Information SecurityCompliance Analyst
Job Field: Office Jobs
Location: LEHI, UT
Job Type: Full Time
JOB SUMMARY:
The Information Systems Security and Compliance Analyst (ISSCA) will provide leadership for the development and implementation of the information system security policies and procedures of SirsiDynix IT and Cloud Services operations. The ideal candidate will be proficient in professional writing, with an emphasis on documenting policies and procedures. Candidates with knowledge of regulatory filings, data privacy laws, test procedures and reports, IT standards, government regulation are preferred, but we are willing to provide training for those with demonstrable and exemplary professional writing skills, excellent organizational and collaboration skills, strong verbal communication and presentation skills, as well as those able and willing to obtain government security clearances. Essential Functions Development and ongoing maintenance of System Security Plans, Policies, and Procedures which encompass (non-exhaustive list): Disaster Recovery (DR), Business Continuity (BC), Contingency Planning (CP), Incident Response Handling (IR), System and Services Acquisition (SA), Access Control (AC), Awareness and Training (AT), System and Information Integrity (SI), Change Management (CM), Certification, Accreditation, and Assessment (CA) Develop and maintain programs to promote awareness of Policies and Procedures, particularly those relating to system security and information privacy Arrange for, assist with, and perform, internal and external Systems and Information security audits toward insuring compliance with contractual and regulatory requirements Consult with IT, Cloud Services, Legal, HR, Proposals, and other teams as necessary on matters of Systems and Information security Produce regular reports of incidents and compliance Maintain familiarity with evolving global requirements, programs, and standards related to Systems and Information security Perform other duties as assigned Required Education and Experience Bachelor's degree in technical field or related equivalent experience IT/IS security training or certifications desired; regulatory training may be provided depending on candidate needs and qualifications 2 - 5 years of experience working in a position with demonstrable evidence of leadership and collaboration skills 2 - 5 years of technical writing experience (provide samples, and list of software tools) Operational experience in SaaS, enterprise software, IT security and compliance is desired Preferred Knowledge and Skills Familiarity with NIST 800-53, ISO 27000 series, FISMA, or similar standards and regulations is desirable Knowledge of SaaS, IT security, or enterprise software business is desirable
KEY REQUIREMENTS:
None