Business Security Analyst

Point Solutions Group
Aurora, IL, US
Full-time

Job Description

Job Description

WHAT DOES THE ROLE ENTAIL?

The Information Security Office (ISO) is seeking a professional with information security, technology risk assessment, technology audit, or legal experience to join our team.

Business Security Analysts work within the ISO's Engagement team but are embedded within departments to evaluate and consult on information security and privacy risk of business drivers and technology.

This position will engage all levels of the business to identify risk and work with business leadership and the CISO to design and execute on remediation projects and build processes that will support the CAO's compliance with industry, legal, as well as policy, security, and privacy requirements.

This position is a senior-level analyst position due to experience required in building a program, strong interpersonal and documentation skills required, and preference for CAO experience.

WHAT ARE THE DAY TO DAY EXPECTATIONS?

  • You'll build the foundation for the Information Security Office's Engagement division. You'll drive adoption of good security hygiene practices by building strong business relationships, understanding the business risk and needs, collaborating with the business as a trusted subject matter expert to support them as they adopt innovative technologies.
  • You'll drive education and awareness for the business, industry, and our community through the development of training materials / content and delivery of training to staff as needed.
  • You will work with leadership and the CISO to develop metrics and reporting, as well as quarterly Customer Business Reviews (CBRs) to inform the business and ISO on program efficacy and effectiveness, as well as identify risks and solutions.
  • You will manage the open record requests and eDiscovery hold requests for the IT department and engage the CAO and business stakeholders to ensure successful response to requests.
  • You will work with leadership and the CISO in development and execution of their business strategies and roadmaps, identifying requisite security control requirements, forecasting implementation costs, TCO, ROI and the level of effort to implement and sustain.
  • You will perform security and privacy risk assessments of infrastructure and provide reporting of findings and recommendations for resolution.

You will track risk findings and support the team, Security Operations, Enterprise Infrastructure and Public Safety teams to properly address.

  • You will be the subject matter expert (SME) for security during internal and external audits, working with the CISO, Risk and Compliance, and leadership to ensure audit requests are fulfilled and findings addressed.
  • You will regularly engage the Security Operations, Enterprise Infrastructure and Enterprise Applications teams to resolve issues and be a champion of business change to ensure good security hygiene is foundational to everything you do.
  • The successful candidate will be able to translate legal and regulatory technical requirements into business language.
  • You will work alongside the Security Operations and Risk & Compliance divisions to ensure existing ISO platforms are deployed, tuned, and effective in meeting governance requirements.

You will be a key member in the design and implementation of security controls to meet this objective.

  • You will perform ongoing learning and research to identify new technology and ensure the ISO is prepared to address and secure those technologies.
  • You will be responsible for evaluating systems, policies, and processes to ensure compliance with the requirements and standards applicable to securing business.
  • Stay up to date with relevant legislation, industry standards, and best practices.
  • Respond to emergencies and other incidents as required and participate in investigations and remediation efforts.
  • You will support leadership as they develop technology strategy, including liaise with IT and ISO colleagues to help drive innovative change in technologies and processes, and ensure the architecture is developed with security-by-design methods to meet compliance and business requirements for confidentiality, availability, and integrity.
  • You will meet regularly with leadership to understand the department's needs and current and future needs.

MINIMUM QUALIFICATIONS

Education :

Bachelor's degree OR four (4) years of directly relatable experience OR a combination of both equal to four years.

Experience :

Required Experience and Skills

  • You will have an extensive background in information security.
  • Experience in regulatory compliance or legal practice.
  • Must be a self-starter and a life-long learner.
  • Must be a critical thinker who believes security can be an enabler of business.
  • Well-developed interpersonal and communication skills.
  • Conflict resolution skills.
  • Strong documentation skills
  • Strong communication skills
  • Excellent analytical, problem-solving, and decision-making skills.

Preferred Experience and Skills

  • You will preferably have prior experience performing security for a law firm or other legal organization.
  • Prior experience using Microsoft Purview.
  • eDiscovery experience
  • Risk assessment experience.
  • Knowledge of cloud-based technology
  • Experience in IT audit
  • Experience in technical writing and / or report writing.

Knowledge :

All ISO employees are expected to maintain currency in security practices, technology, and trends. The ISO provides continuing education assistance to its staff to maintain licensure and learning.

Licenses Or Certificates Required :

  • You will have, or obtain within your first six months, an applicable security certification such as CISSP, CISA, Security+, or comparable.
  • Valid Colorado Driver's License.
  • 26 days ago
Related jobs
Promoted
Point Solutions Group
Aurora, Illinois

Business Security Analysts work within the ISO's Engagement team but are embedded within departments to evaluate and consult on information security and privacy risk of business drivers and technology. You'll drive adoption of good security hygiene practices by building strong business relat...

Promoted
VILLA-TECH INC.
Naperville, Illinois

We are looking for an Information Security Analyst to join our team. Information Security Analyst Qualifications:. ...

Promoted
PersonalizationMall.com
Bolingbrook, Illinois

This QC Compliance Analyst is product focused and will work closely with our Product Development team for PersonalizationMall. Oversee new product samples with Product Development Team, to identify any potential compliance issues and provide recommendations. CPSC, for product safety testing and comp...

Promoted
Simplify Healthcare
Aurora, Illinois

Location: Aurora, IL (not a remote position).Demonstrate healthcare knowledge.Develop product knowledge and get certified.Work with technical teams on User Stories as needed.Identify issues, structures, and conduct necessary analysis of large sets of data from which to draw conclusions.Perform resea...

Promoted
MagickWoods Limited
Aurora, Illinois

The Business Process Analyst is responsible for identifying and addressing inefficiencies in organizational processes. The analyst will utilize process mapping, data collection and analysis, and performance metrics to recommend and implement process enhancements. Document existing business processes...

Promoted
VC5 Consulting
Carol Stream, Illinois

If youre ready to leverage your expertise to drive meaningful change in a dynamic environment, apply now to join our team as a Business Systems Analyst. Your primary focus will be understanding business operations and crafting tailored system solutions to enhance efficiency. Drive the delivery of so...

Promoted
Publicis Groupe
West Chicago, Illinois

Collaborate with internal and external stakeholders to manage data logistics - including data transfers, understanding data structures, business rules, etc. The Analytic Consulting Group partners with internal and external clients and data providers, leveraging predictive analytics and advanced stat...

Promoted
SynergisticIT
Aurora, Illinois
Remote

More than 2 years of data analysis experience. ...

WALGREENS
IL, United States

Multi-Domain Proficiency: Demonstrate expertise in multiple information security domains, including but not limited to network security, application security, cloud security, and data protection. Be a key player in our Information Security team as a Remediation Analyst, focused on strengthening our ...

Vogrinc & Short, Inc.
Aurora, Illinois

As a Business Analyst, you will play a crucial role in analyzing business processes, identifying opportunities for improvement, assisting in implementing SAP, and implementing solutions to enhance operational efficiency. We are currently seeking a Business Analyst to join our team in a dynamic and f...