NOTE: Top three skill sets:
1. Application security best practices
2. Third Party risk management
3. Excellent documentation/note taking
This position will be part of the Cybersecurity department, which is responsible for assuring that security principles and company security policies are adhered to in the design and delivery of systems and software. The Cybersecurity Analyst is responsible for leading a coordinated effort to assess and audit applications, internally and externally. This role will also coordinate penetration tests and third party cybersecurity assessments.
Assess applications with the designated IT and Business owners to meet security requirements, internally and externally, following the documented Application Security Assessment (ASA) process
Manage and organize the documentation for ASAs
Set up and lead meetings between the Business and IT owners to conduct interviews for ASAs
Gather evidence for applications based on ASA control measures, third party assessments and penetration tests
Coordinate penetration tests for applications and ensuring that identified findings are remediated prior to approval/launch
Ensure known vulnerabilities are identified and documented for application
Perform and/or supporting cybersecurity assessments of third parties that are a part of applications through the review of third-party cybersecurity questions, participation in third party interviews, and review of third party documentation
Manage assessment activities and associated timelines persuant to both business and IT need in an urgent but business-like manner
REQUIREMENTS
5+ years of professional experience in information technology, with at least 2 years of experience directly in a Cybersecurity role
Broad understanding of computer networking, technology, and customer service with a security focus
Understanding of common web application security concepts, such as the OWASP Top 10, and their practical implementation
Experience with industry cybersecurity frameworks (e.g. NIST 800-53 or equivalent)
Operational knowledge and skills related to conducting industry standard application security assessments
Experience gathering evidence to verify cybersecurity control implementation
Strong verbal and written communications skills, with an ability to express complex technical concepts in business terms to multiple different audiences
Ability to inform, educate and influence business and IT employees to support goals and initiatives of the Cybersecurity department
Analytical and conceptual thinking - using logic and reason, creative and strategic
Integration - joining people, processes or system
Excellent planning, organization, and time management skill
Ability to work independently with minimal supervision
Education
Bachelors Degree or a combination of formal education and work experience equaling a Bachelors Degree Required
Certifications:
Cybersecurity Certification (Certified Information Security System Professional (CISSP) certification or equivalent)
Equal Opportunity Employer/Veterans/Disabled
To read our Candidate Privacy Information Statement, which explains how we will use your information, please navigate to www.modis.com/en-us/candidate-privacy
The Company will consider qualified applicants with arrest and conviction records