Jobs
>
San Francisco

    Information Technology Security Analyst - San Francisco, United States - HR Pals LLC

    Default job background
    Description
    Summary:
    Under the general direction of the CIO, the Information Technology Security Analyst is responsible for the support, maintenance and implementation of the company's IT security systems and infrastructure. This includes security system design, hardware & software acquisition, installation, configuration and ongoing network security maintenance. This person will need to rely on experience and judgment to plan and accomplish corporate goals.

    Essential Duties and Responsibilities:
    SECURITY SOLUTIONS AND DESIGN:
    • Conduct research and provide insight to identify, assess, and deploy security technology solutions internally or through vendors, including but not limited to encryption, firewalls, authorization, authentication, intrusion detection, and gateway security controls.
    • Assist with recommendations for security improvements and tool acquisition to Senior Management.
    • Weigh business needs against security concerns to articulate issues and recommend options.
    • Participate in the design, development, and delivery of security training programs and individual classes.
    • Provide subject matter expert consultation to company Management on cyber security matters.
    • Manage the relationship with our third-party managed security service providers.
    • Conducts network monitoring and intrusion detection analysis using various tools, such as intrusion detection/prevention systems (IDS/IPS), firewalls, SIEM, as well as
    • other security infrastructure.
    • Responsible for utilizing SIEM (security incident event management) system to carefully examine network activity and to identify both external and internal threats to ensure security specifications meet company security guidelines.
    • Research and stay informed of potential information security threats, industry trends, emerging technologies, and response alternatives.
    • Works closely with the CIO in designing and implementing a multi-layer security strategy to protect LA Financial Credit Union information assets.
    • Alone or in conjunction with the incident response team, respond to security events: triage, contain, remediate, and document.
    • Coordinate with business units, operations, and technology teams for incident response, remediation, and improvement.
    • Participate in ongoing risk management program activities to reduce or maintain corporate and technological risk at acceptable levels.
    • Maintain, manage, and monitor compliance with security control frameworks such as FFIEC, PCI, and other federal law.
    • Coordinate security assessment on new and existing vendors.
    • Firmware and patch oversight for all operating systems in accordance to the Information Security Policy.
    • Monitor compliance with backup schedule.
    • Work with third party security organizations on risk assessments and penetration testing exercises.
    • Administer self-scan audits internally and externally and address all findings.
    • Reviews audits of system security to ensure compliance with security policies.
    • Knowledge of information security audit and assessment methodologies, policies, standards, procedures, and best practices.
    • Responsible for internal and external IT audit preparation and resolutions to findings.
    • Prepare and update documentation, including policies, procedures, standards, baselines, guidelines, incident reports, audit responses.
    • Implement controls to maintain data security through validating and recommending network security configurations, SSL/TLS certificate management, and other security controls.
    • Supports business continuity/disaster recovery plans, to include conducting or participating in disaster recovery tests, publishing test results, and making changes necessary to address deficiencies.
    • Participate in the ongoing security education of all company employees and advocate for secure practices in day-to-day company operations.
    • Stay abreast of the threat landscape affecting the financial industry.
    • Acts as the initial point of contact to facilitate the handling of security incidents and requests, conducts technical investigations resulting in successful root cause analysis of intrusions, and make real-time decisions about incidents as they occur.
    • Provide security expertise for business applications ensuring they are deployed and implemented securely.
    • Assist in the research, and design short and long-term changes and enhancements to the infrastructure from a security perspective.
    • Collaborate on critical technology projects to ensure that security issues are addressed throughout the project life cycle.
    • Participate in developing the annual IT strategic plan, review existing infrastructure security configuration, plan and make recommendations for future enhancements.
    • Engineer solutions that sustain the operational integrity and security of all business systems and networks.
    • Maintain all reporting and documentation pertaining to the IT security infrastructure.
    • From a security perspective, assist with network troubleshooting as needed; work with vendors and telecommunications service providers to ensure continuous network availability.
    • Adhere to the established change management and turnover log procedures.
    • Must be available after hours and weekends to ensure systems are fully operational and respond to crisis and provide management support and oversight.
    • Perform all other duties as required/assigned.
    PROFESSIONAL DEVELOPMENT: Remain current with developments in information technology, information security and their potential impact on our client's present and future needs. Continue technical professional development through seminars and workshops, membership in technical and professional organizations, and through reading technical publications and journals. Network with others in the credit union industry and interface with vendors. Keep certifications current and work towards acquiring new certifications as required.

