Information Security Analyst
Reporting to the CISO (Chief Information Security Officer)
Salary - up to £35,000
Monday to Friday 08:45 to 17:00
Summary
Due to our continued success as one of the country's leading suppliers of heavy commercial vehicles we have a new and exciting opportunity for Security Analyst to join the team based at our Head Office in Milton Keynes.
Information Security analyst is a member of the information security team and works closely with the other members of the team to develop and implement a comprehensive information security.
Essential Duties and Job Responsibilities
- Works with Scanias business functions and with other risk functions to identify security requirements, using methods that may include risk and business impact assessments. Components of this activity include but are not limited to:
- Business system analysis.
- Communication, facilitation and consensus building.
- Assists in the coordination and completion of information security operations documentation.
- Works with information security leadership to develop strategies and plans to enforce security requirements and address identified risks.
- Reports to Scania s management concerning residual risk, vulnerabilities and other security exposures, including misuse of information assets and noncompliance.
- Plays an advisory role in application development or acquisition projects to assess security requirements and controls and to ensure that security controls are implemented as planned.
- Collaborates on critical IT projects to ensure that security issues are addressed throughout the project life cycle.
- Works with Scania s IT department and members of the information security team to identify, select and implement technical controls.
- Develops security processes and procedures and supports service-level agreements (SLAs) to ensure that security controls are managed and maintained.
- Advises security administrators on normal and exception-based processing of security authorization requests.
- Researches, evaluates and recommends information-security-related hardware and software, including developing business cases for security investments.
- Support business in order to comply with ISec Principles, Rules and Standards
- Making ISec an integrated part of daily operations and processes
- Support business in performing risk analysis by using approved corporate tools and methods
- As part of auditing and awareness campaigns travel will be required UK wide.
This job description provides an indication of the role and responsibilities but should not be construed as an exhaustive list of duties that the post holder may be asked to undertake.
Candidate Requirements
- Minimum of 2 years IT or network security experience.
- Bachelors degree in IT systems or equivalent work experience.
- In-depth knowledge and understanding of information risk concepts and principles, as a means of relating business needs to security controls.
- Knowledge of and experience in developing and documenting security architecture and plans, including strategic, tactical and project plans.
- Experience with common information security management frameworks, such as International Organization for Standardization (ISO) 2700x and the ITIL, COBIT and National Institute of Standards and Technology (NIST), GDPR frameworks.
- Knowledge of the fundamentals of project management, and experience with creating and managing project plans, including budgeting and resource allocation.
- In-depth knowledge of risk assessment methods and technologies.
- Proficiency in performing risk, business impact, control and vulnerability assessments.
- Strong understanding of business applications, including ERP and financial systems.
- Excellent technical knowledge of mainstream operating systems [for example, Microsoft Windows and Oracle Solaris] and a wide range of security technologies, such as network security appliances, identity and access management (IAM) systems, anti-malware solutions, automated policy compliance tools, and desktop security tools.
- Experience in developing, documenting and maintaining security policies, processes, procedures and standards.
- Knowledge of network infrastructure, including routers, switches, firewalls, and the associated network protocols and concepts.
- Audit, compliance or governance experience is preferred.
- Strong analytical skills to analyse security requirements and relate them to appropriate security controls.
- Ability to interact with Scanias personnel at all levels and across all business units and organizations, and to comprehend business imperatives.
- Strong leadership abilities, with the capability to develop an information security team and guide team members and to work with only minimal supervision.
- Strong written and verbal communication skills.
- A strong customer/client focus, with the ability to manage expectations appropriately, to provide a superior customer/client experience and build long-term relationships.
- Liaise with 3rd party (POC) on 3rd Party assessments
Experience / skillsregarded as ideal but not essential
Penetration Testing and Vulnerability Assessments
- Develops a common set of security tools. Defines operational parameters for their use and conducts reviews of tool output.
- Performs control and vulnerability assessments to identify control weaknesses and assess the effectiveness of existing controls and recommends remedial action.
- Defines testing criteria for systems and applications.
- Is the primary individual responsible for the execution of risk assessment activities, analysing the results of audits (performed by other groups) to produce recommendations of acceptable risk and risk mitigation strategies.
- Works with junior staff on deploying, tuning and running vulnerability-scanning and penetration-testing tools.
Exposure to implementation of Controls
- Defines security configuration and operations standards for security systems and applications, including policy assessment and compliance tools, network security appliances, and host-based security systems.
- Develops and validates baseline security configurations for operating systems, applications, and networking and telecommunications equipment.
Incident Detection and Response
- Provides second- and third-level support and analysis during and after a security incident.
- Assists security administrators and IT staff in the resolution of reported security incidents.
- Participates in security investigations and compliance reviews, as requested by internal or external auditors.
- Acts as a liaison between incident response leads and subject matter experts.
- Monitors daily or weekly reports and security logs for unusual events.
Audit Support
- Manages relationship with the audit group. Receives audit findings and manages the collection of responses and remediation plans with owners.
- Works within the information security governance process to define control recommendations that are both efficient and effective.
- Provides oversight and management of audit finding remediation, including generating requirements for full remediation, providing feedback and suggestions on managerial responses to findings, and tracking progress and providing status and updates to the enterprise compliance team for reporting purposes.
- Supports e-discovery processes to include identification, collection, preservation and processing of relevant data.
- Maintains an awareness of existing and proposed security-standard-setting groups, state and federal legislation and regulations pertaining to information security. Identifies regulatory changes that will affect information security policy, standards and procedures, and recommends appropriate changes.
Exposure to Information Security Architecture
- Assists in the development of security architecture and security policies, prin