ensure risk, security, and other compliance deliverables are completed on time for supported applications. - Assist with audit exams and risk assessments for the applications. - Track and support technical security and risk activities performed by development teams, including remediation of vulnerabilities and disaster recovery exercises. - Maintain application data in designated systems of record. - Work with vendors for vendor applications to ensure they meet organizational requirements. - Facilitate team planning ceremonies against a backlog and manage risks, dependencies, and impediments for the team. - Contribute to artifacts needed for governance forums and keep stakeholders informed. Required Qualifications - Proficiency with Agile tools (Jira, Kanban) and understanding of agile methodology. - Strong skills in MS Office Suite (PowerPoint, Excel), including pivot tables and macros for data management and reporting. - Ability to connect multiple data sources to create meaningful analysis for KPI reporting. - Experience with ITIL processes and weekly report generation. - Knowledge of software development lifecycles and governance processes. - Excellent oral and written communication skills, with experience presenting to various levels of leadership. - Basic understanding of Information Security, Unix/Windows OS, and scripting (e.g., shell scripts). - Ability to work independently with minimal supervision. Preferred Qualifications - Certifications such as CISA, CISSP, CISM, ITILV2, or RHEL. - Familiarity with business resiliency, risk management principles, and technology change management. - Experience with Remedy/Nexus ticketing systems, patch deployment, CI/CD, and DevOps. - Background in InfoSec, including log analysis and audit/compliance. - Bachelor's degree. This employer is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against on the basis of disability. Apex uses a virtual recruiter as part of the application process. Click here for more details. If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation in using our website for a search or application, please contact our Benefits Department at [email protected]. Apex Systems is a world-class IT services company that serves thousands of clients across the globe. When you join Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRated's Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico. Apex uses a virtual recruiter as part of the application process. Click here for more details. Apex Benefits Overview: Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our 'Welcome Packet' as well, which an Apex team member can provide. Employee Type: Contract Location: Charlotte, NC, US Pay Range: $55 - $65 per hour
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
Information Security Analyst
Foxhole Technology, Inc.Foxhole Technology provides robust cybersecurity and IT support capabilities for federal civilian and defense agencies. A recognized leader in navigating technology and security challenges, Foxhole delivers mission-focused innovations to answer evolving and complex needs. Our talented employee-owners provide agile, scalable services and solutions that solve operational gaps, operate critical systems, and protect and secure the enterprise – across the organization and around the world.
Overview Title-Information Security Analyst (Journeyman) Location: Arlington, VA (Remote) Clearance: Secret Start: Upon Contract Award Foxhole Technology provides robust cybersecurity and IT support capabilities for federal civilian and defense agencies. A recognized leader in navigating technology and security challenges, Foxhole delivers mission-focused innovations to answer evolving and complex needs. Our talented employee-owners provide agile, scalable services and solutions that solve operational gaps, operate critical systems, and protect and secure the enterprise – across the organization and around the world. Foxhole is seeking a qualified Information Security Analyst. The ideal Information Security Analyst will have strong collaboration and communication skills to support our government customers. This position plays a critical role in supporting all facets of information assurance, system security, and compliance across the enterprise. Job Description - Maintain and execute the Information Security Plan - Categorize and assign security controls in Enterprise Mission Assurance Support Service (eMASS) - Create, update, and manage Assessment & Authorization (A&A) packages in eMASS - Coordinate and track inherited security controls within eMASS - Oversee Ports, Protocols, and Services Management (PPSM) - Support processes for achieving and maintaining Authority to Operate (ATO) and Conditional ATO (C-ATO) - Ensure compliance with Security Technical Implementation Guides (STIGs) and Information Assurance Vulnerability Alerts (IAVAs) - Respond to and manage cybersecurity incidents in coordination with both internal and external teams - Conduct vulnerability scanning and compliance reviews using Assured Compliance Assessment Solution (ACAS) - Oversee compliance activities related to Continuous Monitoring (ConMon) and Risk Management Framework (RMF) scoring - Develop and maintain system profiles, security plans, and artifacts within eMASS - Research, analyze, and stay up to date on the latest IT security trends and threats - Prepare detailed reports on security breaches, incident investigations, and overall system security performance Minimum Requirements - Active Secret Clearance - 3+ years of experience as an information security analyst, ISSO, or similar role - Knowledge and understanding of DoD and NIST RMF process - Experience in system accreditation, security assessments, and security engineering within the system development lifecycle - Demonstrated ability to develop security artifacts, POAMs, Security Plans, CONOPS, etc. - Ability to work on multiple documents under tight deadlines - Highly organized, proactive, and collaborative - Must have excellent interpersonal, verbal, and written communication skills - The ability to work independently to ensure tasks are complete Desired Experience/Certifications - Bachelor’s (BS) degree in relevant field – strongly preferred but not required - Certifications such as Security+, or CISSP, CISM, or similar cert is preferred - Familiarity with security tools and frameworks such as ACAS, Nessus, cloud-based scanning technologies, etc. - Experience supporting FedRAMP accreditations is a plus - Knowledge of computer network defense process and procedures More Information Requirements of position: Think analytically, effective verbal and written communication skills, make decisions, observe/remember details, interpret data, concentrate on tasks, adjust to change, handle stress/emotions. Regular attendance, maintain work schedule, attend meetings, meet deadlines, keyboard/type, handle confidential information, use math/calculations, stay organized, operate office equipment, may direct others. May be exposed to dust/dirt, humidity, and noise Foxhole Technology is an Equal Opportunity Employer and makes hiring decisions without regard to race, color, religion, sex (including pregnancy, childbirth and sexual orientation), national origin, age, disability, genetic information, military/veteran status, or any other protected class.
