Soluções que valorizam e impulsionam seu negócio
Data and Information Security Analyst – Junior
Location
Brazil
Posted
5 days ago
Salary
0
Seniority
Junior
Job Description
Data and Information Security Analyst – Junior
Solo Network
• Act as a Data and Information Security Analyst with a technical and consultative focus on protecting sensitive data and information. • Responsible for implementing and maintaining classification, labeling and protection policies, as well as Data Loss Prevention (DLP) technologies and regulatory compliance, ensuring the secure lifecycle of information. • Work with Microsoft Information Protection, Microsoft Purview and Data Loss Prevention (DLP) to identify, classify and protect sensitive data across data infrastructures, endpoints, e-mail, SharePoint, Teams, OneDrive, etc. • Configure DLP policies based on financial, contractual and regulatory information (LGPD, SOX, PCI-DSS). • Continuously improve DLP policies based on events, false positives and exception cases. • Monitor DLP alerts, perform analysis and collaborate with incident response teams. • Support investigations conducted by other teams by providing technical input and context on DLP policies, classification rules and potential leakage vectors. • Work together with Data Stewards. • Conduct mapping, categorization and classification of critical/sensitive data. • Define and maintain OKRs and maturity indicators related to technical data governance and leakage prevention activities. • Demonstrate results through dashboards, executive reports and technical evidence. • Ensure compliance with standards and legislation such as LGPD, GDPR, SOX, HIPAA, PCI-DSS, ISO 27001:2022 and NIST. • Support internal/external audits with compliance evidence related to DLP, classification and governance. • Conduct trainings, workshops and awareness campaigns on secure use and classification of information.
Job Requirements
- Minimum 1 year of experience in Information Security, DLP, data classification or data governance.
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
Junior Data and Information Security Analyst
Solo NetworkSoluções que valorizam e impulsionam seu negócio
• Work with Microsoft Information Protection, Microsoft Purview and Data Loss Prevention (DLP) to identify, classify, and protect sensitive data across data infrastructures, devices, email, SharePoint, Teams and OneDrive. • Continuously improve DLP policies based on events, false positives and exception cases. • Monitor DLP alerts, perform analyses and collaborate with incident response teams. • Support investigations conducted by other teams by providing technical inputs and contextual information about DLP policies. • Work together with Data Stewards who act as focal points to ensure data quality, appropriate use, security and correct data classification. • Conduct mapping, categorization and classification of critical/sensitive data, aligning with the owners of each data domain (e.g., finance, legal, HR). • Define and maintain OKRs and maturity indicators related to technical data governance and data leakage prevention activities. • Ensure compliance with regulations and legislation such as LGPD, GDPR, SOX, HIPAA and PCI-DSS.
• Assist the Vulnerability Operations team with the review and acceptance of Missions, Patch Verifications, and vulnerability reports • Bypass customer patch attempts, create suspected vulnerability reports, and exploit real world vulnerabilities • Work remotely with seasoned Computer Security Analysts • Learn what it's like to review complex vulnerability reports
Role Description The Senior Security Analyst (Healthcare) is responsible for protecting the organization’s information systems, data, and technology assets with a primary focus on safeguarding Protected Health Information (PHI) and ensuring compliance with healthcare regulatory requirements. This role plays a critical part in designing, implementing, monitoring, and improving the organization’s cybersecurity posture in alignment with HIPAA, HITECH, and other applicable standards. This position serves as a senior technical and operational resource within the security function, leading security monitoring, incident response, risk assessments, vulnerability management, and compliance initiatives. The Senior Security Analyst works closely with IT, infrastructure, application teams, compliance, and external partners to identify risks, respond