Senior Information Security Analyst

Full Job Description

Position Overview:

Works closely with the Head of the Department. Possesses a secondary leadership role. Develops and manages information and cyber security related activities and projects. Supports and assists senior management by providing guidance on information and cyber security issues. Effectively works with IT Department on technology risk related matters. Develops ways to improve efficiency, effectiveness, and productivity for the department. May direct subordinate staff.

Duties and Responsibilities:

  • Work closely with the Head of the Department and assumes a secondary leadership role of the Department with expertise in developing and managing information and cyber security related activities and projects.
  • Responsible to effectively work with IT and coordinates any incident response to cyber security events.
  • Provide support and guidance to IRG staff. May supervise projects and/or work product.
  • Keeps abreast of industry wide information risk issues that are relevant and could potentially have an impact on Branch Operations.
  • Acts as an Information Security subject-matter-expert to support and assist with providing guidance to Senior Management on information and cyber security issues.
  • Reviews and proposes practical changes to potential and existing Information Security policies, procedures, practices, and guidelines to ensure business operations and/or effective compliance to existing federal, state, and local government cyber security regulatory requirements.
  • Assists in establishing processes for communicating data classification guidelines and its governance.
  • Revises and maintains information and cyber security policies and procedures manuals.
  • Coordinates and manages the employee information security awareness training program.
  • Assesses and evaluates Information Risks by conducting:
    • Annual Risk Assessment;
    • Semi-annual Vulnerability Assessments;
    • Special Risk Assessments for new information risk related processes or significant process changes; and,
    • Trend analysis of key information risk measurements.
  • Coordinate and prepare material for the monthly information security meetings with various Branch and Head Office Departments and levels of Management.
    • Performs key Information Risk Governance related tasks as described below:
    • Provides user access control management oversight;
    • Monitors, analyzes, and follows-up on Information Risk events/issues; and,
    • Reviews information risk and proactively advises as necessary on: IT Projects/Issues Management process, Change Management Process, Significant changes to IT procedures, IT Asset Management Report, Key IT Vendor Contracts, IT Disaster Recovery Plan/Process, Record Retention Process, and Internal or external audit findings.12. Develops and maintains Information Risk Key Risk Indicators (KRI).
  • Periodically updates members of the IT Department on Information Risk related practices.
  • Reviews vendor service level agreements and contracts to provide guidance on information and cyber security protective controls and countermeasures.
  • Performs other duties and responsibilities as assigned by management.

Knowledge, Skills, and Abilities:

  • Bachelor’s degree in Information Systems or its equivalent with 5+ years of experience in Information Security or IT Audit.
  • Certification in Information Security (CISSP) preferred but not required.
  • An in-depth knowledge and understanding of Information Risk assessment concepts and principles as they relate to risk appetite, risk tolerance, and business risk exposure.
  • Knowledge of Information Security principles, terminology, and technology.
  • Knowledge and expertise in Risk Assessment and Risk Analysis.
  • In-depth knowledge of Information Technology.
  • Ability to analyze and design Information Security monitoring process.
  • Excellent computer skills in Microsoft Office including Excel and Word.
  • Strong interpersonal communication, written documentation, presentation skills, organization, and documentation skills.
  • Strong project management skills.
  • Good people management skills, with the ability to develop and guide Information Security team members, preferred.


To apply for this job email your details to


Care to Share? Please spread the word :)