Talent.com
Analysis Group
Information Security AnalystAnalysis Group • Boston, MA, US
Information Security Analyst

Information Security Analyst

Analysis Group • Boston, MA, US
30+ days ago
Job type
  • Full-time
Job description

Overview

Make an impact at Analysis Group, where we provide our clients with thoughtful, pragmatic solutions to their most challenging business and litigation problems. Analysis Group is one of the largest private economics consulting firms, with more than 1,200 professionals across 14 offices in North America, Europe, and Asia. Since 1981, we have provided expertise in economics, finance, health care analytics, and strategy to top law firms, Fortune Global 500 companies, and government agencies worldwide. Our internal experts, together with our network of affiliated experts from academia, industry, and government, offer our clients exceptional breadth and depth of expertise.

The Information Security Analyst will work with the Director of Information Security and Risk Management on the continuous improvement and development of the firm’s cybersecurity, compliance, and governance programs. As the Information Security Analyst, you are the organizing force responsible for providing oversight, coordination, and execution of the supporting activities for successful internal/external compliance and regulatory audits. This position will be responsible for collaborating with key stakeholders to ensure risks are managed effectively and efficiently in accordance with firm policies and applicable regulatory requirements.

Essential Job Function & Responsibilities:

  • Governance SupportManage the annual review process for policies, procedures, and standards.Develop and manage a security policy exception process.Develop and maintain Information Security and GRC metrics.Support the Information Security Steering Committee (ISSC) as needed.
  • GRC OperationsDevelop a solid foundation in Information Security GRC concepts and processes.Manage the selection, implementation, and operation of GRC tools.Automate the collection of control test and internal audit data with low-code tools.Drive continuous improvement of the InfoSec GRC program.
  • Risk Management SupportOrganize the Risk Management Committee (RMC) and coordinate risk management processes.Maintain the Risk Register.Manage the control test and reporting process.Develop and maintain risk management metrics, reports, and dashboards.Support control enhancement and/or gap remediation projects.
  • Compliance SupportDevelop a repeatable approach to managing NIST 800-53 and SOC 2 Type II audit requirements and testing procedures.Manage internal audit processes.Coordinate information security responses in support of external/third party audits.Manage Corrective Action Plans and/or Plan of Action & Milestones (POA&Ms).
  • Security Operations and ReportingMonitors, collects, and analyzes cybersecurity data and develops KPI and metrics reports.Performs vulnerability scans, conducts risk assessments, and oversees the vulnerability management remediation process.Perform cyber-security related tasks such as phishing analysis and access control reviews.
  • ISO 27001 Compliance:Proactively identify gaps or conflicts in existing policies and processes.Educate and train process/control owners to ensure understanding of the security controls framework and their responsibilities.Assist with and drive remediation of process and control deficiencies and gaps identified internally and externally.Assemble, organize, and implement applicable documentation (e.g. SOA, procedures).
  • Security Awareness and TrainingPartners with the stakeholders to improve security procedures, training, IT processes, and the security of existing systems.Manage phishing training campaigns and follow up / remedial training.Manage and support the effectiveness of the Data Security Awareness and Training program.

Qualifications:

  • Bachelor’s degree required. Degree in Information Systems Security or related field preferred.
  • Minimum of 2 years substantive relevant experience required.
  • An ideal candidate will have 2-5 years of experience in cybersecurity.
  • Knowledge of and experience in information security and monitoring systems.
  • Familiarity/comfort level working with IT Security software and hardware.
  • Strong writing / documentation / presentation skills.
  • Highly organized.
  • Strong communication skills.
  • Self-starter with the ability to work independently, while having good judgment as to when consultation is required.
  • Ability to work on multiple projects and perform well under deadlines.
  • Enthusiastic, flexible, willing to pitch in where needed.
  • Strong drive to learn and grow in the cyber security field.
  • Experience with control standards and frameworks such as FedRAMP, HIPAA, NIST 800-53, SOC 2, or ISO 27001. You have participated in various forms of internal controls review, testing, or internal audit.
  • Must be a natural collaborator, communicate effectively, and be flexible to changing business conditions.
  • An inclusive and growth-oriented mindset, strong interpersonal skills, and an ability to work across differences.
  • To the extent permitted by applicable law, eligible candidates must be authorized to work in the United States without sponsorship or restriction, now and in the future.

Analysis Group embraces diversity and equal opportunity in a deep and meaningful way. We are committed to building teams that represent a variety of backgrounds, perspectives, and skills. The more inclusive we are, the better our work will be.

We provide equal access and opportunities regardless of sex, sexual orientation, gender, gender identity, gender expression, age, religion, race, color, ethnicity, national origin, ancestry, mental and physical ability or disability, medical condition, genetic information, citizenship status, socioeconomic status, veteran and military status, or membership in any other class protected under applicable law. We encourage candidates of all backgrounds to apply.

