Information Security Analyst
Current• Responsible for assisting the administration of RLI’s vulnerability management program, maintaining Sarbanes-Oxley and PCI DSS compliance programs. • Assist in a variety of projects for recommending, designing, implementing, and administering pragmatic information security controls that meet dynamic, tactical, and strategic information security objectives.• Identify security issues and risks associated with security events and manage the incident response process.• Perform network and system forensics in response to security incidents.• Develop and implement remediation plans based on identified security events.• Conduct risk assessments, penetration tests, and diagnose internet/extranet security, intrusion attempts, and cyber-crime response.• Perform project tasks on select security projects including development of requirements, evaluation of competing products, selection and implementation of products.• Assist in developing responses to internal & external audits, penetration tests and vulnerability assessments.• Recommends and coordinates the application of fixes, patches, & recovery procedures in the event of a security breach.