Information security
Job Description
The Information Security Analyst position within the IS&T group is accountable for protecting system applications data and IT assets from a variety of threats that cause a data breach, data destruction or prolonged downtime.
Provide technical expertise of information security applications, software and hardware which deliver defense in depth protection of information technology resources and confidential data across various systems.
Engage in projects, requirements analysis, security solutions research, and implementation of security technologies. Security incident response including, detection, containment, recovery, forensics and reporting to limit data disruptions.
The Information Security Analyst will be responsible for the documentation, support and maintenance of Cyber security tools, policies, and audits.
This position will work closely with the IS&T Infrastructure and Cloud teams ensuring that they follow and fulfill Cyber security best practices and remediate vulnerabilities in their respective roles.
- Provide technical expertise of information security applications, software and hardware which deliver defense in depth protection of information technology resources and confidential data across various systems
- Engage in projects, requirements analysis, security solutions research, and implementation of security technologies
- Security incident response including, detection, containment, recovery, forensics and reporting
- Assemble data from different sources for analysis
- Maintains inventories and inventory processes of information resources protected by security regulations so vulnerability assessments can be performed
- Uses tools and processes to effectively carry out vulnerability testing
- Interprets scanning or testing results and provides consultation to Infrastructure, Cloud, IS&T L1 Service Desk and other teams regarding system and application weaknesses
- Appropriately escalates issues presenting unacceptable risk to our locations
- Monitors risk mitigation progress
- Ensures that equipment and its connectivity complies with the Veolia Group security policies and procedures.
- Assists in materializing security architecture into projects
- Develops, maintains and applies tools, processes and procedures to evaluate suitability of security configuration and feature offerings of proposed systems
- Collect and assemble data for input into the risk analysis process
- Recommends corrective action for vulnerabilities that present unacceptable risk to the organization based upon the Veolia Group security policies and procedures
- Monitors progress for corrective action and assists Infrastructure, Cloud, IS&T L1 Service Desk and other teams in making progress
- Track security systems; recognize anomalies of various systems, and escalates appropriately
- Implement and support the Cyber Security policies, standards and recommendations of the Veolia Group.
- Work with the VWT Corp IS&T Cybersecurity team as the main point of contact for any topic related to cybersecurity.
- Makes recommendations for recovery and prevention process improvements
- Analyzes and correlates network data flow logs, web logs, computer and application user activity logs, and security incident logs for information relevant to a real or potential information security or privacy breach or to support decision making and risk mitigation
- Contribute expertise in discovery and information gathering sessions
- Participate with PMO team to identify alternative analysis evaluating pros and cons, technical feasibility, risk and other information to support a decision to select the best solution
- Complete assigned project tasks on time
- Communicate issues for timely resolution
- Work with other PMO team members to remove barriers to progress
- Communicate progress with PMO lead
- Train, assist and guide colleagues on Cyber security methods, strategies and policies systems they support.
- Interact with the Infrastructure, Cloud, IS&T L1 Service Desk and other teams to assist in troubleshooting and identify root cause.
- Occasionally travel to other states or countries when required, or work outside of business hours
- Performs other duties as assigned
Qualifications
EDUCATION
Bachelor's degree in Computer Science, Information Systems Management, Technology, Engineering or equivalent
SKILLS, KNOWLEDGE and EXPERIENCE
- 4 + years of related work experience
- Must be proficient in Google, Cybersecurity, Security Standards, Cloud software (AWS), Networking, Middleware (Data Lake / Hub)
ESSENTIAL COMPETENCIES / BEHAVIORS
- Proven work experience as a security lead
- Expertise in medium to large enterprise systems infrastructure
- Familiarity with various modern operating systems and platforms (Microsoft Windows, GNU / Linux, Chrome OS, IOS, Android, etc.)
- Strong understanding of core Windows Server roles such as Active Directory, DNS, DHCP and File Sharing
- Hands-on experience with networking components and technologies such as switches, routers, firewalls, Wi-Fi, VOIP and VPN
- Working knowledge of virtualization technologies
- Good knowledge of AWS and Google Cloud Platforms
- Excellent communication skills
- Ability to write audience appropriate reports, standards, process, and procedures
- Experience with scripting and automation tools
- Functional knowledge of relational database applications such as Microsoft SQL Server
- Dynamic, flexible and customer oriented
- Strong technical background with an ability to give instructions to a non-technical audience
- Good team spirit
- Ability to adapt and respond to changing work situations
- Have an exceptional analytical mind, be conscientious and methodical
- Be autonomous, responsible, organized and show initiative
- Demonstrate a high aptitude for problem solving
- Must have superb priority management skills and demonstrate the ability to work on several projects simultaneously
- Troubleshoot, analyze, and test solutions to technical problems
Related Jobs
Information security
Sr. Security Engineer
Manager, Security Engineering
Security officer