Hiring.Camp

Senior Cybersecurity Analyst

SRPMIC

·

Yesterday

Salary
$116k – $165k/yr
Location
Scottsdale, AZ, AZ, US
Type
Full-time
Department
IT
Seniority
Senior
Source
GovernmentJobs

Description

Under general supervision of the Cyber Security Manager, assumes responsibility for the implementation and maintenance of security processes and technology improvements in support of the organization’s Cyber security Strategic Plan.  Works cohesively with the IT teams and divisions to conduct risk assessments, administer and audit security systems.  As a member of the security team develops, implements and maintains security architecture design as well as maintains the technologies and processes that support continuous security improvements.  This job class is treated as FLSA Exempt.

Essential Functions:  Essential functions may vary among positions and may include the following tasks and other characteristics.  This list of tasks is ILLUSTRATIVE ONLY and is not intended to be comprehensive listing of tasks performed by all positions in this classification.1. Mentoring, Supervision & Leadership:   Mentors security team staff so they attain the technical skills and customer service skills along with experience necessary to perform independently and attain further career progression goals.
    • Ensures cross-functional training of staff to ensure that primary and secondary support personnel are properly trained to support division services.
    • Assists with the routine supervision of assigned staff.        Prioritizes and coordinates staff workflow and provides training and assistance as needed.
    • Helps establish criteria for employee performance evaluations based on division and department goals and objectives.
    • Helps prioritize and coordinate staff workflow and provides training and assistance as needed.
    • Provides senior leadership to the Security Team staff and works closely with other IT divisions to establish and enforce IT standards.  Evaluates and recommends best in class standards and processes.
2. Security Team Member:   Participates as a key member of the security team in setting organizational security direction.
    • Contributes knowledge of security best practices and technical skills.  Utilizes problem-solving techniques during security planning, implementation and incident response activities.
    • Assumes responsibility for protecting all confidential information discussed, documented or otherwise provided in the course of security events.
3. Network Security Support:  Proactively audits and reviews the network and security infrastructure.
    • Ensures that scheduled maintenance, patching and performance is monitoring and managed.
    • Monitors LAN/WAN, network, security firewalls, routers and systems to ensure security standards are maintained.
    • Provides operational reporting that effectively communicates the security posture of the SRPMIC organization.
    • Provides technical input and assistance to troubleshoot security issues.
4. Cloud Security:  Develops and maintains cloud security standards, controls, and processes to ensure the confidentiality, integrity, and availability of organizational systems and data hosted in cloud environments.
    • Performs security assessments of cloud infrastructure, services, architectures, and configurations to identify and mitigate security risks. 
    • Provides cybersecurity SME support for cloud migrations, implementations, and technology initiatives. 
    • Establishes and maintains cloud security standards, configuration baselines, and best practices aligned with the organization’s adopted security framework. 
    • Monitors cloud environments for security threats, vulnerabilities, misconfigurations, and anomalous activity and coordinates remediation efforts. 
    • Partners with IT and business stakeholders to implement appropriate controls for identity and access management, logging and monitoring, encryption, network security, and data protection. 
    • Provides reporting and metrics regarding the security posture and risk of organizational cloud environments.
5. Artificial Intelligence Security:  Provides cybersecurity leadership and subject matter expertise for the secure adoption, implementation, and use of artificial intelligence technologies throughout the organization.
    • Develops and maintains security standards, policies, and guidelines governing the secure and responsible use of AI technologies. 
    • Performs security and risk assessments of AI solutions, applications, platforms, and third-party AI services. 
    • Identifies and evaluates AI-related security risks, including data exposure, unauthorized access, insecure integrations, prompt injection, data poisoning, model misuse, and third-party risks. 
    • Evaluates AI vendors and services to ensure security, privacy, data protection, and contractual requirements are appropriately addressed. 
    • Monitors emerging AI security threats, vulnerabilities, regulatory requirements, and industry best practices and recommends appropriate security controls. 
    • Provides cybersecurity SME support for AI-related projects, audits, vendor reviews, incident investigations, and organizational AI governance initiatives.
6. Security Risk Assessments:  Develops and implements security, technology and assessments based on the organization’s selected security framework.
    • Develops and maintains adopted security standards and industry best practices.
    • Works closely with internal stakeholders and security leadership to build and maintain an effective security program to protect the confidentiality, integrity and availability of IT assets to help mitigate overall organizational risks.
7. Investigation Support:  Responds to security breaches or personnel investigation requests.
    • Ensures accurate data capture, chain of custody and reporting for an incident or investigation.
    • Provides leadership, consultation or technical support.
    • Maintains confidentiality and integrity of systems, data and security processes.
8. Project Coordinator and SME
    • Fulfills all duties as the Cyber Security subject matter expert in support of IT and external departmental projects.
    • Fulfills all duties as the Cyber Security subject matter expert in support of 3rd part audit engagements.
    • Leads Cyber Security team projects and initiatives to include security tool integrations, tool evaluations, and process improvements.
9.  Audit and Compliance
    • Participates in audit reviews.
    • Participates and fulfils a lead role in security penetration activities and the coordination of mitigation and remediation efforts.
10. Other Duties as Assigned:   Performs other job-related tasks as assigned by the Cyber Security Manager, IT Assistant Director – Enterprise Architecture, Custom Development & Cyber Security, or IT Director/CIO.

