freehire launches on Product Hunt on 26 August.

Follow →

Lead Security Analysis

Open 31d

GENERAL PURPOSE\:
The Lead, Security Analysis is the senior member of the Cybersecurity Risk Management group
responsible for leading and executing IT security risk management and governance processes
within the organization. This includes performing risk assessments, tracking mitigation efforts
and developing risk metrics and risk reports. This position is also responsible for leading security
risk related projects and enhancing programs, such as business process risk assessments, insider
threat management, updating security policies and standards and executing security awareness
programs for corporate as well as overseas offices.

The base salary range for this role is $124,700 – $212,800. The base salary range is
dependent on factors including, but not limited to, experience, skills, qualifications, relevant
education, certifications, seniority, and location. The range listed is just one component of
the total compensation package for employees. Other rewards vary by position and
location.

ESSENTIAL FUNCTIONS\:
• Provides subject matter expertise in all aspects of risk management including performing
risk assessments to proactively identify current and future security issues/vulnerabilities
and recommend remediation strategies.
• Leads insider risk programs by identifying improvements and establishing supporting
processes across the enterprise.
• Identifies and implements improvements to enhance the Cybersecurity Risk Management
program through optimization of processes, solutions, policies, procedures KPIs and other
techniques.
• Develops standards to support vendor selection and RFP process and participates in
product and vendor selection process to provide subject matter expertise on Information
security risk and compliance.
• Maintains risk register and develops Cybersecurity Risk Management metrics and reports.
Collaborates with Compliance Manager, Secure SDLC Manager, Information Security,
and IT groups to gather and analyze metrics.
• Leads information security awareness programs by regularly conducting exercise to
educate employees of information security and best practices.
• Monitors current and proposed laws, regulations, industry standards, and ethical
requirements related to information security and privacy.
• Lead and perform end-to-end risk assessments across business processes, applications,
infrastructure, cloud environments, and third-party/vendor eco-systems.

COMPETENCIES\:
People
• Building Effective Teams
• Developing Talent
• Collaboration
Self
• Leading by Example
• Communicates Effectively
• Ensures Accountability and Execution
• Manages Conflict
Business
• Business Acumen
• Plans, Aligns and Prioritizes
• Organizational Agility
With particular emphasis on the following specific position-related competencies\:
• Technical Competence and Expertise
• Analysis / Judgement
• Communication
• Customer Service

QUALIFICATIONS AND SPECIAL SKILLS REQUIRED\:
• Five years of experience within Information Technology with at least 3 in Security and/or
Risk Management.
• Bachelor’s degree preferred or equivalent combination of education and relevant experience
• Strong understanding of security governance, compliance and risk management principles.
• Proficient in Microsoft Word, Excel, PowerPoint
• Excellent analytical, organizational and communication skills
• Strong Project Management skills
PREFERRED QUALIFICATIONS\:
• CISSP (Certified Information Systems Security Professional)
• CRISC (Certified in Risk and Information Systems Control (CRISC)
• Working knowledge of UNIX and Windows
• Firewalls, VPN, PKI, IPS,
• Oracle, MS SQL
• Virtualization Security
• Software programming skills

PHYSICAL REQUIREMENTS/ADA\:
Job requires ability to work in an office environment, primarily on a computer.
Requires sitting, standing, walking, hearing, talking on the telephone, attending in-person
meetings, typing, and working with paper/files, etc.
Consistent timeliness and regular attendance.
Vision requirements\: Ability to see information in print and/or electronically.
This role requires regular in-office presence, including to engage in in-person team interaction,
meetings and collaboration, client support, mentoring, coaching, and/or feedback. However, this
role can perform duties effectively using a combination of in-office and remote work. #LI-Hybrid

SUPERVISORY RESPONSIBILITIES\:
N/A

DISCLAIMER\:
This job description is a summary of the primary duties and responsibilities of the job and position.
It is not intended to be a comprehensive or all-inclusive listing of duties and responsibilities.
Contents are subject to change at management’s discretion.

Ross is an equal employment opportunity employer. We consider individuals for employment or
promotion according to their skills, abilities and experience. We believe that it is an essential part
of the Company’s overall commitment to attract, hire and develop a strong, talented and diverse
workforce. Ross is committed to complying with all applicable laws prohibiting discrimination
based on race, color, religious creed, age, national origin, ancestry, physical, mental or
developmental disability, sex (which includes pregnancy, childbirth, breastfeeding and medical
conditions related to pregnancy, childbirth or breastfeeding), veteran status, military status, marital
or registered domestic partnership status, medical condition (including cancer or genetic
characteristics), genetic information, gender, gender identity, gender expression, sexual
orientation, as well as any other category protected by federal, state or local laws.