Information Security Analyst II

1 Month ago • 2-5 Years • Cyber Security

Job Summary

Job Description

The Information Security Analyst II supports security policies and technologies to protect networks, systems, applications, and data. This role acts as an information security expert, ensuring effective corporate security controls and responding to security events. Responsibilities include supporting GRC functions and PCI Compliance, participating in audits (PCI DSS, SOX, privacy laws), managing vulnerability programs (scans, penetration tests, remediation), representing security in contract reviews, and facilitating GRC workflows. Candidates should have experience in information security or IT audit roles and knowledge of IT security concepts and regulatory requirements.
Must have:
  • Support security policies, practices, procedures, and technologies to protect networks, systems, applications, and data.
  • Act as an information security expert, ensuring corporate security controls are effective.
  • Respond to security events and recommend corrective actions with IT and non-IT teams.
  • Support Governance, Risk, and Compliance (GRC) functions and PCI Compliance Program.
  • Participate in audit, compliance, and regulatory functions (PCI DSS, SOX, privacy laws).
  • Manage vulnerability program including scans, penetration tests, documentation, and remediation.
  • Represent security interests in third-party and customer contract reviews.
  • Facilitate and manage policy exception, risk acceptance, and policy management workflows.
Good to have:
  • College degree in Management of Information Systems, Information Security, Business/Accountancy (auditing focus), or equivalent experience
  • Experience with audits and controls
  • Experience working in a highly-regulated environment
  • 2-5 years of experience in information security or IT audit roles
Perks:
  • Sulamerica Health
  • Sulamerica Dental
  • Vidalink
  • Food/Meal Voucher
  • Child Care Assistance
  • Day off: on birthday
  • Gympass
  • Language assistance
  • Digital course platform
  • Volunteer time off: 2 days a year

Job Details

Position Details:

The Information Security Analyst II will support the security policies, practices, procedures, and technologies in order to ensure the protection of networks, systems, applications, and data. This role will be looked to as an information security expert within the organization, helping ensure corporate security controls are effective. This role will also be involved with day-to-day security operations by responding to security events of interest and recommending corrective action by working with IT and non-IT team members.

This job is responsible/accountable for supporting the processes and objectives of the Governance, Risk, and Compliance (GRC) function and Payment Card Industry (PCI) Compliance Program within the Information Security department.

We are looking for an Information Security Analyst II who will:

  • Participate and be an integral component of audit, compliance, and regulatory functions, including and not limited to: Payment Card Industry (PCI) Data Security Standard (DSS), Sarbanes-Oxley (SOX), emerging state and Federal privacy laws, and general security auditing
  • Participate in a vulnerability management program that includes: external and internal vulnerability scans of applications and systems, external and internal penetration tests of applications and systems, the documenting and remediation of identified vulnerabilities and exploits, routinely monitoring various communication avenues for security vulnerabilities and security patches, taking a risk based approach comparing those security vulnerabilities and security patches across the operating environment, and making recommendations to various IT teams on the mitigation process for those identified security vulnerabilities
  • Participate and represent the organization’s security interests in third party and customer contract reviews
  • Facilitate and manage the policy exception, risk acceptance, policy management and other GRC workflows within the security function.

Is this opportunity right for you? We are looking for candidates who has:

  • College degree: Management of Information Systems, Information Security, Business/Accountancy (auditing focus), related field, or equivalent experience
  • Experience with audits, controls, and PCI and/or ISO requirements
  • Experience administering and creating workflows in GRC tools
  • Experience working in a highly-regulated environment
  • Qualified and successful candidates will have at least 2 years of experience working within information security or IT audit roles or 3-5 years in information technology.
  • Working knowledge with IT security, compliance, and regulatory requirements, such as: Payment Card Industry (PCI) Data Security Standard (DSS), Sarbanes-Oxley (SOX), Healthcare Information Privacy Protection Act (HIPPA), state and Federal privacy laws
  • Advanced knowledge of IT security concepts.
  • Certified Information Systems Auditor (CISA)
  • GIAC Security Essentials (GSEC)
  • Other Governance, Risk, Compliance, Audit, or Security certifications
  • CLT contract model

Similar Jobs

Yggdrasil Sandbox - Information Security and Data Protection Specialist

Yggdrasil Sandbox

St. Julian's, Malta (On-Site)
3 Months ago
Redhorse Corp - Resource Efficiency Manager II

Redhorse Corp

Bangor Base, Washington, United States (On-Site)
1 Month ago
ISS Stoxx - Head of Data Operations

