- Company Name
- Software Technology Inc.
- Job Title
- Information Technology Security Analyst
- Job Description
-
Job Title: Information Technology Security Analyst
Role Summary:
Lead security operations and incident response for critical infrastructure, ensuring compliance with PCI DSS 4.0+ and NIST frameworks. Oversee Azure, IIS, Active Directory, SQL database environments, and tolling/traffic management systems.
Expectations:
- 11+ years in cybersecurity, with 1+ year in Azure, IIS, AD, SQL, and critical infrastructure.
- Proficiency in SIEM tools, log analysis, and incident response workflows.
- Deep knowledge of PCI DSS 4.0+, NIST 800‑53, NIST 800‑82, and CIS Controls.
- Experience securing tolling, traffic management, or roadside equipment.
- Strong analytical, communication, and collaboration skills.
- Ability to work with third‑party vendors and mixed state/vendor‑managed environments.
Key Responsibilities:
- Monitor and analyze security events across Azure, IIS, AD, SQL, and infrastructure assets.
- Conduct incident investigations, root‑cause analysis, and post‑mortem reporting.
- Design, implement, and maintain system hardening and asset inventory practices.
- Ensure PCI DSS 4.0+ compliance and support audits.
- Manage security controls for tolling systems, traffic management, and roadside equipment.
- Collaborate with vendor partners to assess and mitigate third‑party risks.
- Develop and deliver security awareness training for operational teams.
Required Skills:
- Expertise in SIEM (e.g., Splunk, QRadar) and log analysis.
- Proficient with Azure security, IIS, Active Directory, SQL database security.
- Strong understanding of networking protocols and system hardening.
- Incident response and forensics experience.
- Vendor management and third‑party risk assessment.
- Excellent analytical, written, and verbal communication.
Required Education & Certifications:
- Bachelor’s degree in Cybersecurity, Information Technology, Engineering, or related field (or equivalent experience).
- Certifications: GICSP, GCIA, CompTIA Security+, or CISSP.