Knowledge, Skills, Abilities and Other Characteristics:
  • Ability to assess security vulnerabilities at the system and/or network level.
  • Ability to coordinate vulnerability mitigation efforts across multiple teams 
  • Ability to assess and document risk related to third party system and/or software integrations 
  • Ability to manage and leverage security tools to reduce organizational risk
  • Ability to lead and coordinate team level projects and programs with little to no oversight 
  • Ability to work independently and make well informed decisions based on experience and data gathering
  • Ability to assess cloud environments for security vulnerabilities, misconfigurations, and compliance risks. 
  • Ability to evaluate cloud architectures and services for adherence to organizational security standards and industry best practices
  • Ability to assess security risks associated with cloud migrations, integrations, and implementations. 
  • Ability to assess cybersecurity and data protection risks associated with the implementation and use of artificial intelligence technologies
  • Ability to evaluate AI solutions, applications, and third-party AI services for security risks and compliance requirements
  • Knowledge of the Elastic Stack and the ability to leveraging multiple log sources to identify security risk and/or compromise
  • Knowledge of secure protocols and how, when, and where they should be implemented 
  • Knowledge of Microsoft 365 Cloud security suites to include:  365 Defender, Purview/Compliance, Azure, Defender for Cloud, and Microsoft Entra ID 
  • Knowledge of AI security risks including data exposure, unauthorized access, prompt injection, data poisoning, model misuse, insecure integrations, and third-party AI risks
  • Knowledge of AI governance, risk management, data protection, and responsible AI principles.
  • Knowledge of industry regulations and data classification standards i.e.: HIPAA, PCI, PII, PHI and FERPA
  • Knowledge of CIS, NIST and FedRamp controls/standards.
  • Knowledge of firewall rules and audits  
  • Skilled at providing outstanding internal and external customer service.
  • Skilled at interfacing at all staff levels and providing effective verbal and written communication.
  • Skilled at verbal & written communication.
  • Skilled at defining issues, analyzing and evaluating information, presenting recommendations and identifying alternative solutions.
  • Ability to work effectively across and within diverse teams.
  • Ability to effectively manage simultaneous security issues.
  • Highly self-motivated and directed combined with extensive experience working in a collaborative, team-oriented environment.
Education:   A Bachelor’s degree from an accredited college or university in Information Security, Cyber Security or related discipline. Maybe accept a combination of 7 years direct cyber security experience and industry certifications in lieu of degree.  


Experience:
  • Five (5) years’ experience with the following:
    • Direct experience working within an IT/Cyber security role. Hands-on experience implementing network security, security monitoring, cloud security monitoring, or vulnerability management. 
    • Direct experience supporting Microsoft 365 Cloud security.
    • Direct experience assessing, evaluating, or supporting the secure implementation and use of artificial intelligence technologies, including identification and mitigation of AI-related cybersecurity and data protection risks. 
    • Direct experience with the Elastic log management platform. 
    • Direct experience supporting cyber security incident response. 
    • Direct experience managing and/or mitigating software and system vulnerabilities. 
    • Direct experience conducting security audits to include access control and system configuration. 
    • Direct experience conducting security assessment on 3rd party integrations.  
    • Direct experience with secure remote access technologies.
  • One of the following certifications is required:
    • CompTIA Security +
    • Systems Security Certified Practitioner (SSCP®)
    • Certified Information Systems Security Professional (CISSP)
  • Two of the following certifications is preferred:
    • CompTIA Security +
    • Systems Security Certified Practitioner (SSCP®)
    • Certified Information Systems Security Professional (CISSP) 
    • Certified Cloud Security Professional (CCSP)
    • Certified Information Security Manager (CISM)
    • SANS Global Information Assurance Certifications (GIAC)
    • Certified Ethical Hacker (CEH)
    • Microsoft Azure Security Engineer Associate AZ-500
    • Microsoft Cloud and AI Security Engineer Associate SC-500


    Equivalency: Any equivalent combination of education and/or experience that would allow the candidate to satisfactorily perform the duties of this position, will be considered.


    Underfill Eligibility: An enrolled Community Member whom closely qualifies for the minimum qualifications for a position may be considered for employment under SRPMIC Policy 2-19, Underfill.
    • May be required to work beyond normal work hours including nights, weekends and holidays.
    • May be required to complete and Salt River Police Department (SRPD) background investigation and polygraph examination.
    • May be required to receive and maintain a Salt River Pima-Maricopa Indian Community, Community Regulatory License, and State Certification (ADOG). All applicants applying for jobs will be subject to Pre-Employment Drug Test and extensive Fingerprint and Background Check. In addition, all employees providing services to a campus with children will be subject to the “Community Code of Ordinances”, Chapter 11 “Minors”, Article X. “Investigation of Persons Working with Children”, random drug testing and completion of a background check every five (5) years.

