What are the responsibilities and job description for the Security Systems Analyst (GRC & Linux) position at Apexon?
Job Title: Security Systems Analyst (GRC & Linux)
Location: Columbia, SC (Onsite)
Work Schedule: Monday – Friday, 9 AM to 5 PM (Minimum 3 days onsite required)
Job Summary
We are seeking a skilled Security Systems Analyst with strong expertise in Linux administration and Governance, Risk, and Compliance (GRC). The ideal candidate will manage security tools, support compliance initiatives, and ensure system integrity through proactive risk assessment and remediation.
Key Responsibilities
Linux & Security Operations
- Administer and manage IT security technologies, including Snort IDS sensors
- Deploy and maintain Rocky Linux / Red Hat Enterprise Linux 9/10 systems
- Apply OS patches, kernel updates, and system upgrades
- Automate repetitive tasks using Python or Ansible
- Configure, deploy, and maintain open-source and commercial security tools
- Troubleshoot Linux servers and applications at an advanced level
- Manage updates and performance of security tools on Linux environments
- Support data center activities including rack and stack operations
- Develop and improve operational workflows
Network & Infrastructure
- Demonstrate working knowledge of:
- Routers and switches
- VLAN configurations
- VPN technologies
Governance, Risk, and Compliance (GRC)
- Act as the primary technical contact for internal and external audits
- Conduct risk assessments on Linux environments and define remediation plans
- Translate compliance requirements into technical controls and standards
- Perform vulnerability management using tools like Nessus and OpenVAS
- Assess control design and effectiveness; identify gaps and risks
- Support audit processes:
- Evidence collection
- Issue tracking
- Walkthroughs and testing
- Maintain control libraries aligned with:
- ISO 27001
- NIST
- SOX
- SOC 2
- Prepare reports, dashboards, and governance metrics for leadership
- Coordinate with IT, security teams, business units, and internal auditors
- Automate workflows within RSA Archer (GRC tool)
- Participate in governance and regulatory review discussions
Required Skills & Qualifications
- Strong experience in Linux (RHEL / Rocky Linux) administration
- Hands-on experience with security tools and IDS systems (Snort preferred)
- Proficiency in Python or Ansible scripting
- Experience with vulnerability scanning tools (Nessus, OpenVAS)
- Solid understanding of networking fundamentals (VLAN, VPN, routing)
- Experience in GRC frameworks and compliance standards
- Strong troubleshooting and analytical skills
- Ability to work onsite and handle physical infrastructure tasks
Preferred Skills
- Experience with RSA Archer or similar GRC tools
- Prior experience in audit support and compliance environments
- Knowledge of enterprise security architecture