Information Security Specialist
CurrentAs an Information Security Specialist at Stowers, I ensure the security and integrity of our systems and data. My role involves monitoring, analyzing, and detecting threats, as well as implementing effective countermeasures.Key Responsibilities: • Strategy & Planning: Develop and enforce security policies, guidelines, and procedures. Ensure compliance with GDPR, HIPAA, PCI DSS, and other regulations. • Acquisition & Deployment: Stay updated on IT security trends, recommend… Show more As an Information Security Specialist at Stowers, I ensure the security and integrity of our systems and data. My role involves monitoring, analyzing, and detecting threats, as well as implementing effective countermeasures.Key Responsibilities: • Strategy & Planning: Develop and enforce security policies, guidelines, and procedures. Ensure compliance with GDPR, HIPAA, PCI DSS, and other regulations. • Acquisition & Deployment: Stay updated on IT security trends, recommend and integrate new security solutions, and evaluate cloud vendors for compliance. • Operational Management: Maintain secure configurations for IT devices, monitor security solutions, and conduct regular vulnerability assessments. • Security Implementation: Conduct physical site analysis and recommend security solutions like cameras and alarms. • Endpoint Security Management: Manage antivirus, endpoint detection, and mobile device management solutions. Monitor and configure security controls to prevent malware, ransomware, and data breaches. • User Access Management: Implement and manage user access controls based on least privilege. Expand single-sign-on and multi-factor authentication. • Incident Response and Support: Provide timely response and support for security incidents. Lead investigations and implement countermeasures. • Secure Communication and Collaboration: Implement and manage secure communication tools. • Security Monitoring and Reporting: Monitor devices for security events, analyze logs for potential incidents, and prepare security reports. • Backup and Recovery Management: Implement and manage backup and recovery solutions, ensuring data is securely stored and regularly tested. • Collaboration and Training: Collaborate with IT support teams, provide training and support, and develop cybersecurity awareness programs. • Compliance & Risk Assessment: Conduct risk assessments, ensure compliance with security regulations, and monitor adherence to NIST standards. Show less