Information Security Analyst 3
Job Description
Insitu seeks an experienced Information Security Analyst (Risk Management) for a 12-month contract based in Bingen, WA with remote location flexibility. This role is centered on protecting enterprise systems through risk management, compliance oversight (including NIST 800-171), security testing and monitoring, and support for incident response and governance.
Key Responsibilities
- Plan, implement, and upgrade network and information security controls in line with industry standards.
- Assess security needs and develop strategies to safeguard sensitive information.
- Coordinate and maintain security architecture and applications, including ongoing infrastructure maintenance.
- Perform compliance monitoring, identify organizational deficiencies, and recommend and implement corrective actions.
- Conduct risk assessments, security evaluations, and rigorous testing of systems and equipment.
- Develop, deploy, and manage firewalls and other security technologies, and establish effective safeguard procedures.
- Analyze system logs, configure alerts, and use security controls to detect threats and anomalies.
- Execute penetration testing and vulnerability assessments to determine system risk levels.
- Create, implement, and track mitigation plans for identified vulnerabilities.
- Carry out active threat monitoring, evaluate indicators of compromise, and support responses to security incidents.
- Research, develop, and refine incident response tools and processes; participate in breach investigations and remediation.
- Develop and deliver security awareness training for staff, including ad hoc sessions and scheduled requirements.
- Maintain and refine Insitu’s System Security Plan to comply with NIST 800-171 standards.
- Develop and update governance documentation, including policies, standards, and work instructions.
- Serve as a security advisor to senior stakeholders, providing guidance to managers, directors, and executives.
Required Qualifications
- Bachelor’s degree in a technical field (such as Information Technology, Computer Science, or Cybersecurity) and at least 5 years of relevant Information Security experience, or a master’s degree with at least 3 years.
- Strong knowledge of information security principles, including governance, risk, and compliance.
- Familiarity with information protection regulations such as NIST 800-171, DFARS, HIPAA, and PCI-DSS, as well as applicable laws.
- Experience configuring and managing firewalls and security safeguard systems.
- Demonstrated background in penetration testing, vulnerability assessments, and threat monitoring.
- Strong verbal and written communication skills for technical and non-technical audiences.
- Ability to independently research and resolve complex technical security issues.
- High degree of integrity and professionalism.
- Effective collaboration, teaming, and adaptability in a fast-paced, dynamic environment.
Technology & Compliance Focus
- NIST 800-171
- Firewalls
- Security architecture
- DFARS
- HIPAA
- PCI-DSS
Preferred Education & Experience
- Bachelor’s or master’s degree in Cybersecurity, Information Assurance, or a related field.
- Professional Information Security certifications such as CISSP, CISM, or CEH.
- Experience in highly regulated industries such as defense, aerospace, or government.
- Experience with cloud security frameworks and technologies.
- In-depth understanding and practical experience with NIST, ISO/IEC 27001, or similar security frameworks.
- Familiarity with security incident response platforms.
Work Location
Remote with a limited in-office collaboration requirement. The role will need in-person presence for collaboration 2-3 times per year, and can be located anywhere within the continental United States. Candidates local to the Bingen, WA area will have a hybrid onsite requirement based on their location.