Senior IT Security Analyst Job at World Vision USA
Join World Vision as a Senior IT Security Analyst on the Digital Team.
00 At a Glance
Role: Senior IT Security Analyst, Digital Team
Reports to: Executive Director, Chief Information Security & Privacy Officer
Required Experience: Bachelor's degree in information systems or related field strongly preferred. Five to seven years of relevant technical work experience. Experience must include a minimum of two years with IT security. Requires in-depth knowledge and experience with multiple enterprise applications. CISSP certification strongly recommended. Read more below in Section 03.
Location: Remote.The role can be based in any of these 39 states.
Salary Range: $80,000 - $128,000. Applies to locations with a market similar to our U.S. HQ in the Greater Seattle area. A different range may apply based on your work location. Typical hiring range is $85,000 - $104,000/year. Job offers within the range are based on relevant job qualifications and pay equity. See Salary Range & Benefits section below for more details on our compensation and benefits. World Vision employees see our Salary Administration Guidelines and My Life My Benefits pages on our organization intranet known as The Vine.
01 The Job
The Senior IT Security Analyst role is a highly technical role on the information security and data privacy team of six. You will work alongside another Senior IT Security Analyst to inform World Vision’s security technology roadmaps and will engage with business leaders to assess and mitigate cyber security risks to their lines of business, including third-party vendors. You will also have a hands-on role in World Vision’s detection and response capabilities to protect World Vision’s ministry to vulnerable children and communities around the world. If you’re looking for an opportunity to work remotely, use your professional talents on a diverse team, and make a bigger impact for God’s Kingdom, this might just be your calling!
Job responsibilities include:
- Keep Christ central in individual and corporate life. Actively participate in and contribute to the spiritual disciplines of the organization (Christian conduct, devotions, chapel, prayer, worship); incorporate WV Core Values into decisions within scope of role.
- Strategy:
- Provide strategic and tactical direction and consultation on security and IT compliance.
- Business Requirements:
- Engage directly with the business to gather a full understanding of project scope and business requirements.
- Work with customers to identify security requirements using methods that may include risk and business impact assessments.
- Consult with other business and technical staff on potential business impact of proposed changes to the security environment.
- Provide security related guidance on business processes.
- Security Solutions:
- Work closely with IT and development teams to design secure infrastructure solutions and applications, facilitating the implementation of protective and mitigating controls.
- Identifies and when necessary, proposes variances to the architecture to accommodate project needs.
- Risk Assessments:
- Conduct business impact analysis to ensure resources are adequately protected with proper security measures.
- Work directly with the customers and other internal departments and organizations to facilitate IT risk analysis and risk management processes and to identify acceptable levels of residual risk.
- Review risk assessments, analyze the effectiveness of IT control activities, and reports on them with actionable recommendations.
- Assess potential items of risk and opportunities of vulnerability in the network and on information technology infrastructure and applications.
- Monitor risk mitigation and coordinates policy and controls to ensure that other managers are taking effective remediation steps.
- Manage the oversight of technical risk assessments, such as vulnerability scanning and penetration testing.
- Information/Data Security:
- Consult with clients on the data classification of their resources.
- Define, identify, and classify information assets.
- Assess threats and vulnerabilities regarding information assets and recommends the appropriate information security controls and measures.
- Develop and manage security measures for information systems to prevent security breaches.
- Manage project documentation (compliance documentation, security plans, risk assessment, corrective action plans, etc.)
- Security Support:
- Provide security support to ensure that security issues are addressed throughout the project life cycle.
- Provide responsive support for problems found during and after normal work hours.
- Lead and respond to security incidents and investigations and target reviews of suspect areas.
- Consult on teams to resolve issues that are uncovered by various internal and third party monitoring tools.
- Communication Consulting:
- Collaborate on critical IT projects to ensure that security issues are addressed throughout the project life cycle.
- Inform stakeholders about compliance and security related issues and activities affecting the assigned area or project.
- Interface regularly with staff from the department communicating security issues and responding to requests for assistance and information.
- Report to management concerning residual risk, vulnerabilities and other security exposures, including misuse of information assets and noncompliance.
- Serve in an advisory role in application development projects to assess security requirements and controls and ensure that security controls are implemented as planned.
- Vendor Management:
- Work with third party vendors during problem resolutions.
