Position SummaryAs the Security Analyst, you will be responsible for ensuring the organization is effectively designing, developing, and implementing security compliance controls and solutions. You will engage with stakeholders throughout the organization, and throughout the Product Lifecycle to ensure that standard security practices are followed and implementing risk mitigations where required. The position will work closely with IT Operations, Information Technology, Commercial Software, and Engineering, along with the business to ensure there is a consistent and common approach to implementation of security and compliance management activities.Responsibilities:Security Operations and Risk ManagementCollaborate with cross-functional teams to implement compliance initiatives and security controlsLead Security projects from ideation through deployment/delivery, while supporting day to day Security OperationsSupport Neptunes Security Operations Center (24x7x365) on overall event and incident management activitiesEnsure security requirements are implemented within various stages of the Software/System/Product lifecycle processWorking with various product management teams from design to build phasesWork closely with teams to Pen Test new features within software, products, infrastructureWork with teams to validate and address vulnerability and threat findings from analysis partners and toolsResearch upcoming IT trends and make security recommendationsPerform security reviews of software/product/infrastructure designs to assist developers in ensuring quality and robustness of our software and productsEngages in Disaster Recovery Planning/Testing to ensure all risks and potential threats have been mitigatedLeads analysis and review of security events conducted throughout the companyLeads exploration of practical security solutions to address emerging threats and compliance requirements, including design and implementation of recommended solutionsSupports ongoing compliance activities and monitoring efforts across applicable Regulations and StandardsEffectively deliver technical security issues to non-technical managementRequirementsEducation/Experience:Typically requires a bachelor's degree (or international equivalent) and 6 years of relevant experience.Preferred Qualifications:Bachelor's degree, preferably in Cybersecurity, Computer Science, or equivalent.5 years of infrastructure/network security, application security, security assessmentExperience in 2 or more of the following areas Incident Response, Vulnerability and Patch Management, AD Security, Disaster Recovery, Device/OS Hardening, Forensics, PKI encryption and authentication, Security engineering, Cloud Security, Security Standards NIST/SOC/ISO27001, SIEM management, Security assessmentsIT experience - infrastructure, networking, and/or software developmentProfessional certifications such as Security , CASP , CySA , GIAC or ISC2 certifications.Ability to take ownership of your areas and actively improve our security postureExperience working with outsourced organizations and third-party vendors preferredAdvanced written and verbal communication skillsStrong problem-solving skillsStrong analytical skills and the ability to understand and document complex technical or business process data flowTravel Requirements: Typically requires overnight travel less than 10% of the time.Location: Duluth, GA, Tallassee, AL
Equal Opportunity Employer/Protected Veterans/Individuals with DisabilitiesThe contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to in ividuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractors legal duty to furnish information. 41 CFR 60-1.35(c)
Equal Opportunity Employer - minorities/females/veterans/individuals with disabilities/sexual orientation/gender identity