Senior Information Security Analyst
EDC (Education Development Center)EDC envisions a world where all people are empowered to lead healthy, productive lives.
• Own and improve the end-to-end security investigation lifecycle to strengthen detection accuracy and overall security posture. • Manage incident response, including triage, containment, and remediation. • Support the implementation of security practices for AI-enabled systems (e.g., OpenAI, CoPilot, AWS Bedrock, and CrewAI). • Partner with engineering teams to integrate security controls into CI/CD pipelines and provide guidance on secure development practices to support both security and delivery speed. • Build and enhance security automation using scripting, APIs, SOAR platforms, and cloud-native tools. • Support risk management activities, policies, assessments, and audits. • Stay current on emerging threats and evolving security technologies, including AI-driven attack and defense techniques.
Security Officer Flex Officer
Allied UniversalAllied Universal, founded in 2016 with the merger of AlliedBarton Security Services and Universal Services of America, is now a widely-recognized industry leader and North America�
Role Description Allied Universal® is hiring a Security Professional Flex Officer. The Security Professional Flex Officer will serve and safeguard clients in a range of industries such as Healthcare, Education, Finance and more. Join a leading team where flexibility meets opportunity. As a Security Professional Flex Officer, you’ll use our exclusive shift-pickup platform to view and claim open shifts based on your availability - giving you the freedom to build a schedule that works for you, while gaining valuable site experience across various industries. Whether you're looking to supplement your income or take the first step toward a phenomenal career, this position offers unmatched access to hands-on experience and growth opportunities. The Security Professional Flex Officer may be called upon to work irregular shifts at times with little to no advance notice. - Perform security patrols of designated areas on foot or in vehicle - Watch for irregular or unusual conditions that may create security concerns or safety hazards - Sound alarms or calls police or fire department in case of fire or presence of unauthorized persons - Warn violators of rule infractions, such as loitering, smoking, or carrying forbidden articles - Permit authorized persons to enter property and monitors entrances and exits - Observe departing personnel to protect against theft of company property and ensures that authorized removal of property is conducted within appropriate client requirements - Investigate and prepare reports on accidents, incidents, and suspicious activities; maintain written logs as required by the post - Aid customers, employees, and visitors in a courteous and professional manner - Make emergency notifications as necessary pursuant to site Post Orders Qualifications - Must possess a high school diploma or equivalent or 5 years of verifiable experience - Licensing requirements are subject to state and/or local laws and regulations and may be required prior to employment - Valid driver’s license if driving a company or customer-owned vehicle - As a condition of employment, applicants will be subject to a background investigation in accordance with all federal, state, and local laws; Allied Universal will consider qualified applications with criminal histories in a manner consistent with applicable laws - As a condition of employment, applicants will be subject to a drug screen to the extent permitted by law - No prior experience required - Be at least 18 years of age, or higher if required by the state (21 years, if armed) - Reliability and ability to adapt to different post assignments - Be able to operate radio or telephone equipment and/or console monitors - Demonstrated ability to interact cordially and communicate with the public - Effective oral and written communication skills; able to write informatively, clearly, and accurately - Active listening and problem-solving skills - Assess and evaluate situations effectively; identify critical issues quickly and accurately - Mediate conflict with tact, diplomacy - Teamwork - Attention to detail Requirements - Ability to speak, read, and write in multiple languages (e.g., Spanish, Portuguese, French, Arabic) - Prior security, military, or law enforcement experience Benefits - Health insurance and 401k plans for full-time positions - Schedules that fit with your personal life goals - Ongoing paid training programs and career growth opportunities - Employee discounts through our perks program to your favorite restaurants, entertainment venues and much more…
Sr Cybersecurity Analyst
Southwest AirlinesSouthwest Airlines flew its first commercial passenger flights in the spring of 1971. The company has since become an industry leader in affordable air travel a
