
Configuration Management Security Analyst
Salary undisclosed
Checking job availability...
Original
Simplified
Software Guidance & Assistance, Inc., (SGA), is searching for a Configuration Management Security Analyst for a CONTRACT assignment with one of our premier Healthcare Services clients . This position is fully remote.
Responsibilities :
The Configuration Management Engineer is responsible for managing the identification, assessment, reporting, and mitigation of infrastructure and cloud vulnerabilities. A candidate for this role will have a mindset of a defender and be able to operate in a fast-paced environment working closely with infrastructure and cloud teams on addressing misconfigurations on network assets, servers, and business applications.
SGA is an Equal Opportunity Employer and does not discriminate on the basis of Race, Color, Sex, Sexual Orientation, Gender Identity, Religion, National Origin, Disability, Veteran Status, Age, Marital Status, Pregnancy, Genetic Information, or Other Legally Protected Status. We are committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, and our services, programs, and activities. Please visit our company to request an accommodation or assistance regarding our policy.
Responsibilities :
The Configuration Management Engineer is responsible for managing the identification, assessment, reporting, and mitigation of infrastructure and cloud vulnerabilities. A candidate for this role will have a mindset of a defender and be able to operate in a fast-paced environment working closely with infrastructure and cloud teams on addressing misconfigurations on network assets, servers, and business applications.
- Evaluate and establish information security requirements by researching industry standards, conducting system security and vulnerability analyses, performing risk assessments, and analyzing architecture and platform configurations.
- Provide vulnerability and misconfiguration remediation governance and operational support.
- Perform vulnerability metrics reporting for ad-hoc and scheduled metrics report for various KPIs (Key Performance Indicators) around vulnerability management activities.
- Drive and track remediation initiatives across multiple support teams.
- Respond to questions from stakeholders about remediation and vulnerability assessment results and actions.
- Collaborate with support groups/stakeholders on details about identified vulnerabilities.
- Bachelor's degree in Computer Science, Cybersecurity or other related field, or equivalent work experience.
- Ability to analyze vulnerability/configuration metrics using Microsoft Excel advanced techniques.
- 3-4 years of combined IT and security work experience with a broad range of exposure to cybersecurity, systems analysis, application development and/or systems administration and 2+ years of vulnerability management experience.
- Requires Security Certification(s) (i.e., Certified Information Systems Security Professional (CISSP), or Certified Information Security Manage (CISM), Certificate of Cloud Security Knowledge (CCSK), Offensive Security Certified Professional (OSCP) or other equivalent recognized security certifications. Knowledge of Cloud like Microsoft Azure is a plus.
- Good understanding of industry standard regulations and risk management frameworks and standards (e.g., ISO, PCI, NIST, COBIT, GAPP, HIPAA, CIS, HI-TRUST, GDPR).
- Familiarity with SANS Top 25 controls, OWASP Top 10 and/or MITRE ATT&CK framework
- Excellent communication skills: able to explain complex concepts clearly to both technical and non-technical stakeholders.
- Exposure or knowledge of cloud and on prem architectures, services, and vulnerabilities.
- Understanding of risk assessment methodologies.
- Proficiency in using configuration/posture mgmt scanning tools such as Qualys Policy Compliance, Microsoft Defender for Cloud/Endpoint, Prisma, Wiz or similar CSPM/ CNAPP
- Reporting and metrics expertise with platforms such as ServiceNow (SecOps), PowerBI, etc.
SGA is an Equal Opportunity Employer and does not discriminate on the basis of Race, Color, Sex, Sexual Orientation, Gender Identity, Religion, National Origin, Disability, Veteran Status, Age, Marital Status, Pregnancy, Genetic Information, or Other Legally Protected Status. We are committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, and our services, programs, and activities. Please visit our company to request an accommodation or assistance regarding our policy.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
Report this job