to threats, and maintain a strong security posture across a multi-site healthcare environment. Everything we do connects back to real people navigating complex healthcare journeys - and this role helps make that journey brighter. What You’ll Do - Security Operations and Monitoring - Monitor and analyze security events and alerts across networks, endpoints, cloud platforms, and applications. - Investigate suspicious activity and lead incident response efforts, including triage, containment, eradication, and recovery. - Serve as an escalation point for complex security incidents and coordinate cross-functional response efforts. - Maintain and tune SIEM, EDR, and other security tools to improve detection and reduce false positives. - Conduct root cause analysis and document incidents, actions taken, and lessons learned. - Healthcare Security and Compliance - Ensure compliance with HIPAA, HITECH, and other healthcare regulatory and privacy requirements. - Participate in security risk assessments, gap analyses, and audits (internal and external), including support for third-party assessments. - Develop and maintain security policies, standards, and procedures aligned with regulatory expectations. - Monitor controls related to PHI protection, data access, and breach prevention. - Support audit readiness and remediation activities for compliance findings. - Vulnerability and Risk Management - Conduct regular vulnerability scans and coordinate remediation efforts across infrastructure and application teams. - Prioritize risks based on business impact, exploitability, and regulatory exposure. - Track and report on vulnerability remediation status and risk reduction efforts. - Perform risk assessments on new systems, vendors, and technology implementations. - Contribute to third-party risk management and vendor security reviews. - Security Engineering and Architecture Support - Collaborate with infrastructure and application teams to implement secure configurations and controls. - Evaluate and recommend security solutions, tools, and technologies to enhance protection capabilities. - Support secure design reviews for new applications, systems, and integrations. - Validate implementation of security controls across networks, endpoints, and cloud environments. - Identity and Access Management (IAM) - Review and monitor user access to systems containing PHI and sensitive data. - Support access governance processes, including provisioning, deprovisioning, and periodic access reviews. - Investigate access anomalies and enforce least-privilege principles. - Training, Awareness, and Continuous Improvement - Support security awareness and training initiatives with a focus on healthcare threats (e.g., phishing, ransomware). - Provide guidance to IT and business teams on security best practices and risk mitigation. - Identify opportunities to improve security processes, tooling, and response capabilities. - Mentor junior analysts and contribute to the development of the security team. Qualifications - Bachelor’s degree in Cybersecurity, Information Technology, or a related field preferred; equivalent experience considered. - 5+ years of experience in cybersecurity, information security, or related roles. - 2+ years of experience in healthcare IT, security, or regulated environments required. - Demonstrated experience with incident response, threat detection, and vulnerability management. - Experience supporting audits and compliance frameworks in regulated industries. Requirements - Strong understanding of: - Security operations (SIEM, EDR, log analysis) - Network security (firewalls, IDS/IPS, segmentation) - Endpoint security and device hardening - Cloud security principles (Azure, AWS, or similar) - Vulnerability scanning and remediation tools - Familiarity with: - HIPAA Security Rule and Privacy Rule - NIST Cybersecurity Framework (CSF) and/or NIST 800-53 - HITRUST CSF (preferred in healthcare environments) - Knowledge of identity and access management practices. - Understanding of secure system and application design principles. Benefits - Purpose-driven work with real impact - A patient-first, clinician-led culture - Supportive, collaborative teammates - The opportunity to grow with a company building something meaningful Pay Range/Rate $110,000 — $120,000 USD
Cyber Security Analyst, Senior
ICFWe are not a typical consulting firm and our people are not typical consultants.
