IT Security Analyst Job at GovServicesHub, Richmond, VA

UjUxNy90amJscGc5dGU2Si9lVzQ0MldJTHc9PQ==
  • GovServicesHub
  • Richmond, VA

Job Description

Job Location: Virginia(Hybrid)

Job Description:

For this position we are really looking for someone who is strong in Security Operations (Vulnerability Management, Penetration Testing, Incident Response, Identity Access Management, etc.). A few of the candidates were strong in Risk Management (Risk Assessment, Data Classification, Audits, etc.) but we already have those skills on our team. The remaining candidates mostly struggled to answer basic technical questions relating to security and seemed to mostly come from more IT Operations backgrounds. We are looking for an experienced person as this is not an entry level opening. 

General things to consider when screening:

  1. Experience with vulnerability management is key for this position.
  2. Experience with application penetration is key for this position.
  3. Experience with Dev SecOps/Secure Software Development Lifecycle (Secure SDLC/SSDLC)/Secure by Design is key for this position.
  4. Scripting and automation experience is highly desired for this position.
  5. Interpersonal skills and being able to talk with and manage stakeholders are key for this position. 

Analyze the security impact of application, configuration, and infrastructure changes to ensure compliance with the security standard as part of the change management lifecycle.

·Assess the configurations of applications, servers, and network devices for compliance with the security standard.

·Analyze and document how the implementation of new system or new interfaces between systems impacts the security posture of the current environment.

·Assess and document the security impact and risks of newly discovered vulnerabilities in the environment.

·Coordinate resolution of application and infrastructure security vulnerabilities with System Owners, IT, and vendors. Track resolution of vulnerabilities and provide regular updates to management.

·Coordinate resolution of endpoint security vulnerabilities with users and provide regular updates to management.

  • Respond to, and investigate, security incidents and provide thorough post-event analyses.
  • Perform internal application penetration testing, document findings, and recommend improvements to improve the organization’s security posture.
  • Complete annual password security audits and coordinate completion of agency wide user access audits in compliance with the security standard.
  • Determine the protection needs (i.e., security controls) for the information system(s) and network(s) and document appropriately.
  • Create and maintain desk procedures and process documentation for all responsibilities.

Benefits

Skill

Required /Desired

Amount of Experience

Candidate Experience

NIST 800-53 rev 5 and/or Criminal Justice Information System (CJIS) specifications for an information security management system.

Required

5

 

Software development lifecycle, vulnerability management processes, role-based authentication methodologies, etc.

Required

5

 

Familiarity with programming languages such as Python, Java, JavaScript, C++, C#, SQL, HTML, CSS, and/or COBOL.

Required

5

 

Expertise in using automated vulnerability scanners like Nessus, Qualys, Retina, and/or Tenable.

Required

5

 

Familiarity with web application security testing tools like Burp Suite, Fortify, and/or AppScan.

Required

5

 

Basic scripting skills (e.g. WDL, VBScript, JavaScript, PowerShell, Python) for automation

Required

5

 

IT security or risk assessment certifications are advantageous (CISM, CCSP, CISSP, CEH, CompTIA Pentest+ and/or CompTIA Security+)

Required

5

 


Job Tags

Contract work,

Similar Jobs

WES Health System

Community Social Worker Job at WES Health System

 ...individual occupying this position will perforn work in the community that supports establishing and building relationships with local CRC's,...  ...resources and services. Collaborate with other social workers, healthcare professionals, and community leaders to address... 

Northwestern Memorial Healthcare

Nurse Practitioner or Physician Assistant - Emergency Medicine - Full-time, Nights Job at Northwestern Memorial Healthcare

 ...Ready to join our quest for better? Job Description Northwestern Medicine has an exciting opportunity for either a Nurse Practitioner or a Physician Assistant to work in our Emergency Medicine department. Schedule: 3x12s; all NIGHTs; rotating weekends and... 

Robert Half

Front End Developer Job at Robert Half

 ...office number at (***) ***-********We are looking for a talented Front End Developer to join our team in Irvine, California. In this long-term...  ...you will play a key part in creating dynamic, user-friendly web interfaces while ensuring optimal performance and accessibility... 

MercyOne

Clinical Documentation Specialist Job at MercyOne

Clinical Documentation Specialist Location Clinton, IA : Employment Type: Part time Shift: Day Shift Description: At MercyOne, health care is more than just a doctor's visit or a place to go when you're in need of medical attention. Our Mission is based on improving... 

VIRTUA

Gastroenterology - Advanced Practice Provider - APP - Nurse Practitioner / Physician Assistant (Inpatient) Job at VIRTUA

Virtua Medical Group is currently seeking a full-time Physician Assistant or Nurse Practitioner to join our Gastroenterology team. This role involves coverage across our five inpatient facilities, situated in Voorhees, Marlton, Willingboro, Mount Holly and Camden. The...