Security Analyst
Cybersecurity Tools
Endpoint Security
Identity and Access Management
Incident Response
Information Security
Information Technology (IT)
InfoSec
Project Management
Risk Management
Security
Security Compliance
Security Information And Event Management
Security Operations
Security Standards
Security Testing
Job Description
Join LBMC’s Enterprise Department to support security operations and projects, strengthen controls, and help manage cybersecurity risk across the firm.
Responsibilities
- Collaborate with IT and non-IT teams to establish and maintain procedural security controls aligned with security requirements and industry best practices
- Use security software to gather data for reporting capabilities
- Assist with investigation and response to security alerts
- Analyze security issues and help design and implement effective solutions
- Review security logs and support technical analysts in interpreting log activity
- Work with the Information Security Officer to facilitate cybersecurity risk management by reporting inherent risks and supporting residual risk decisions
- Support the Vulnerability Management Program by reviewing vulnerability scan results, patching updates, and penetration test outcomes for an “as is” risk assessment of IT assets
- Conduct risk reviews for new applications, developed code, and related areas before implementation and production to help minimize exposure
- Monitor phishing campaigns
- Report potential threats or software issues
- Research system weaknesses and determine countermeasures
- Assist employees with cybersecurity, software, hardware, and IT needs
- Carry out and support information security plans and policies
- Support response, investigation, and recovery efforts for security breaches
- Assist with information security awareness training development and support
- Protect organizational data and infrastructure by enabling and/or recommending appropriate security controls
- Participate in and follow the change management process
- Handle daily administrative tasks, reporting, and communication within Information Security and relevant departments as needed or directed
- Assist with testing new software and firmware as needed or directed
Requirements
- Bachelor’s degree in Information Systems, Computer Science, Information Security, or related field
- Minimum 1-3 years progressive experience in IT risk, cybersecurity risk management, IT audit, or information security risk management, with emphasis on cybersecurity technology implementation projects or related technology implementations
- Strong knowledge of core IT and security infrastructures, including Active Directory, Azure AD, Microsoft Windows security controls, SIEM, AV/EDR, IDS/IPS, PIM, PAM, IAM, certificate management, and vulnerability scanners
- Strong understanding of each phase of the (S)SDLC and project delivery under Agile methodologies
- Cloud security knowledge for Azure/Windows environments, including risk assessments, security controls definition, control procedure appropriateness, and security capability identification
- Working knowledge of standards and frameworks: ISO 27001, IT Infrastructure Library and ISO 20000, Capability Maturity Model Integration, and laws/standards (NIST, GDPR, Sarbanes-Oxley)
- Understanding of SOC 2, Type II audits
- Strong knowledge of information security across Analyze, Prevent, Detect, and Respond domains
- Highly analytical, detail-oriented, and organized to complete assigned work
Technologies
- Active Directory
- Azure AD
- Microsoft Windows security controls
- SIEM
- AV/EDR
- IDS/IPS
- PIM
- PAM
- IAM
- Certificate Management
- Vulnerability scanners
- Azure
- ISO 27001
- IT Infrastructure Library
- ISO 20000
- Capability Maturity Model Integration
- NIST
- GDPR
- Sarbanes-Oxley
- SOC 2
- Type II audits
- Agile methodologies
- (S)SDLC
Location
- Brentwood, TN (Onsite)
Opportunity
- Maintain security operational and project activities and recommend remediation to minimize cybersecurity risks
- Work closely with the Information Security Officer, IS leadership, and team members to implement and sustain security and compliance across LBMC
- Continually monitor compliance-related activities and support risk assessments, monitoring, and security projects