What are the responsibilities and job description for the Information Security Analyst position at FFVA Mutual Insurance Co?
FFVA Mutual is a workers’ compensation carrier, rated A- (Excellent) by A.M. Best, that insures a variety of businesses across all major industry groups in ten states (AL, FL, GA, IN, KY, MS, NC, SC, TN, and VA). We are seeking a detail-oriented, proactive, versatile Security Analyst to join our IT team. This role is responsible for safeguarding our digital infrastructure by monitoring, assessing, and enhancing the security posture of our systems.
The ideal candidate will have effective communication skills and a strong understanding of cybersecurity principles, incident response, and regulatory compliance. Information technology security certifications such as CISSP, CISM, CEH, or CompTIA Security are highly valued.
Our employees enjoy a family-friendly work environment. We offer a competitive compensation package, including a generous 401(K) plan and strong employee benefits.
Key Responsibilities
Monitoring & Detection
- Monitor enterprise networks for security issues and investigate breaches or incidents.
- Review internal and external security alerts to assess relevance and urgency.
- Analyze threat intelligence to anticipate and mitigate risks.
- Stay current on emerging IT trends and security standards.
Assessment & Testing
- Conduct vulnerability assessments, risk analyses, and security audits.
- Perform and coordinate penetration testing and simulated attacks.
- Collaborate with IT teams to uncover network vulnerabilities through testing and audits.
- Evaluate third-party vendor security practices and ensure compliance.
Prevention & Hardening
- Recommend and implement security measures, including firewalls and encryption.
- Develop and enforce security policies, protocols, and procedures.
- Maintain and upgrade security systems and tools.
- Ensure protection of digital assets across cloud, on-premise, and internal systems.
- Ensure compliance with industry regulations (e.g., HIPAA, GDPR, NIST).
- Develop company-wide best practices for IT security policies, protocols, and procedures.
Incident Response & Recovery
- Lead incident response efforts and coordinate recovery activities.
- Analyze breaches to identify root causes and assess damage.
- Develop and review disaster recovery and business continuity plans.
Reporting & Metrics
- Provide documentation and reports to IT leadership and stakeholders.
- Develop and deliver metrics to measure security performance and capability.
Collaboration & Support
- Assist team members with IT troubleshooting and network security support.
- Educate staff and stakeholders on system security best practices.
Other Duties
- Perform additional responsibilities as directed.
Qualifications
- Bachelor’s degree in computer science, information security, or related field preferred.
- Experience in cybersecurity or IT security roles.
- Competent knowledge of security frameworks, tools, and best practices.
- Experience with SIEM tools, firewalls, IDS/IPS, and endpoint protection.
- Familiarity with regulatory standards (e.g., HIPAA, GDPR, NIST).
- Excellent analytical, communication, and problem-solving skills.
- Relevant certifications (e.g., CISSP, CISM, CEH) are highly valued.