Department: Technology Our Company Promise We are committed to provide our Employees a stable work environment with equal opportunity for learning and personal growth. Creativity and innovation are encouraged for improving the effectiveness of Southwest Airlines. Above all, Employees will be provided the same concern, respect, and caring attitude within the organization that they are expected to share externally with every Southwest Customer. Job Description: All of Southwest’s People come together to deliver on our Purpose; Connecting People to what’s important in their lives through friendly, reliable, and low-cost air travel. The Senior Cybersecurity Analyst delivers on our Purpose by joining the Incident Response Team, providing advanced technical expertise and leadership in cybersecurity, contributing to the identification and resolution of complex cybersecurity issues across various domains such as incident response, threat intelligence, governance, risk, and compliance (GRC), privacy, vulnerability management, and engineering operations. This role guides the development and enforcement of security policies, standards, and procedures while fostering a security-aware Culture among the Team and stakeholders. The Senior Cybersecurity Analyst enjoys being hands-on with many parts of the business and looks forward to keeping Southwest cyber safe. Additional Details: - This role is offered as a remote workplace position, which may require travel for trainings, meetings, conferences, etc. Outside of those required visits, the majority of your working time may be spent in an approved remote location, away from our Corporate Campus. Please note, while this is a remote position, there is limited group of states or localities ineligible for Employees to regularly perform their work off-site. Those ineligible locations are: Alaska, Delaware, New Jersey, North Dakota, South Dakota, Vermont, West Virginia, and Wyoming, and Puerto Rico. - U.S. citizenship or current authorization to work in the U.S. required and no current or future work authorization sponsorship available. We’re committed to fair hiring practices and to making employment decisions without regard to race, color, religion, sex, sexual orientation, gender identity, gender expression, national origin, age, military or veteran status, disability, genetic information, or other legally protected characteristics. Responsibilities - Provide advanced technical expertise and leadership in cybersecurity, contributing to the identification and resolution of complex cybersecurity issues across various domains such as Incident Response, Threat Intelligence, Governance, Risk, and Compliance (GRC), Privacy, Vulnerability Management, and Engineering Operations - Lead and coordinate complex incident response efforts, overseeing the identification, containment, and resolution of sophisticated security incidents, and providing mentorship to junior and mid-level analysts - Champion advanced threat intelligence initiatives, including the development of threat hunting strategies, proactive identification of emerging threats, and the implementation of innovative solutions to enhance the organization's security posture - Take ownership of the organization's vulnerability management program, developing and implementing advanced strategies for identifying, prioritizing, and mitigating vulnerabilities, and providing expert guidance to analysts at all levels - Architect and lead the optimization of the organization's security infrastructure, ensuring the implementation of cutting-edge cybersecurity controls and practices, and providing strategic direction for the organization's evolving security architecture - Drive the maturity of GRC initiatives, providing expert guidance on compliance matters, shaping policies and procedures, and ensuring a proactive and comprehensive approach to governance, risk, and compliance - Serve as the primary authority on privacy matters, overseeing the organization's privacy program, and ensuring the effective implementation and continuous improvement of privacy controls in line with evolving regulations - Lead advanced research and development efforts in cybersecurity, staying at the forefront of emerging technologies, and driving innovation in security practices to stay ahead of evolving cyber threats - Mentor and coach junior and mid-level cybersecurity analysts, providing guidance on complex technical and strategic challenges, and contributing to the professional development of the cybersecurity team - Foster strong collaboration across the organization, engaging with senior leadership, cross-functional teams, and external stakeholders, and representing the cybersecurity function at a strategic level - May perform other job duties as directed by Employee's Leaders Knowledge, Skills and Abilities - Knowledge of advanced cybersecurity concepts, including threat intelligence, penetration testing, and advanced attack techniques - Skilled in cybersecurity regulations and standards, such as GDPR, HIPAA, and industry-specific compliance requirements - Skilled in advanced threat detection methods and tools, as well as the ability to analyze and respond to complex threats - Skilled in guiding incident response efforts, including managing complex incident investigations and coordinating teams - Skilled in conducting in-depth vulnerability assessments and