Information Security Analyst - Washington, United States - MUNICIPAL SECURITIES RULEMAKING BOARD

Mark Lane

Posted by:

Mark Lane

beBee recruiter


Description

The Information Security Analyst is responsible for securing the MSRB by supporting existing controls and processes across multiple dimensions and domains, including MSRB Web Applications, Cloud environments, networks, SaaS platforms, and enterprise systems.

The analyst will support operational security processes by triaging our security alerts, phishing reports, vulnerabilities, and end-user requests. The analyst will also perform routine maintenance and troubleshooting of security tools and platforms.

We expect the Analyst to work effectively with internal stakeholders, including the information security team, MSRB leadership, developers, system, database, and network administrators.


The Analyst will assist with implementing new tools and controls, enhancing existing controls, and monitoring the evolving threat environment to make informed recommendations and changes.

The Analyst may also contribute to incident response efforts, education, training, policy, and governance initiatives.


Essential Duties and Responsibilities:


  • Operational Support:
  • Directly triage and respond to security alerts, phishing reports, and enduser requests on a regular basis.
  • Support maintenance and troubleshooting activities for the Information Security program, including maintenance related to visibility, logging, SIEM, and antimalware controls
  • Support vulnerability management processes, such as scanning, assessments, penetration testing, and remediation efforts.

Continuous Improvement and Attack Surface Reduction:

  • Identify and implement improvements in vulnerability management, anti-malware and SIEM platforms.
  • Assist with implementation of new security tools and controls to enhance the organization's security posture.
  • Proactively monitor and understand the evolving threat environment and cybersecurity developments.

Enterprise Security:

  • Identify configuration issues and improvement opportunities.
  • Lead and assist defenseindepth efforts.
  • Review and improve securityrelated SaaS configurations.
  • Assist with Identity and Access Management efforts, including access reviews and implementation of least privilege.
  • Communication, Education, and Security Awareness:
  • Assist with incident response efforts.
  • Assist with selection and management of security awareness courses, simulated phishing campaigns, and other routine education exercises.
  • Communicate security policies and best practices to endusers, fostering a securityconscious culture.
  • Assist staff with monitoring for and ensuring compliance with security policies, procedures, standards, and guidelines.
  • Educate staff on associated risks and benefits of technologies.
  • Expertise in enterprise security or technology functions, including:
  • Critical Thinking Can break problems down into manageable, ordered components and effectively communicate issues and plans to others. Can incorporate new knowledge quickly. Demonstrates the ability to use different problem-solving strategies and select the one that best meets the requirements of the situation. Gathers data to support recommendations and seeks approval before taking action to minimize risk and maximize impact.
  • Good Judgment Takes selfgoverned, consistent action to prioritize and weigh cost and value in order to determine the action most appropriately aligned with organizational goals. Keeps the big picture in mind while focusing on specific issues. Weighs risks and tradeoffs reasonably. Reliably escalates when necessary.
  • Proactivity Eager to tackle daytoday tasks and help teammates solve problems. Works with more experienced teammates to assist with solving complex problems and complete tasks within time constraints. Takes a deep sense of ownership in their work, no matter how small the task.
  • Collaborative Takes initiative to actively participate in team interactions. Draws on the strengths of fellow team members. Actively seeks opinions and ideas from people of varied background and experiences to improve decisions. Can effectively distill and communicate complex technical concepts to nontechnical staff. Communicates effectively.
We are proud to be a collaborative organization that values diversity, equity and inclusion. We offer comprehensive benefits that support our employees' overall mental and physical health and wellness. We aim to empower our employees with the resources they need to achieve a successful work-life integration.

A resume must be attached for full consideration. All applicants must demonstrate their ability to work in the U.S. without current or future employer sponsorship. No exceptions will be made.

More jobs from MUNICIPAL SECURITIES RULEMAKING BOARD