- Interface with third party vendors to evaluate new security products or as a part of a security assessment process.
- Maintain contact with vendors regarding security systems updates and technical support of security products.
- Research/Evaluation:
- Lead and review application security risk assessments for new or updated internal or third-party applications.
- Evaluate and recommend hardware and software systems that provide security functions.
- Coaching/Mentoring:
- Provide technical leadership, coaching/mentoring to team and department members.
- Training:
- Provide communication and training as needed.
- Develop security awareness and compliance training programs.
- Provide security briefings to advise on critical issues that may affect the client.
- Conduct knowledge transfer training sessions to security operations team upon technology implementation.
- Monitoring:
- Maintain, monitor and support monitoring applications in an Enterprise environment.
- Define procedures to monitor Enterprise applications and resolve problems.
- Provide SME level expertise on the monitoring system of record.
- Perform other duties as assigned.
- Maintain awareness of corporate goals, objectives, organizational announcements, and activities. Reference and follow organizational policies and procedures, seeking clarity as needed.
02 About World Vision USA When you work at World Vision, your passions and talents come together to meet the greatest needs in the world today. As a global Christian humanitarian organization, we partner with children, families, and their communities to reach their full potential by tackling the causes of poverty and injustice. We're Christian and follow Jesus' example to show unconditional love to the poor and oppressed. Serving every child we can regardless of faith. Are you feeling called to explore joining us? We hope so.
03 You Bring Bachelor's degree in information systems or related field strongly preferred. Five to seven years of relevant technical work experience. Experience must include a minimum of two years with IT security. Requires in-depth knowledge and experience with multiple enterprise applications. CISSP certification strongly recommended.
Additional Skills we’d like to see include:
- Administrative background and experience in two or more of the following domains: Client, Network (Cisco), Server, Cloud, API.
- We’re mainly a Microsoft shop. We use Microsoft Azure, Microsoft Intune, Windows 10, Windows Server and advanced Microsoft Defender security solutions. We do have a material number of MacOS and iPad/iOS devices.
- Most of our systems and data have been migrated to the cloud and most of our workforce works remotely. Cloud security is essential.
- We currently work with a third-party MSSP but will be transitioning to an MDR/XDR provider based in the next 6 months.
- NIST Core Security Framework and CIS benchmarks and controls
- Business Impact Analysis
- Quantitative and Qualitative Risk Analysis
- Third-party Risk Management
04 Let your work be your faith in action Every day, nearly 16,000 children under the age of 5 die from preventable causes. Our call to action is urgent. That’s why we’re looking for someone who is ready to place their expertise in IT toward helping the world’s most vulnerable children.
05 Salary Range & Benefits Your compensation and benefits are important to you so they’re important to us. The full range for this position is $80,000 - $120,000. This applies to locations with a market similar to our U.S. HQ in the Greater Seattle area. A different range may apply based on your work location. Typical hiring range is $85,000 - $104,000. Job offers within the range are based on relevant job qualifications and pay equity. World Vision employees see our Salary Administration Guidelines and My Life My Benefits pages on our organization intranet known as The Vine. Please indicate the range you're targeting when asked during the application process. In addition, we have a robust and comprehensive benefits package to round out our total compensation package. Click here to learn more. Additionally, merit, auto allowance, and relocation may be available to eligible employees based on existing plans.
06 To Apply Press the orange apply button on this page. Still not sure? We’d really like to hear from you, even if it’s just to ask a question about the job. Email Melissa DiFrancesco in Talent Acquisition at mdifrancesco@worldvision.org.
07 What happens next? Short-listed candidates are contacted for an initial phone conversation with our recruiting staff. Moving deeper into our selection process, candidates can expect to participate in two additional panel interviews with members and leaders on the Digital Team.
Required Skills
Required Experience
Please Note :
www.bankofmontserrat.ms is the go-to platform for job seekers looking for the best job postings from around the web. With a focus on quality, the platform guarantees that all job postings are from reliable sources and are up-to-date. It also offers a variety of tools to help users find the perfect job for them, such as searching by location and filtering by industry. Furthermore, www.bankofmontserrat.ms provides helpful resources like resume tips and career advice to give job seekers an edge in their search. With its commitment to quality and user-friendliness, Site.com is the ideal place to find your next job.