Title: Cyber Security Analyst, Senior (High Level Clearance Required) Location: Pensacola United States Job Description: time type Full time job requisition id R2602422 ICF seeks an experienced Senior Cyber Security Analyst to support the research and development of new cyber analytic capabilities that will help the US protect and defend its networks and critical information systems. The successful cleared candidate will act as a Senior Cyber Security Analyst to support a large federal cyber security analytic program. Your work will contribute to the knowledge of how cyber-attacks work, how vulnerabilities are exploited, and the way hostile cyber actors operate. Utilize your skills to help experiment and prototype future cyber capabilities for implementation at large-scale. As the Senior Cyber Security Analyst, you will work with our customers, developers, and researchers to evolve, automate, and enhance cybersecurity capabilities in defense or federal agencies. This is an opportunity to contribute to an important project from its beginning, work with the latest and emerging technologies, and all while building a great career at ICF! This role has a hybrid work schedule with the expectation of a minimum of two days/week supporting the program based in Pensacola, FL and the remainder of the week teleworking. What You Will Be Doing: - Augment operational cyber analysts and act as a consultant for detection and/or threat hunting - Advise on data preparation, implementation of techniques, visualizations, and employment of analytics developed by ICF and customer partners - Assess current use of cyber tools by analysts and assess whether efficiencies can be made via alternate use of current, or adoption of alternate tools - Problem-solve by identifying potential tools/processes to support needs, capturing areas of improvement that can be translated into functional requirements for future planning - Provide ad-hoc training to cyber analyst teams on tools that support or enhance current processes - Identify areas of technical training gaps and proposed approaches to methods (hands on, online modules, etc.) to improve the use of tools and data in support of the cybersecurity mission. - Participate in post-engagement review - Effectively communicate with leadership to ensure awareness of progress, challenges What You Must Have: - Bachelor’s degree with 12+ or Master’s degree with 10+ years of experience in IT, Cyber, or related field - Position requires a minimum of 5 years of Cyber Security experience (e.g., Threat Hunt, Incident Response, Investigations, Technical Reporting, etc.) - 5 years of experience using network security analysis/IDS tools - 5 or more years of experience analyzing packet capture and NetFlow data with an understanding of current cyber threats and trend derived from multiple sources (e.g., open-source, intelligence products, etc.) - 5 or more years of experience with different types of Malware including detection methods, attack vectors, and vulnerabilities used - Experience with query languages (e.g., SQL, KQL, etc.) - Experience developing advanced dashboards (e.g., Kibana, Splunk, etc.) - Experience with different cybersecurity frameworks and knowledge bases to identify tactics, techniques, and procedures of known actors - 5 or more years of Leadership experience - Active high-level security clearance required as part of client contract requirement - Due to the nature of the work and contract requirements, US citizenship is required Preferred Qualifications: - Interpersonal skills and the ability to communicate effectively with various clients in order to explain and elaborate on technical details - Practical experience with different scripting languages (e.g., Python, JavaScript, etc.) - Practical experience with the Databricks Intelligence Platform - Experience with system vulnerability assessments - Knowledge of Linux/Unix and Windows operating systems security - Knowledge of computer programming and scripting languages - Excellent written and verbal communication skills - Scaled Agile Framework (SAFe) experience - CompTIA Security+ or higher certification level preferred Working at ICF ICF is a global advisory and technology services provider, but we’re not your typical consultants. We combine unmatched expertise with cutting-edge technology to help clients solve their most complex challenges, navigate change, and shape the future. We can only solve the world's toughest challenges by building a workplace that allows everyone to thrive. We are an equal opportunity employer. Together, our employees are empowered to share their expertise and collaborate with others to achieve personal and professional goals. For more information, please read our EEO policy. We will consider for employment qualified applicants with arrest and conviction records. Reasonable Accommodations are available, including, but not limited to, for disabled veterans, individuals with disabilities, and individuals with sincerely held religious beliefs, in all phases of the application and employment process. To request an accommodation, please email and we will be happy to assist. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations. Read more about workplace discrimination rights or our benefit offerings which are included in the Transparency in (Benefits) Coverage Act. Candidate AI Usage Policy At ICF, we are committed to ensuring a fair interview process for all candidates based on their own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) tools to generate or assist with responses during interviews (whether in-person or virtual) is not permitted. This policy is in place to maintain the integrity and authenticity of the interview process. However, we understand that some candidates may require accommodation that involves the use of AI. If such an accommodation is needed, candidates are instructed to contact us in advance. We are dedicated to providing the necessary support to ensure that all candidates have an equal opportunity to succeed. Pay Range - There are multiple factors that are considered in determining final pay for a position, including, but not limited to, relevant work experience, skills, certifications and competencies that align to the specified role, geographic location, education and certifications as well as contract provisions regarding labor categories that are specific to the position. The pay range for this position based on full-time employment is: $98,145.00 - $166,846.00


