What are the responsibilities and job description for the Information Security Analyst position at The Intersect Group?
Role Summary
A client of The Intersect Group is seeking a Senior Information Security Analyst to lead the development and implementation of enterprise-wide technology policies and standards. This role ensures compliance with regulatory requirements, mitigates risks, and strengthens governance practices across the organization.
You will play a critical role in shaping cybersecurity strategy by creating policies aligned with industry standards, monitoring compliance, and driving risk management initiatives. Your expertise will help safeguard systems, protect sensitive data, and maintain trust with stakeholders.
Key Responsibilities
- Develop, implement, and maintain comprehensive cybersecurity and IT policies, standards, and guidelines.
- Ensure policies comply with applicable laws, regulations, and frameworks (e.g., NIST, FFIEC, GLBA, NYDFS, SOX, PCI-DSS).
- Collaborate with IT, legal, compliance, and business teams to align cybersecurity policies with organizational objectives.
- Conduct risk assessments, gap analyses, and audits; recommend actionable solutions to mitigate risks.
- Monitor and evaluate policy effectiveness through KPIs, audits, and incident reviews; implement continuous improvements.
- Maintain accurate documentation of policies, procedures, and compliance activities.
- Stay current on emerging cybersecurity threats, trends, and best practices to inform policy updates.
- Lead and support internal and external audits related to cybersecurity governance.
Key Requirements
- Bachelor’s degree in Information Security, Computer Science, IT, or related field (preferred).
- Minimum of 5 years experience in Cybersecurity Governance, Risk & Compliance (GRC), policy development, or risk management.
- Hands-on experience with GRC tools (e.g., Archer, ServiceNow, OneTrust).
- Proficiency in data analysis and reporting tools (e.g., Excel, Power BI).
- Relevant certifications such as CISM and/or CISA highly desirable.
- Strong understanding of regulatory frameworks and industry standards.
- Excellent communication skills with the ability to simplify complex concepts for diverse audiences.
- Proven ability to collaborate across departments and influence stakeholders.