Share this Job
Apply now »

Senior Information Security Analyst

Date: 
Req ID:  38366
Remote Position:  Yes
Country:  US
Line of Business:  VSP Vision Care
Division:  Information Technology

VSP Global is comprised of five complementary businesses that combine high-quality eye care insurance, high-fashion eyewear, customized lenses, ophthalmic technology and retail solutions, with employees in over 23 countries. No matter the role, we’re all focused on a singular mission: to help people see. Learn more by visiting https://vspglobal.com/cms/careers/

General Summary

Under the direction of the Information Security Manager, act as a subject matter expert and technical leader concerning complex information security technology, topics and issues. Responsible for technical and specialized duties in the areas of security framework, architecture design, risk management, incident management, vulnerability management, information security program and technology implementations, with the goal of improving the overall security posture of the organization.

Essential Functions

Provide subject matter expertise in defining, evaluating and recommending/implementing information security controls and technology to ensure the protection of the organization’s assets

 

Lead the security architecture and technology design, identify gaps, recommend security enhancements and lead efforts to ensure security requirements are integrated and implemented

 

Partner with the Architecture, Infrastructure and Technology teams to review existing architecture, identify gaps, and recommend security enhancements

 

Assist in defining architectural and technology standards that impacts the security of systems and data

 

Develops, validates, maintains and implements information security policies, standards, guidelines and procedures to ensure compliance with the Information Security Program

 

Lead detailed risk analysis and risk assessment to identify, mitigate and control risks to infrastructure, information systems and data; advocate security and risk management to key stakeholders in order to balance security and business needs

 

Lead third party evaluation to ensure that their technology environment appropriately protects shared data, that contracts have the appropriate security requirements, and that those requirements are met through regular audits and assessments

 

Monitors changes in current threats and looks at trends for future threat analysis in order to proactively plan and design the environment to protect against current and future threats

 

 

Job Specifications

Typically has the following skills or abilities:

 

Bachelor’s Degree in Computer Science or related field or equivalent experience

 

Minimum 8 years of hands-on technical information security experience

 

Expert level knowledge of security principles and technologies

 

5+ years hands-on experience designing and implementing a variety of security solutions and technologies across multiple disciplines

 

Broad experience with risk and threat assessment methodologies

 

Proven ability to weigh business needs against risk concerns and articulate issues to business leaders

 

Extensive experience implementing security controls to comply with various IT regulatory compliance requirements such as HIPAA and PCI as well as various standards including ISO 27001

 

Strong, proven skills and ability to identify and analyze security vulnerabilities

 

Experience performing network and application security penetration testing and/or vulnerability management, interpreting results and remediating findings

 

Ability to interact with personnel at all levels of the organization and interpret complex business initiatives

 

Excellent written and verbal communication skills

 

Ability to analyze various complex issues, projects, technologies and solutions

 

Ability to regularly exercise discretion and independent judgment in the performance of his/her job duties

 

Working Conditions / Physical Demands

The working environment is generally favorable.  Lighting and temperature are adequate, and there are no hazardous or unpleasant conditions caused by noise, dust etc.

 

The above information in this description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.

VSP Global is an equal opportunity employer and gives consideration for employment to qualified applicants without regard to age, gender, race, color, religion, sex, national origin, gender identity, sexual orientation, disability or protected veteran status.  We maintain a drug-free workplace and perform pre-employment substance abuse testing.


Nearest Major Market: Sacramento

Job Segment: Information Security, Ophthalmic, Risk Management, Information Systems, Computer Science, Technology, Healthcare, Finance

Apply now »