IT Security Analyst
Gentex CorporationAbout the role
Description
PURPOSE:
We are seeking an experienced IT Security Analyst with a strong focus on Cybersecurity Maturity Model Certification (CMMC) compliance and ITIL best practices. The ideal candidate will be responsible for enhancing the security posture of our organization, ensuring compliance with CMMC requirements, and integrating ITIL methodologies into our IT service management processes.
Our IT Security Analyst will focus on achieving and maintaining security audit requirements as well as working within the IT and cross-functional teams to refine ITIL best practices within our IT service management processes. The position will also work collaboratively with user groups to optimize manufacturing processes by evaluating and integrating IT solutions. However, much of this role will be focused on the following areas:
· CMMC Compliance:
o Develop, implement, and manage policies and procedures to ensure compliance with CMMC standards.
o Conduct risk assessments and security audits to identify vulnerabilities and gaps in compliance.
o Collaborate with teams to implement necessary security controls and practices aligned with CMMC levels.
· IT Security Management:
o Monitor network security and respond to incidents to mitigate risks effectively.
o Implement and maintain security tools and technologies (e.g., firewalls, intrusion detection/prevention systems).
o Conduct regular security training and awareness programs for staff.
· ITIL Integration:
o Apply ITIL best practices to improve IT service management and security processes.
o Collaborate with service management teams to ensure security is integrated into the service lifecycle.
o Contribute to continual service improvement initiatives, focusing on enhancing security measures.
· Documentation and Reporting:
o Maintain comprehensive documentation of security policies, procedures, and compliance activities.
o Generate reports for management on security metrics, compliance status, and incident response efforts.
· Collaboration:
o Work with cross-functional teams to ensure security requirements are integrated into project planning and execution.
o Liaise with external auditors and assessors during compliance audits.
The IT security analyst will act as an IT security ambassador to cross-functional teams through comprehensive status reporting, developing risk assessments, and executing upon project plans and priorities.
DUTIES, RESPONSIBILITIES, ESSENTIAL FUNCTIONS:
- Monitor Security Events: Continuously monitor network traffic, security logs, and alerts from various tools (e.g., firewalls, SIEM systems) to detect suspicious activities.
- Incident Detection: Identify and investigate potential security incidents, such as unauthorized access, malware infections, or data breaches.
- Incident Response: Respond to security incidents in real-time, containing the threat, mitigating damages, and ensuring proper recovery of systems.
- Reporting Security Incidents: Document incidents thoroughly, including the nature of the attack, remediation steps taken, and any potential vulnerabilities exploited.
- Conduct Security Assessments: Perform regular vulnerability scans and assessments to identify weaknesses in systems, networks, and applications.
- Penetration Testing: Perform or oversee penetration testing to simulate attacks and uncover potential security gaps.
- Evaluate Security Risks: Analyze the risk level associated with different vulnerabilities and provide recommendations for mitigating risks.
- Develop and Update Risk Management Plans: Collaborate with management to ensure that risk management plans are in place and regularly updated based on new risks or vulnerabilities.
- Develop Security Policies: Help develop and enforce security policies, standards, and best practices for the organization (e.g., password policies, data protection protocols).
- Monitor Access Controls: Manage access control systems, ensuring that only authorized personnel can access sensitive data and systems.
- Deploy and Maintain Security Tools: Configure and manage security tools such as firewalls, antivirus software, intrusion detection/prevention systems (IDS/IPS), and data loss prevention (DLP) tools.
- SIEM Systems Management: Oversee Security Information and Event Management (SIEM) systems to correlate logs and generate alerts for potential threats.
- Encryption and Data Protection: Implement encryption technologies to safeguard data, both at rest and in transit.
- Conduct Security Audits: Perform regular audits of systems and networks to ensure compliance with security standards and identify any areas
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s