­

  • Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities.
  • Please view Equal Employment Opportunity Posters provided by OFCCP .
  • The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor's legal duty to furnish information. 41 CFR 60-1.35(c)
Create a job alert for this search

Information Security Analyst • Boston, MA, US

Similar jobs

Senior SecOps Analyst: Incident Commander & Threat Hunter

AndurilBoston, Massachusetts, United States
Full-time

A defense technology company is seeking a Security Operations Analyst to monitor and respond to security incidents.You will manage alerts across various disciplines, develop detection automation, a... Show more

 • Promoted

Information Security Analyst

TradeJobsWorkForce02475 Arlington Heights, MA, US
Full-time

Monitor their organization’s networks for security breaches and investigate a violation when one occurs Install and use software, such as firewalls and data encryption programs, to protect sensitiv... Show more

 • Promoted

Information Security Manager

Franklin FitchBoston, MA, United States
Full-time

This role leads the firm’s Governance, Risk, and Compliance (GRC) program, including regulatory compliance, enterprise risk management, and audit assurance.It also owns Information Security AI gove... Show more

 • Promoted

Senior Information Security Manager for HPC & AI

ARMA InternationalCambridge, MA, United States
Full-time

A leading research computing consortium in Cambridge is seeking an Information Security Manager to lead security strategy and compliance for high-performance computing and AI infrastructure.The ide... Show more

 • Promoted

Business Analyst Security Master

The CERES GroupBoston, MA, United States
Full-time

Business Analyst Security Master.We are currently looking for a BA to work in our product team.This could be a contractor role or contract-hire.Target candidate: 5+ years financial services, solid ... Show more

 • Promoted

Remote Information Security Data Analyst | DLP & Analytics

Apex SystemsBoston, MA, United States
Remote
Full-time

A leading IT services provider is seeking an Information Security Data Analyst to focus on data protection and security analytics.This remote position includes responsibilities like monitoring data... Show more

 • Promoted

Manager Information Security

Akamai TechnologiesCambridge, MA, United States
Full-time

Do you relish the prospect of working with cutting‑edge web security platforms? Do you love collaborating with teams to solve complex problems? Join our global Information Security team.We are seek... Show more

 • Promoted

Information Security Manager

Center For Health Information And AnalysisBoston, MA, US
$100,000.00 yearly
Full-time
Quick Apply

At the Center for Health Information and Analysis (CHIA), we serve as stewards of Massachusetts health data, employing multifaceted datasets and cutting-edge analytics to ensure transparency in our... Show more

Senior Information Security Architect for HPC & AI

Massachusetts Institute of TechnologyCambridge, MA, United States
Full-time

A prestigious academic institution in Massachusetts is seeking an INFORMATION SECURITY MANAGER to take charge of security leadership across the Massachusetts Green High Performance Computing Center... Show more

 • Promoted

Senior Information Security Manager for HPC & AI

ISACACambridge, MA, United States
Full-time

A leading tech organization is seeking an Information Security Manager to oversee security strategy within the AI Computing Resource and the Massachusetts Green High Performance Computing Center.Th... Show more

 • Promoted

Federal Information Security Training Specialist (*ISSM experience req'd) - 1 yr contract, 100%[...]

Jobot ConsultingBoston, MA, United States
Full-time

Federal Information Security Training Specialist (*ISSM experience req'd) - 1 yr contract, 100% REMOTE.Looking for an Information Security Training Coordinator with a well-known and well-establishe... Show more

 • Promoted

Cyber Security Operations Center (CSOC) Analyst – Tier 3

AthenahealthBoston, MA, United States
Full-time

Boomband is working directly with Athenahealth to connect them with people who are a strong fit for this role.Senior Incident Responder (Incident Response, Forensics, InfoSec).This is a highly tech... Show more

 • Promoted

Information System Security Manager 2

Draper LabsCambridge, MA, United States
Full-time

Draper is an independent, nonprofit research and development company headquartered in Cambridge, MA.The 2,000+ employees of Draper tackle important national challenges with a promise of delivering ... Show more

 • Promoted

M4-14Lead Security Analyst 141809

FHREast Boston, MA, US
Full-time
Quick Apply

Our direct client has a new opening for a Lead Security Analyst 141809.This job is 14 months to start, and the client is located in Augusta, ME.Please send your rate and resume.Regulatory compli... Show more

CISO: Strategic Information Security Leader

SHIBoston, MA, United States
Full-time

A global IT solutions provider in Boston is seeking a Chief Information Security Officer.The CISO will develop and implement a comprehensive information security strategy while managing incident re... Show more

 • Promoted

Information Security Data Analyst

Apex SystemsBoston, MA, United States
Full-time +1

Information Security Data Analyst.Strong potential for extension / full time hire.Our client in the banking industry is seeking a Data Analyst to join the Information Security & Risk team.This role... Show more

 • Promoted

Information Security Manager

Massachusetts Institute of Technology (MIT)Cambridge, MA, United States
Full-time

INFORMATION SECURITY MANAGER, The Massachusetts Green High Performance Computing Center (MGHPCC), to serve as the primary security leader across MGHPCC and the AI Computing Resource (AICR) at the h... Show more

 • Promoted

Information Security Manager

ISACACambridge, MA, United States
Full-time

The Massachusetts Green High Performance Computing Center (MGHPCC), to serve as the primary security leader across MGHPCC and the AI Computing Resource (AICR) at the heart of the Massachusetts AI H... Show more