Global IT Senior Security Analyst
GLOBAL IT SENIOR SECURITY ANALYST
The Global IT Senior Security Analyst will work closely with the entire Global IT Team and all levels of management to ensure that cyber security services are provided as outlined. The role will also work closely with the Portfolio Management teams, partners and customers as needed. This role reports to the Global IT Security Manager and will be located in Glen Mills, PA.
Essential Job Functions
- Conduct internal, external and 3rd party IT audits, risk assessments, and vulnerability scans.
- Liaise with other governance functions such as physical Security/Facilities, Internal Audit, IT, HR, Legal, and Compliance.
- Respond to computer security incidents, in-depth computer and network investigations. Assist in or lead incident response to a successful completion.
- Oversee installation, upgrades, and configuration of Information Security software. Make sure issues are properly coordinated, tracked, monitored and resolved globally.
- Be an Information Security subject matter expert (SME) that's part of an information security center of excellence; offering internal management consultancy advice and practical assistance on information security risk and control matters.
- Drive for consistent deployment of information security policies, standards, procedures, guidelines and training.
- Assess Information Technology technical controls, policies and procedures for control gaps. Recommend and support deployment of mitigations design on business need and risk.
- Develop new and improve existing technical documentation.
- Work as a team player.
- Perform Security Risk Assessments, identifying gaps and recommending mitigating controls.
- Develop and present project related material (e.g. to key stakeholders, peers, etc.).
- Support an Application Security program working closely with the DevOps, application development and QA teams.
- Maintain documentation related to the Application Security program including the development of secure coding policies, procedures and standards, modification of the Software Development Life Cycle (SDLC) to include necessary security checkpoints, code review methodologies, etc.
- Pursue understanding of application security requirements early-on and incorporate into secure code development practices.
- Maintain knowledge of new security trends and technologies.
- Support the assessment and acquisition of application security tools and technologies.
- Attend design and application architectural reviews to establish expertise and assimilate knowledge of the environment.