    PROJECT MANAGEMENT: Lead internal technical project teams in the implementation of IT security upgrades such as firewalls, antivirus systems, data loss prevention systems, intrusion detection systems, web and email filters and others. Evaluate project proposals and implement project life-cycle and manage approved projects. Work closely with the CIO to ensure technical specifications meet the client IT infrastructure guidelines and with the implementation of corporate wide IT related projects.

    KNOWLEDGE, SKILLS, AND ABILITIES:
    Must be skilled in communications, human relations, problem solving and organization.

    GENERAL ADDITIONAL RESPONSIBILITIES: Perform additional responsibilities as assigned.

    Qualifications:
    EDUCATION:
    • Requires Bachelor's Degree in Information Security or other related technical field.
    • One or more industry certifications such as ISC2, Certified Information Systems Security Professional (CISSP), Microsoft Certified Professional (MCP), Cisco Certified CyberOps Associate (CCCOA), or similar are required. Experience can be credited in lieu of education.
    EXPERIENCE:
    • 5-7 years of work experience in IT cyber security related position.
    • Experience with IT security infrastructure consisting of firewalls, IPS/IDS, web and email filters, antivirus/antimalware systems, and VMware virtualization.
    • Knowledge of systems and networking in a primarily Windows domain environment including but not limited to Active Directory, Azure Active Directory/Entra ID, Group Policy, Microsoft 365, and Conditional Access Policy.
    PHYSICAL DEMAND: The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. While performing the duties of this job, the employee is regularly required to stand; walk; use hands to finger, handle, or feel objects, tools, or controls; and talk or hear. The employee frequently is required to reach with hands and arms. The employee is frequently required to sit, stoop, kneel, or crouch. The employee must frequently lift and/or move up to 25 pounds, and be capable of transporting related supplies and equipment. Specific vision abilities by this job include vision, distance vision, color vision, peripheral vision, depth perception and the ability to focus.

    Our client acknowledges that equal opportunity for all persons is a fundamental human
    value. Each employee and applicant will be considered on the basis of individual ability and merit, without regard to race, color, religion, age, sex, sexual orientation, gender identity, gender expression, pregnancy, national origin, marital status, physical disability, mental disability, medical condition, genetic information, protected military or veteran status, or any other characteristics.

    For more job opportunities, follow us at .


  • Allied Universal® San Francisco, United States

    SOC Security Analyst · **Overview**: · Allied Universal, North America's leading security and facility services company, provides rewarding careers that give you a sense of purpose. While working in a dynamic, diverse and inclusive workplace, you will be part of a team that fuels ...

  • University of California , San Francisco

    Security Analyst

    1 week ago


    University of California , San Francisco San Francisco, United States

    · Security Analyst · PPH-Domestic-Core-IZ · Full Time · 77068BR · Job Summary · This position supports the California Immunization System and involves work implementing and maintaining measures to safeguard the system from unauthorized access, data breaches, and cyber threat ...

  • University of California

    Security Analyst

    1 week ago


    University of California San Francisco, United States

    · Security Analyst · PPH-Domestic-Core-IZ · Full Time · 77068BR · Job Summary · This position supports the California Immunization System and involves work implementing and maintaining measures to safeguard the system from unauthorized access, data breaches, and cyber threat ...

  • Abnormal Security

    Security Analyst

    3 days ago


    Abnormal Security San Francisco, United States

    Job Description · Job DescriptionThe OpportunityWe are looking for an Overnight Security Analyst to join our frontline cybersecurity defense team. As a Security Analyst, you will be responsible for identifying, catching, and preventing email fraud by efficiently handling a high v ...


  • AMN Healthcare San Francisco, United States

    Job Description · Information Security Engineer, · San Diego, CA (Hybrid) · **This role doesn't provide sponsorship or H1 transfer. · Welcome to AMN Healthcare: Where Your Career Becomes the Next Big Success Story · Have you ever wondered what it takes to build one of the la ...


  • Falcon IT & Staffing Solutions San Francisco, United States

    02nd May, 2024 · Role: Information Security Analyst. · Location: Point Mugu Naval Air Station / Camarillo, CA. · Job Description: · A defense contractor is seeking an Information Security Analyst with 3+ years of experience in classified programs, working onsite at Point Mugu N ...


