Search jobs > St Louis, MO > Information security

Information Security Analyst III - Technical

Bi-State Development
St. Louis, Missouri
Full-time

The Role

The Information Security Analyst is responsible for improving and maintaining a comprehensive Information Security Program for Bi-State Development.

It would include working with all aspects of the BSD environment including the SCADA network and radio maintenance teams to ensure compliance to all mandates from the FTA, Homeland Security Department, and any other governing body Bi-State must adhere to.

This role seeks to protect against the unauthorized access, modification, or destruction of Bi-State Development’s systems and information assets.

On an on-going basis, this position will manage all activities across Bi-State Development (BSD) to ensure ongoing data security and validation with current security standards.

Responsibilities

  • Research the latest information technology security trends, to keep current and promote use of the latest technology to protect our information by creating recommendations for company-wide best practices.
  • Coordinate / Conduct frequent simulated cyber-attacks and penetration testing to look for vulnerabilities in the computer systems and take care of these before an outside cyber-attack.
  • Tracking and coordinating known cyber vulnerabilities following them to completion and ensuring all are properly closed out.
  • Assist in system monitoring and remediation to manage security alerts and identify / reduce false positives.
  • Development cyber security related strategies and approaches including a cybersecurity breach contingency and recovery plan.
  • Research new tools and technologies to assist in the cyber security area.
  • Coordination with external entities on critical cyber matters.
  • Work with other IT Security team members to share information and promote a secure and proactive IT security environment.
  • Work with emergency management and COOP Planners to ensure that the Information Technology’s recovery plan is fully coordinated with the COOP and emergency plans.
  • Investigate and document security breaches and other cybersecurity incidents including assessing damage potential.
  • Perform computer forensics as needed.
  • Implement and maintain vendor supplied security hardware components & software packages.
  • Perform diagnostics for security problems and identify and analyze security risks.
  • Coordination of security assessments with internal audit and external vendors.
  • Assist in developing security awareness and training programs for IT and employees who work with sensitive data.
  • Create and manage Cyber Security policies, standards, procedures, and guidelines.
  • Work with confidential information obtained through security scans and assessments of BSD systems.
  • Report status and progress on efforts to management as necessary.
  • Other related security duties as assigned.

Knowledge, Skills, & Abilities

  • Knowledge of NIST Cyber Security Framework, CIS Security Controls.
  • Experience with network and application security including firewalls, VLANs, routers, switches, Linux, Microsoft Windows and VMware operating systems, Oracle and Microsoft SQL Server databases, ecommerce, PCs.
  • Experience performing penetration testing.
  • Experience setting up firewall rules.
  • Experience performing computer forensics.
  • Experience with designing, implementing and managing an enterprise-wide security program.
  • Experience working with outside vendors to coordinate testing and resolution of security vulnerabilities.
  • Experience writing recovery plans, updating policies / procedures and documenting security breaches.
  • Ability to efficiently and effectively communicate technical information to colleagues and management.
  • Ability to manage time efficiently and multitask when appropriate in potentially high demand scenarios.
  • Ability to solve problems and provide solutions that are technically, financially, and administratively responsible.
  • Ability to provide competent, realistic estimates for cost, effort, and time requirements for assigned initiatives.
  • Completion of one of the following recognized professional certifications : QSA (Qualified Security Assessor), CISM (Certified Information Security Manager), CISSP (Certified Information Systems Security Professional), SSCP (Systems Security Certified Practitioner), Certified Ethical Hacker (CEH)

Education

Experience

Degree : . / . or equivalent experience required. MS preferred

Years : Minimum of two (2) years of cybersecurity experience and a total of 5 or more years’ experience in Information Technology related areas.

Field : Computer Science or related field

Field : Information Technology or related field

30+ days ago
Related jobs
Promoted
Core & Main
St. Louis, Missouri

We are seeking a vigilant and proactive Information Security Analyst to join our team in safeguarding our organization's digital assets. You will play a critical role in monitoring, investigating, and responding to security alerts and incidents across various security platforms. Collaborate with IT ...

Promoted
VirtualVocations
St. Louis, Missouri

Key Responsibilities:Support Risk Management Framework (RMF) monitoring and accreditation/re-accreditation processCreate and maintain standard artifacts related to cybersecurity complianceAssist in the maintenance of security controls and vulnerability assessmentsRequired Qualifications:Minimum of 2...

Promoted
Safety National
St. Louis, Missouri

Your day-to-day responsibilities as an Information Security Risk Management Analyst will include assisting with IT risk management activities including some or all of: the entire IT risk lifecycle, security education and awareness, vulnerability management, third party risk management, policies and ...

Promoted
VirtualVocations
St. Louis, Missouri

A company is looking for an Information Security Analyst (Vulnerability Management Specialist). Key Responsibilities:Perform risk and vulnerability assessmentsAnalyze vulnerabilities and determine mitigation strategiesMaintain cyber defense assessment toolkit and prepare reports on findingsRequired ...

Envision, LLC
St. Louis, Missouri

Completion of one of the following recognized professional certifications: QSA (Qualified Security Assessor), CISM (Certified Information Security Manager), CISSP (Certified Information Systems Security Professional), SSCP (Systems Security Certified Practitioner), Certified Ethical Hacker (CEH...

Envision-TBS
St. Louis, Missouri

Completion of one of the following recognized professional certifications: QSA (Qualified Security Assessor), CISM (Certified Information Security Manager), CISSP (Certified Information Systems Security Professional), SSCP (Systems Security Certified Practitioner), Certified Ethical Hacker (CEH). Co...

Core and Main
Remote, Missouri, United States
Remote

Overview We are seeking a vigilant and proactive Information Security Analyst to join our team in safeguarding our organization's digital assets. You will play a critical role in monitoring, investigating, and responding to security alerts and incidents across various security platforms. Security Op...

Jobot
Hazelwood, Missouri

Information Security Engineer / Infosec Analyst Needed for Growing Inc. As a Cybersecurity Engineer / IT Security Analyst in our company, we are able to offer:. Infosec Engineer / Cybersecurity Analyst who is willing to work onsite 5 days a week!. As an IT Security Engineer / Cyber Security Engineer...

The Judge Group
St. Louis, Missouri

Completion of one of the following recognized professional certifications: QSA (Qualified Security Assessor), CISM (Certified Information Security Manager), CISSP (Certified Information Systems Security Professional), SSCP (Systems Security Certified Practitioner), Certified Ethical Hacker (CEH). We...

SSM Health
St. Louis, Missouri

Manages security of confidential information, assets and intellectual property, reviews all systems allowing access or attempted access to the network and ensures proper security controls are in place. Conducts regular information security risk assessment of security controls, programs and procedure...