Information Security Analyst - Client Facing

Work set-up: 
Full Remote
Contract: 
Experience: 
Mid-level (2-5 years)
Work from: 

Offer summary

Qualifications:

Bachelor’s degree in cybersecurity or related field, master’s preferred., Minimum of five years’ experience in information security, with at least two years in software development., Experience with ISO27001, SOC2 audits, and regulatory compliance such as GDPR, CCPA, PCI., Proficiency with Microsoft Azure, O365, PowerShell, and secure SDLC tools..

Key responsibilities:

  • Partner with development teams to integrate security into the SDLC.
  • Ensure compliance with ISO27001 and SOC2 standards through audits.
  • Conduct internal audits and manage security assessments and reviews.
  • Serve as the primary contact for vendors and champion security best practices.

K2 Integrity logo
K2 Integrity https://www.K2Integrity.com/
201 - 500 Employees
See all jobs

Job description

K2 Integrity is seeking an experienced Information Security Analyst who is passionate about secure software development and developer enablement. This is a contract role. This candidate will be responsible for the design, implementation, and management of ISO27001-compliant security controls within our software development process. The ideal candidate will have the ability to collaborate with a software development team, raise awareness of secure coding practices, and foster a security-focused culture. We are looking for someone with the expertise to integrate robust security measures seamlessly into the development process, ensuring that security becomes an integral part of our software development lifecycle.

Responsibilities:
  • Partner with software development teams to integrate security practices into the software development process.
  • Ensure that SDLC processes comply with ISO27001 and SOC2 audit standards within agreed timeframes.
  • Conduct internal audits of SDLC controls.
  • Manage secure code review processes, threat modeling, and application security assessments.
  • Develop and maintain policies, coding standards, and best practices for developers.
  • Maintain and support internal security systems relevant for secure software development.
  • Identify and correct issues with vendors, suppliers, and subcontractors as required.
  • Identify security gaps and manage gap mitigation.
  • Participation in audit, incident response and access review processes.
  • Serve as the primary point of contact for technology vendors, coordinating support activities, managing vendor relationships, and ensuring timely resolution of issues.
  • Champion good security practices and assist developers with questions.
  • Act as project manager for information security projects.

Qualifications:
  • Bachelor’s of science in cybersecurity required; master’s preferred.
  • At least five years’ experience in the information security field and at least 2 years within software development
  • Experience with Microsoft Azure, O365, and PowerShell.
  • Experience with software tools which facilitate secure SDLC.
  • Experience completing ISO27001, and SOC2 audits.
  • Experience with regulatory compliance (GDPR, CCPA, PCI).
  • Good understanding of information security principles.
  • Ability to explain complex theories to development staff.
  • Strong knowledge of operating systems and related security issues (Windows, Linux, mobile).
  • Strong knowledge of network security systems and practices.
  • Strong knowledge of encryption technologies and common issues.
  • Any security certification or progress towards a certification is a plus.
  • Strong desire to learn, research, and problem solving.
  • Excellent communication skills.

This role is work from home (USA).
 

Required profile

Experience

Level of experience: Mid-level (2-5 years)
Spoken language(s):
English
Check out the description to know which languages are mandatory.

Other Skills

  • Communication
  • Problem Solving

Information Security Analyst Related jobs