penetration testing to identify and address security weaknesses - Ability to provide strategic insights into emerging threats, technologies, and best practices and shape the organization's cybersecurity strategy - Ability to lead risk management efforts and develop effective strategies for identifying, assessing, and mitigating cybersecurity risks - Skilled in effective collaboration and communication to work effectively with cross-functional teams, stakeholders, and external partners - Ability to develop and enforce security policies, standards, and procedures, ensuring compliance and comprehensive security controls - Ability to foster a security-aware culture within the organization, promoting cybersecurity awareness and knowledge-sharing among team members and stakeholders Education - Required: High School Diploma or GED - Required: Bachelor's degree in Computer Science, Engineering, Information systems or similar fields of study or equivalent advanced level experience Experience - Required: Advanced-level experience, seasoned and specialized knowledge in cybersecurity principles and concepts, developing skills and knowledge in information technology (IT) operations, programming, systems/software development or another IT related field - Preferred: Experience in Cloud (AWS), EDR (such as CrowdStrike), SIEM - Preferred: Experience in performing log analysis and Digital Forensics - Preferred: Advanced knowledge of global privacy regulations (e.g., GDPR, CCPA/CPRA, LGPD, HIPAA), including experience interpreting regulatory requirements and applying them to data privacy incident response processes - Preferred: Proven experience leading complex data privacy incidents from detection through resolution, including familiarity with forensic analysis, containment strategies, and root cause investigations - Preferred: Strong understanding of data governance and lifecycle management, including data classification, retention policies, and secure disposal practices - Preferred: Demonstrated executive presence and communication skills, with the proven ability to deliver executive briefings and present complex technical and regulatory incident information to technical and non-technical audiences, including executive and senior leadership - Preferred: Ability to manage multiple concurrent incidents with varying priorities, exercising strong organizational skills and delegating effectively when appropriate - Preferred: Ability to operate effectively in high-pressure situations, communicate clearly with internal and external stakeholders, and contribute to or draft public statements or regulatory disclosures - Preferred: Deep understanding of global privacy laws and frameworks (e.g., GDPR, CCPA, LGPD, HIPAA). Licensing/Certification - N/A Physical Abilities - Ability to perform work duties from [limited space work station/desk/office area] for extended periods of time - Ability to communicate and interact with others in the English language to meet the demands of the job - Ability to use a computer and other office productivity tools with sufficient speed and accuracy to meet the demands of the job Other Qualifications - Must maintain a well-groomed appearance per Company appearance standards as described in established guidelines - Must be a U.S. citizen or have authorization to work in the United States as defined by the Immigration Reform Act of 1986 - Must be at least 18 years of age - Must be able to comply with Company attendance standards as described in established guidelines - Must be able to travel and /or attend Company and non-Company facilities and remote locations such as remote-based offices as necessary Pay & Benefits: Competitive market salary from $122,200 per year to $135,800 per year* depending on qualifications and experience. For eligible Leadership and individual contributor roles, additional bonus opportunities are available and awarded at the discretion of the company. Benefits you’ll love: - Fly for free, as a privilege, on any open seat on all Southwest flights (your eligible dependents too) - Southwest will help fund your Retirement Savings Plan with Company contributions up to 9.3% of your eligible earnings** - Potential for annual ProfitSharing contribution in the Southwest Retirement Savings Plan- when Southwest profits, you profit*** - Competitive health insurance for you and your eligible dependents (including pets) - Southwest offers health plan coverage options that start from the very first day of employment. You will have 30 days to select and enroll in your health plan with coverage retroactively available to your first day of employment. - Explore more Benefits you’ll love: https://careers.southwestair.com/benefits *Pay amount does not guarantee employment for any particular period of time. **401(k) match contributions are subject to Retirement Savings Plan vesting schedule and applicable IRS limits ***ProfitSharing contributions are subject to Retirement Savings Plan vesting schedule and are made at the discretion of the Company. Southwest Airlines is an Equal Opportunity Employer. Please print/save this job description because it won't be available after you apply.


