CybersecurityJobs.io
← Back to all jobs

Job Description

Hybrid in Little Rock, AR with a regular employment setup and a compensation range of $99,000 - $128,600 per year. This Senior Information Security role supports the operations, administration, and governance of enterprise security solutions and processes, including proficiency across multiple security components.

This position is responsible for helping ensure information security is designed for confidentiality, integrity, and access, while also driving policy, framework compliance, audit remediation, vulnerability management, and security testing practices.

Responsibilities

  • Provide guidance and policy expertise for data security, including data classification, storage, transmission, and lifecycle; set baseline configurations and monitor data governance.
  • Set security policy and enforcement for standards such as file permissions, encryption, cloud data security, network assets, and endpoint requirements.
  • Provide or support network monitoring solutions within SOC/SIEM implementation.
  • Perform initial incident response functions and support incident response plans and capabilities using security concepts and best practices.
  • Support investigations, including logging and monitoring activities, securely provisioning resources, testing disaster recovery plans, and addressing personnel safety and security concerns.
  • Oversee implementation, configuration, maintenance, and changes for network security capabilities and assets.
  • Manage account security across account security systems, including privileged access management entitlement review and approvals.
  • Conduct usage audits, verify removal and retirement of accounts, approve launcher requests, and provide end user support.
  • Create, modify, delete, and retire member accounts, and manage role entitlement processes.
  • Maintain Workday integration, and manage access management application/system updates and testing.
  • Provide guidance to business partners on information security issues and identified security risks.
  • Create, manage, and enforce information security policy and provide oversight of framework compliance.
  • Manage enterprise audit remediation and CAP management, and manage the vulnerability management plan.
  • Conduct anti-phishing campaigns and manage the information security awareness and training program.
  • Manage the third-party risk management program.
  • Set security requirements, standards for mobile and web security, and security requirements for IoT devices.
  • Provide requested evidence and artifacts for security-related assessments and audits; coordinate and schedule required enterprise security assessments.
  • Coordinate quality of outside vendor-provided security assessments, risk assessments, and penetration testing of enterprise assets.
  • Oversee static and dynamic scanning of internally developed software and report to support remediation of code vulnerabilities.
  • Review SDLC documentation for compliance with company and regulatory standards as applicable.
  • Provide technical consultation as required. Other duties may be assigned.

Requirements

  • Bachelor’s degree in Business, Computer Science, Management Information Systems, or a related field.
  • In lieu of degree, five (5) years of relevant experience will be considered.
  • Minimum five (5) years of IT security experience with complex system technology.
  • Advance knowledge of at least one common information security management framework, such as HIPAA, HITRUST, ISO/IEC 27001, ITIL, NIST, COBIT, and/or ITL.
  • Professional security management certification such as HITRUST (CCSFP), CISSP, CISM, CISA, or similar credentials preferred.
  • Detail-oriented with critical thinking and strong analytical skills; problem sensitivity and ingenuity.
  • Strong project management skills and excellent communication skills.
  • Ability to build collaborative relationships.
  • System analysis experience preferred; project management, data testing/software application testing preferred.

Tools and Frameworks

  • Technologies: HITRUST (CCSFP), CISSP, CISM, CISA, HIPAA, ISO/IEC 27001, ITIL, NIST, COBIT, ITL, SOC, SIEM, Workday, SDLC

Certifications

  • CISM (ISACA)
  • CISA (ISACA)
  • CISSP (ISACA)

Security and Compliance Requirements

  • Position is identified as level three (3), requiring protection of records and information to prevent substantial harm, embarrassment, inconvenience, or unfairness.
  • Maintain integrity of information as outlined in the company Administrative Manual.
  • Adhere to segregation of duties guidelines in the Administrative Manual to prevent or detect errors or irregularities in a timely basis.

Location and Work Schedule

  • Hybrid role in Little Rock, AR with a minimum of three days in office weekly.
  • Employment type: Regular.

ADA Requirements

General office worker role with semi-active campus travel. Periodic lifting and carrying up to 40 lbs and routine work-related travel within walking distance of the primary work assignment as essential functions.

Similar Jobs