Point your AI agent at freehire and let it find you a job.

Get the CLI →

Steve Madden

NewBe an early applicant

Information Security Analyst

Posted Updated 1 view
Discussion

The role of the Information Security Analyst will be responsible for implementing and executing on all IT security services as outlined by the Steve Madden Cyber Security framework (NIST based). This position ensures the IT Security department provides an efficient, effective, updated, and secure IT environment in alignment with past, present and future cyber risks. The position is accountable for developing, publishing, maintaining, and enforcing enterprise IT security policies and standards encompassing data, digital and intellectual security. Secondary tasks include the selection of appropriate security solutions (tools) and oversight of any vulnerability audits and assessments including follow-up with remediation based on audit recommendations. This position is also responsible for supporting the Chief Information Security Officer in the conducting of PCI, IT SOx, external vendor and data privacy audits on an annual basis. Major Responsibilities and Competencies: • Works within the Steve Madden IT Cyber Security framework to support the data, digital and intellectual security needs of the company covering corporate, stores and e-commerce assets.• Identifies and establishes compliance with regulatory requirements defined for the security of information, personal data and intellectual property. Advises management on risks and best security practices, ensure proper methods are applied for compliance.• Determines the appropriate security response to cyber incidents. Intervenes whenever conditions exist that pose a threat to the security of the company. Provides senior management with updates or details regarding threats or serious incidents.• Leads the evaluation and analysis of security applications and systems and makes recommendations to management.• Monitors security alerts published on the internet (i.e. US-CERT, Homeland Security, FBI etc.) and determines whether reported threats could affect SM information systems.• Monitors internal security system alerts for possible intrusion or suspicious activity.• Reviews and creates audit reports on user and system activities.• Periodically tests security measures to reduce and mitigate risk.• Performs security architecture implementation and reviews.• Performs periodic IT risk assessments, reports on vulnerabilities and proposes remediation plans.• Assists with the company's annual PCI audit, filing and development of the SAQ.• Conduct PCI external vulnerability scans and provide the reports to the Trustwave.• Assists with the annual IT SOx internal/external audits and remediation.• Administer the IT Information Security Training course on an annual basis.• Conduct IT Security overview training as part of the new hire on-boarding process.• Report all violations of the IT Security program and security policies to senior management.• Communicates unresolved security exposures, misuse, or non-compliance situations to management.• Facilitate periodic system patching of our security appliances and applications as required.• Facilitate and provide scoping for all IT Security Audits as required.• Assist with the conducting of external vendor security audits for all new vendors that we share systems/data with. Functional and Technical Skills: • 3-5 years IT experience with a minimum of 3 years information security/infrastructure protection experience.• At least 3 years IT security & auditing experience required.• Technical proficiency in security-related hardware and software; ability to function as a consultant to other IT groups on security matters, as a subject matter expert.• Knowledge of IT security controls for midrange computers, servers, PCs, laptops, tablets.• Understanding of various operating environments, e.g. Windows, AS400, Cisco, MAC, tablets.• Proven professional experience evaluating IT infrastructure and applications, including network devices, firewalls, VPNs, desktop and server configuration, database security, and other security devices and applications, with a goal of eliminating or mitigating security risk.• Solid knowledge of the Sarbanes Oxley Act (SOx), EU GDPR and PCI-DSS compliance, corporate security and network policies/procedures.• Excellent verbal and written communications skills; ability to present and discuss technical information in a way that establishes rapport, persuades others, and gains understanding.• Ability to adequately maintain an up-to-date knowledge of the IT security industry including awareness of new or revised security solutions, improved security processes and the development of new attacks and threat vectors.• Understanding of relationships between threats, vulnerabilities, asset values and their effect on overall business risk.• Hands-on experience performing network traffic analysis, intrusion analysis and detection.• Experience in cyber incident response and computer forensics.• Experience in developing information security policies and standards.• Familiarity with some of the following security tools; Carbon Black, Windows Defender, Open DNS, Dark Trace, Mimecast, Sumologic, Trustwave, Qualys, and Forcepoint.• Familiarity with the NIST and PCI-DSS cyber security frameworks and their subsequent components. Education, Licenses, Certificates, Registrations and/or Experience: • Bachelor's degree in computer science, information security, electrical engineering, information technology or a related study, or equivalent experience.• CISSP, CISM, CISA or PCI certifications are a plus.• Fashion industry, retail, wholesale experience is preferred.

Skills

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available