Information Security Risk Analyst Ii
CurrentCyber Security Risk Assessments • Work with business units and third parties to evaluate the risk of vendor relationships.• Perform application security assessment on both internal and external applications.• Translate cyber risk into business risks and communicate this to business units.• Identify information system vulnerabilities through automatic and manual means.• Prioritize gaps based on the risk to SCI information systems and data.• Document identified risks and follow up on remediation activities to ensure risks are mitigated.• Assist in preparation of metrics and reporting for Cybersecurity management activities.• Stay abreast of new developments via forums and cyber groups. Compliance • Complete required testing and compliance controls within the scoped timeframe.• Work with other departments within IT to obtain the required evidence for Compliance controls.• Perform analysis on control evidence to ensure all controls have been performed according to the requirements and meet the control objective.• Work with both internal and external auditors to provide evidence of compliance.Security Awareness • Develops security awareness communications and updates internal websites.• Coordinates with internal teams to assign courses and train targeted groups.• Assists with the execution of Security Simulation User training (Phishing)