    Prior to hire as an employee, applicants will be subject to drug and alcohol testing. Will be required to pass a pre-employment background/fingerprint check. 

    "SRPMIC is an Equal Opportunity/Affirmative Action Employer" Preference will be given to a qualified: Community Member Veteran, Community Member, Spouse of Community Member, qualified Native American, and then other qualified candidate.

    In order to obtain preference, the following is required: 1) Qualified Community Member Veteran (DD-214) will be required at the time of application submission 2) Qualified Community Member (must provide Tribal I.D at time of application submission),3) Spouse of a Community Member (Marriage License/certificate and spouse Tribal ID or CIB is required at time of application submission), and 4) Native American (Tribal ID or CIB required at time of application submission).

    Documents may be submitted by one of the following methods: 

    1) attach to application

    2) fax (480) 362-5860

    3) mail or hand deliver to Human Resources.

    4.) email to [email protected]

    Documentation must be received by position closing date. 

    The IHS/BIA Form-4432 is not accepted. 

    Your Tribal ID/CIB must be submitted to HR-Recruitment-Two Waters.

    Skills

    AzureCybersecurityRisk ManagementComplianceCustomer ServiceHIPAACISSPCompTIA

    Similar Jobs

    30

    Sr Cybersecurity Analyst

    Target·Bangalore, India

    1w ago

    Senior Cybersecurity Analyst

    Triumf·TRIUMF, Canada

    2w ago

    Senior Cybersecurity Analyst

    relay·Raleigh, NC +1

    3w ago

    Sr. Analyst, Cybersecurity

    Nexgen Sports Group Inc·Orlando, FL

    3w ago

    Senior Cybersecurity Analyst

    Leidos·2019 DISA HQ Fort George G. Meade MD, US

    4w ago

    Senior Cybersecurity Analyst

    ISO New England Inc.·ISO New England Inc., One Sullivan Road

    4w ago

    Senior Analyst - Cybersecurity

    Freshworks CRM·Chennai, India

    1mo ago

    Cybersecurity Analyst Senior

    Basecamp·Minnesota - Minneapolis, US·Hybrid

    1mo ago

    CyberSecurity Senior Analyst

    Nelnet as the nation·Centennial, CO

    2mo ago

    Sr Cybersecurity Analyst

    Dexcom·Bengaluru, KA

    3mo ago

    Sr Cybersecurity Analyst

    Dexcom·Bengaluru, India

    3mo ago

    Cybersecurity Analyst, Senior

    Cook Children's·Rosedale Office Building, US

    3mo ago

    Senior Cybersecurity Analyst

    Cyberphore·New Westminster, British Columbia

    10mo ago

    Sr Analyst-Cybersecurity

    Ascension1 Ascension·Remote, US·Remote

    1y+ ago

    Sr Principal Classified Cybersecurity Analyst - Top Secret

    Northrop Grumman·Redondo Beach, CA·Remote, Onsite

    1d ago

    Sr Principal Classified Cybersecurity Analyst - Top Secret

    Northrop Grumman·CARBR11, US·Remote, Onsite

    1d ago

    Sr Cybersecurity Analyst - Cyber Threat Intelligence (CTI)

    Target·7000 Target Pkwy N, NCD-0375 Brooklyn Park·Remote

    1d ago

    Sr Principal Classified Cybersecurity Analyst - Top Secret

    Northrop Grumman·COCO07, US·Onsite

    2d ago

    Sr Principal Classified Cybersecurity Analyst - Top Secret

    Northrop Grumman·Colorado Springs, CO·Onsite

    2d ago

    Cybersecurity Senior Incident Response Analyst - Remote based in the US

    Facility 238 - Conifer Revenue Cycle Solutions·US·Remote

    2d ago

    Senior Software Analyst/Cybersecurity

    Gloucester County·Gloucester, VA

    3d ago

    Cybersecurity Senior Threat Analyst (Hybrid)

    Bancorpbank·Wilmington, DE·Hybrid

    3d ago

    Senior Associate - Cybersecurity Operations Analyst (L2)

    Pwc·Argentina AC Olivos +1

    3d ago

    Senior Third Party Risk (TPRM) Cybersecurity Analyst

    The Future of Health Starts with You·Cork, IRL - 3300 Cork Airport Business Pk·Hybrid

    4d ago

    Sr. Cybersecurity AI Compliance Analyst

    Marvell·US-CA - Santa Clara, US

    1w ago

    Senior Cybersecurity Analyst - (Cyber Defense Operations)

    Talan·Bucharest, Romania·Remote

    1w ago

    Senior Cybersecurity Analyst - (Cyber Defense Operations)

    Talan·Cairo, Cairo Governorate·Remote

    1w ago

    Senior Cybersecurity Analyst - (Cyber Defense Operations)

    Talan·Budapest, Hungary·Remote

    1w ago

    Senior Cybersecurity GRC Analyst (3 -4 years)

    Danaher·IND - Bangalore - Beckman Coulter India Private Limited·Onsite

    1w ago

    Senior Cybersecurity Analyst - (Cyber Defense Operations)

    Talan·València, VC·Remote

    1w ago