Role OverviewAs a member of the Engagement Solutions Business Information Security Team, the Info Security Analyst I is responsible for partnering with business and technology teams to identify, assess, and mitigate information security risks while supporting Maritz's overall information security program.
What You Will Do
The analyst will support secure use case reviews, application security assessments, architecture reviews, security exception requests, and third-party/vendor risk evaluations. They will also support vulnerability management and DevSecOps initiatives, security governance, compliance, and audit activities, and develop, maintain, and utilize security reporting, automation, and analysis solutions.
Why It Might Be a Fit
The successful candidate must be able to think critically and be capable of researching unfamiliar technologies to identify risks and recommend practical solutions. They should be able to interpret Maritz security policies, communicate effectively with internal teams and clients, and make risk-based recommendations that align with Maritz's security objectives and risk tolerance.
Requirements
- Bachelor's Degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or related field of study
- At least two years of experience within information security
- Ability to research unfamiliar technologies, analyze technical documentation, troubleshoot issues, and develop practical recommendations or solutions
- Knowledge of fundamental cybersecurity concepts including risk management, vulnerability management, incident response, secure software development, network security, cloud security, and authentication and authorization principles
- Strong written and verbal communication skills with the ability to communicate technical concepts, security requirements, and risk-based recommendations to both technical and non-technical audiences
- Ability to work independently and within a team environment to identify and analyze security risks, formulate recommendations, and coordinate remediation activities across multiple stakeholders
- Basic scripting, automation, or data analysis experience using Python, PowerShell, SQL, APIs, Bash, Power Automate, or similar technologies preferred
- Familiarity with cybersecurity frameworks and standards such as NIST Cybersecurity Framework, CIS Controls, PCI DSS, SOC 1, and SOC 2
- Experience working with cloud platforms, application security tools, vulnerability management platforms, source code repositories, CI/CD pipelines, or ticketing systems preferred
Benefits
- Medical, dental, vision, life insurance, disability, paid parental leave, 401k, tuition reimbursement, paid time off, year end holiday closure
]]>