
Information Security Specialist
STRATEGIC STAFFING SOLUTIONS HAS AN OPENING!
This is a Contract Opportunity with our company that MUST be worked on a W2 Only. No C2C eligibility for this position. Visa Sponsorship is Available! The details are below.
Beware of scams. S3 never asks for money during its onboarding process.
Title: Information Security Specialist
Contract Length: 6+ months
Location: San Antonio, TX
Job ref# 240248
Quick summary:
As a dedicated Information Security Specialist - Sensitive Data Management (SDM), with an active ISC2 CISSP certification, you will join our Enterprise Data Management (EDM) SDM team and will play a critical role in delivering high-quality data management products and services, enabling the organization to effectively handle and leverage data as a strategic asset. You will be involved in the implementation, and ongoing support of internal controls, sensitive data loss prevention, sensitive data discovery, sensitive data classification, and applicable documentation (policies, standards, governance procedures), development for Tokenization, Data Security Posture Management (DSPM) and Zero Trust Architecture (ZTA). You will collaborate with multi-functional teams to ensure data reliability, security, and accessibility, contributing on the overall business strategy and data-driven decision-making. Expect to lead Investigating, analyzing, and responding to process and security anomalies and events (e.g. control failure, suspicious behavior, attacks, and security breaches) within our environments using a variety of cyber defense tools to detect and respond to threats in addition to staying current with latest information security and data governance threats, exploits, trends, and intelligence.
Requirements:
- ISC2 CISSP Certification Required
- Sensitive data controls to protect PCI, PHI, PII and IP data or (3 Years)
- Email and Network Data Loss Prevention (5 Years)
- Data Centric Information Security Issue Remediation (5 Years)
- Data Loss Prevention - Agent and Cloud hosted based, Tokenization, Query language skills (SQL, KQL)
Brief description of the daily duties using the technology tools above?
Deep technical conversations.
Collaborate at the architecture level.
Reviewing updates to current deliverables.
Coordinating activities to defined sprint objectives and overall goals.
Support automation of current manual processes
Support ongoing processes and procedures to ensure control health, process delivery and customer support from data discovery through remediation activities.
Meet and partner with internal and external teams to drive progress for the organization.
Resolve ServiceNow and other assignments.
Ensures risks associated with business activities are effectively identified, measured, monitored, and controlled.
Follows written risk and compliance policies, standards, and procedures for business activities.
Develops, publishes, maintains and/or interprets complex Sensitive Data Security governance requirements (e.g. policies and standards).
Designs, develops, and optimizes repeatable methods and measurements for Sensitive Data
Security and information risk management program.
Performs and advises on Sensitive Data Security and information focused risk assessments of complex projects (e.g. newly established domain or system with limited to no structure or governance) and new technologies.
Influences and leads efforts across the EDM department and enterprise as SME in the area of Data Management to refine tooling, increase delivery through technology and drive automation.
Partners with IT to lead research efforts and analysis of the latest data governance vulnerabilities, tools, trends and intelligence in an Agile environment. Shares intelligence with the enterprise and collaborates with other internal and external organizations.
Develops junior analysts through training and knowledge sharing activities.
Responds both verbally and in writing to moderately complex inquiries and periodic exams from both internal control partners (e.g. legal, compliance, audit, risk) and external control partners (e.g. regulators, external auditors, third parties).
Ensures process owners identify, develop and test Sensitive Data and Information Security controls for Sensitive Data risk mitigation effectiveness.
Acts as an advisor on Sensitive Data focused standards, policies, processes, and procedures for the enterprise.
Quickly develops and maintains expert level knowledge of Information Security/Enterprise Data Governance standards as well as increasing industry information security standard methodologies, frameworks, laws, and regulation knowledge.
Ensures risks associated with business activities are effectively identified, measured, monitored, and controlled in accordance with risk and compliance policies and procedures.