  • AMN Healthcare San Francisco, United States

    Job Description · Information Security Engineer, · San Diego, CA (Hybrid) · **This role doesn't provide sponsorship or H1 transfer. · Welcome to AMN Healthcare: Where Your Career Becomes the Next Big Success Story · Have you ever wondered what it takes to build one of the la ...

  • Motion Recruitment

    Security Analyst/ PCI

    2 weeks ago


    Motion Recruitment San Francisco, United States

    A successful retail company based in San Francisco is hiring for a Security Analyst to join the Information Security Governance, Risk and Compliance GRC Team. The candidate will have experience & knowledge of Information Security Compliance Management and Quality Management and w ...

  • Motion Recruitment

    Security Analyst/ PCI

    2 weeks ago


    Motion Recruitment San Francisco, United States

    Security Analyst/ PCI / 3 Month Contract · San Francisco, CA · **Onsite** · Contract · $53/hr - $58/hr · A successful retail company based in San Francisco is hiring for a Security Analyst to join the Information Security Governance, Risk and Compliance GRC Team. The candidate wi ...


  • Astranis San Francisco, United States

    Astranis is on a mission to bridge the digital divide by connecting the four billion people worldwide who currently lack internet access. We're doing this by building the next generation of smaller, more cost-effective spacecraft to bring the world online. · As a team, we've lau ...


  • Ask Staffing San Francisco, United States

    Position: Information Security Analyst · Location: Remote - 8 am-5 pm PST work hours required · Duration: Through 1/31/24 - No potential to extend or convert at this time as it's budget-based and the budget is only approved through the end of the fiscal year · Interview Proces ...

  • Lambda

    Security GRC Analyst

    2 weeks ago


    Lambda San Francisco, United States

    Lambda's GPU cloud is used by deep learning engineers at Stanford, Berkeley, and Carnegie Mellon. Lambda's on-prem systems power research and engineering at Intel, Microsoft, Kaiser Permanente, major universities, and the Department of Defense. · If you'd like to build the world ...

  • Lambda

    Security GRC Analyst

    2 weeks ago


    Lambda San Francisco, United States

    Lambda's GPU cloud is used by deep learning engineers at Stanford, Berkeley, and Carnegie Mellon. Lambda's on-prem systems power research and engineering at Intel, Microsoft, Kaiser Permanente, major universities, and the Department of Defense. · If you'd like to build the world ...


  • absolute California City, United States Full time

    Responsibilities of Information Security Analyst Responsible for managing/advising protection on Local Area Networks (LAN) the Wide Area Networks (WAN) firewalls routers Internet gain access to wireless methods Directory Services Network Intrusion Detection Systems (NIDS) Intrusi ...

  • Motion Recruitment

    Security Analyst/ PCI

    4 weeks ago


    Motion Recruitment San Francisco, United States CONTRACT

    A successful retail company based in San Francisco is hiring for a Security Analyst to join the Information Security Governance, Risk and Compliance GRC Team. The candidate will have experience & knowledge of Information Security Compliance Management and Quality Management and w ...


  • HonorVet Technologies San Francisco, United States

    Job Title - Information Security Analyst Operations · This position will be onsite with the possibility of teleworking offered 2 days a week after the training period · Key Information:Security Operations Center (SOC) Analyst to perform threat analysis, threat response, threat h ...


  • Postman, Inc. San Francisco, CA, United States

    Senior Security Compliance Analyst - San Francisco · Postman is the world's leading collaboration platform for API development. Postman's features simplify each step of building an API & streamline collaboration to help create better APIs—faster. More than30 million developers & ...


  • Postman San Francisco, CA, United States

    Postman is the world's leading collaboration platform for API development. Postman's features simplify each step of building an API & streamline collaboration to help create better APIs—faster. More than 30 million developers & 500,000 organizations worldwide use Postman today, a ...


  • TEKsystems San Francisco, United States

    *No C2C · Job Description: · Our client is seeking Metrics and Reporting experience to support the Cyber Security Metrics Monitoring team. This team is instrumental in providing metrics for cross functional teams to help better understand how well they are at certain deliverables ...

  • Insight Global

    Security Analyst

    1 week ago


    Insight Global Berkeley, United States

    Job Description · Insight Global is looking for a security analyst to join one of our largest education client's IT Division · We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are a ...