Information Security Analyst
Job Description
With over 120 offices and nearly 7,000 associates throughout the U.S. CBIZ (NYSE : CBZ) delivers top-level financial and employee business services to organizations of all sizes, as well as individual clients, by providing national-caliber expertise combined with highly personalized service delivered at the local level.
CBIZ has been honored to be the recipient of several national recognitions :
- 2022 Best and Brightest Companies to Work for in the Nation
- 2023 Top Workplaces USA
- 2022 America's Best Mid-Size Employers
- 2022 Best and Brightest Companies in Wellness
- 2022 Great Place to Work Certification
CBIZ Corporate is a division of CBIZ, Inc., providing internal support in the areas of finance, human resources, payroll, benefits, IT, legal, and marketing.
CBIZ is ranked as a Top 20 Largest Broker of U.S. Business (Business Insurance Magazine) and a Top 100 Retirement Plan Adviser (PLANADVISER).
Job Purpose / Objective
The Information Security Analyst will support the protection of our information assets from intentional or unintentional disclosure, modification, destruction, or denial of access through the implementation of appropriate information security policies, standards, guidelines, and procedures.
The Analyst's primary role is to support our vulnerability and risk management programs and facilitate incident response procedures in a timely and accurate fashion.
The Information Analyst will conduct network and application vulnerability assessments for the organization, participate in penetration testing and detection activities, and perform security incident response procedures utilizing internal and external resources.
The analyst will assist with the implementation and enhancement of information security measures to safeguard our systems and information assets.
Essential Functions & Primary Duties
- Perform audits, risk assessments, and vulnerability testing (internal, external, application, database, and firewall) to identify potential threats with appropriate remediation strategies.
- Identifies, investigates, and responds to potential threats, reported security violations / incidents.
- Conducts security audits, recommends, and implements corrective actions.
- Support the Vulnerability Management program to identify, communicate, and track vulnerabilities and patches for critical systems and devices.
- Support and manage threat detection solutions and processes including new deployments, maintenance, monitoring and investigation, and Security Operations Center team support.
- Support and assist with security endpoint and email solutions, system information and event management (SIEM), password vault, and network firewalls as needed with the focus on minimizing threats and exposure risks to CBIZ.
- Recommend, pilot, and deploy additional security products and tools, or enhancements to existing tools, to detect violations of network security measures and malicious activities.
- Develop and implement, as required, the necessary monitoring and detection solutions to audit and enforce company policies, controls, and standards.
- Conduct research on emerging threats and mitigating security products, services, and standards to protect our systems, networks, and data.
- Assist with the development of security policy, awareness materials, presentations, and training sessions to ensure employee awareness of appropriate information security policies and controls.
Preferred Qualifications
- CISSP, CISA, or equivalent certifications.
- Experience with network and application vulnerability management and assessment solutions.
- Knowledge of information security frameworks and standards including the NIST Cyber Security Framework and ISO 27002 Information Security Control standards.
- Experience with threat detection solutions and incident and breach response activities.
- Understanding of data protection requirements relating to personally identifiable information and protected health information.
- Knowledge of information security and computer network, application, and user access technologies including email security and encryption, multi-factor authentication, end-point security, anti-virus / anti-malware, and security log management.
Required Qualifications
- College Degree or equivalent preferred
- 4 years related experience
- Proficient knowledge of applicable infrastructure technologies
- Ability to execute and draft technical instructions and guidelines
- Ability to document daily control activities and system functions
- Ability to work independently and with cross-functional teams.
- Demonstrated ability to communicate verbally and in writing
- Ability to travel as required by business and on-call availability
REASONABLE ACCOMMODATION
If you are a qualified individual with a disabilityyou may request reasonable accommodation if you are unable or limited in your ability to use or access this site as a result of your disability.
You can request a reasonable accommodation by calling 844-558-1414 (toll free)or send an email to [email protected]
EQUAL OPPORTUNITY EMPLOYER
CBIZ is an affirmative action-equal opportunity employer and reviews applications for employment without regard to the applicant's race, color, religion, national origin, ancestry, age, gender, gender identity, marital status, military status, veteran status, sexual orientation, disability, or medical condition or any other reason prohibited by law.
If you would like more information about your EEO rights as an applicant under the law, please visit these following pages EEO is the Law and EEO is the Law Supplement.
PAY TRANSPARENCY PROTECTION NOTIFICATION
Related Jobs
Information Security Analyst
Security Guard - Security Agent - Security Officer
Security Officer
Evening Security