Jobs and Careers
BO
Senior Information Security Analyst
Boys TownNational Headquarters - 14100 Crawford Street, United States, United Statesfull_timeVerifiedPosted 19 Dec 2024
About the role
Boys Town is Changing the way America cares for children and families. We are seeking an experienced and dedicated individual to join our Information Security team as a Sr. Information Security Analyst (GRC). The individual selected for this role must have experience with governance, risk and compliance concepts and processes and a background in Information Technology and /or Cyber Security, proven ability to work across the enterprise with various business units and leadership to provide proper guidance and expertise.
MAJOR RESPONSIBILTIIES & DUTIES:
Develops, implements, and executes projects and operations to ensure organizational information security.
Evaluates information security risk, identifies physical, technical, and administrative security control gaps, and works with stakeholders to prioritize remediation and document risk management decisions.
Leads major GRC projects that are complex and enterprise-wide with complete authority over assigned projects and tasks under the purview of information security.
Advises organizational business units on security controls and practices to ensure information security requirements are considered at all lifecycle stages and addressed appropriately, with authority to establish mandatory requirements based on existing policy.
Monitors vendor risk and cloud security dashboards and works with internal and external stakeholders to prioritize risk remediation and documentation of risk management decisions.
Prepares and submits formal documentation for regulatory compliance obligations, including completion of security assessment questionnaires and attestations of compliance.
Works with IT, Legal, and Security Operations to administer the information security major incident response program, including design and documentation of all tasks associated with preparation, detection, analysis, containment, eradication, recovery, and lessons learned.
Assists IT, Security Operations, and GRC staff in drafting recommended policies, procedures, standards, guidelines, and enterprise-wide communications.
Maintains up-to-date knowledge of latest security risks and industry trends.
Builds and maintains close working relationships with all levels of IT, Compliance, Internal Audit, and operational business units to collaborate on projects and operations to enhance security.
Supports the Manager Information Security GRC in covering management-level work tasks, meetings, and providing continuity when the Manager is unavailable, with full authority to perform tasks and make decisions when delegated management-level activities.
KNOWLEDGE, SKILLS, AND ABILITIES:
Adherence to the Information Security Department’s values of integrity, excellence, mission-focused, risk-based, and data-driven.
Strong knowledge and experience with information security governance, risk management, and compliance, including relevant cybersecurity frameworks (NIST RMF, CSF) and applicable regulations (COPPA, FERPA, FISMA, HIPAA, PCI-DSS).
Ability to independently manage security projects and operations across departments in a large organization with minimal guidance and direction from leadership.
Strong interpersonal skills, including ability to negotiate and mediate professional disagreements while maintaining a positive, empathetic, and calm demeanor.
Ability to interpret customer requirements into technical solutions and communicate technical information effectively to non-technical staff.
Ability to effectively communicate legal, regulatory, contractual, and proprietary security requirements to technical and non-technical staff at all levels of the organization.
Solid understanding of IT and information security principles and concepts, including cloud and on-premises infrastructure, desktop and server computing environments, physical and virtual machines, mobile devices, Internet of Things, industrial control systems, software and applications, and emerging technologies.
Excellent critical thinking skills and ability to adapt to changing situations.
Ability to teach and mentor GRC team members as a senior-level role model.
REQUIRED QUALIFICATIONS:
Bachelor’s degree in Cybersecurity, Information Security, Information Assurance, related field, or equivalent combination of education and experience required.
Minimum of 5 years of experience with increasing responsibility in information security, risk management, and systems analysis required.
On-call (continuously or rotationally) to provide support re
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s
Similar roles
Senior Sales Representative
Southern National Roofing
Greenville
$200,000/yr
Senior Human Resource Generalist
Conagra Brands
Archbold OH, United States
$118,000/yr
Senior Superintendent (Water/Wastewater)
Clark Construction Group
21079W3 - Loudoun Water - Milestone Reservoir Raw & Pump Station Process Mechanical, United States