ISS Stoxx

Sydney, New South Wales, Australia (On-Site)
3 Months ago
bytedance - Global Legal Compliance Counsel

bytedance

Singapore (Hybrid)
9 Months ago
GHX - Inventory Specialist

GHX

Tampa, Florida, United States (On-Site)
3 Months ago
Zscaler - Senior Staff Devops Engineer (Terraform/Security Solutions)

Zscaler

Bengaluru, Karnataka, India (Hybrid)
3 Months ago
Devoteam - Cybersecurity Consultant

Devoteam

Cité Mahrajène, Tunis, Tunisia (On-Site)
9 Months ago
Trend Micro - Staff/Sr. Cloud Service Engineer (VicOne_ Automotive Security)

Trend Micro

Taipei City, Taiwan (On-Site)
10 Months ago
bytedance - Software Engineer, Security Operation Center

bytedance

San Jose, California, United States (On-Site)
5 Months ago
Roblox - Senior Security Software Engineer, Network Security

Roblox

San Mateo, California, United States (On-Site)
2 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

OKX - Senior Accountant

OKX

New Providence, The Bahamas (On-Site)
2 Months ago
SoftSwiss - Product Security Architect

SoftSwiss

Poland (Remote)
1 Month ago
Trek - Sales Associate

Trek

Lake Mary, Florida, United States (On-Site)
1 Year ago
Aledade - Senior Security Engineer I (Data Security)

Aledade

Bethesda, Maryland, United States (Remote)
1 Month ago
Condé Nast - Deputy US Market Controller

Condé Nast

New York, United States (On-Site)
1 Year ago
Spaulding Ridge - Governance Risk & Compliance Manager

Spaulding Ridge

Madrid, Community Of Madrid, Spain (On-Site)
2 Months ago
Nice - Information Security Analyst - Audit, Compliance & Cybersecurity

Nice

Southampton, England, United Kingdom (Hybrid)
2 Months ago
Interactive Brokers - Compliance Surveillance Analyst

Interactive Brokers

Montreal, Quebec, Canada (Hybrid)
1 Month ago
PwC - Senior de Auditoria Interna (Caracas)

PwC

Caracas, Capital District, Venezuela (On-Site)
10 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Brazil

pipa studios - Talent Bank (On-site)

pipa studios

São Paulo, Brazil (On-Site)
2 Years ago
TAG - Designer / Production Designer

TAG

State Of São Paulo, Brazil (Remote)
3 Months ago
PwC - Java Jr Analyst and Developer (AdvCon - DTS) | Associate [tag01]

PwC

Piracicaba, State Of São Paulo, Brazil (On-Site)
1 Month ago
FICO - Platform Solution Sales Executive

FICO

State Of São Paulo, Brazil (On-Site)
2 Months ago
Square - Global Business Process Owner - Request to Pay

Square

Santos, State Of São Paulo, Brazil (On-Site)
1 Month ago
Voldex - Roblox Modeler

Voldex

State Of Rio De Janeiro, Brazil (Remote)
3 Months ago
USE Insider - Inside Sales Specialist - US Market

USE Insider

São Paulo, Brazil (Hybrid)
4 Months ago
Fanatee - Jr Marketing Performance Analyst (USER ACQUISITION)

Fanatee

São Paulo, State Of São Paulo, Brazil (Remote)
1 Year ago
Epic Games - Associate Art Producer

Epic Games

Porto Alegre, State Of Rio Grande Do Sul, Brazil (On-Site)
4 Months ago
PwC - Java Analyst and Developer

PwC

Piracicaba, State Of São Paulo, Brazil (On-Site)
1 Month ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

Rackspace Technology - Senior Cyber Security Engineer (IAM/PAM - DevSecOps)

Rackspace Technology

Riyadh, Riyadh Province, Saudi Arabia (On-Site)
4 Months ago
bytedance - Software Engineer, Global Payment Privacy & Security

bytedance

San Jose, California, United States (On-Site)
5 Months ago
Roblox - Senior Security Software Engineer, Network Security

Roblox

San Mateo, California, United States (On-Site)
2 Months ago
whoop - Senior Information Security Engineer

whoop

Boston, Massachusetts, United States (On-Site)
1 Month ago
Unisys - Vulnerability Analyst (experience in the banking sector)

Unisys

Bogotá, Bogota, Colombia (On-Site)
4 Weeks ago
Saronic Technologies - Software Security Engineer

Saronic Technologies

Austin, Texas, United States (On-Site)
4 Weeks ago
Qualcomm - Security and Access control - Lead/Staff Engineer

Qualcomm

Bengaluru, Karnataka, India (On-Site)
2 Months ago
CyberArk - IT Security Operation Team Leader

CyberArk

Israel (On-Site)
1 Month ago
Rackspace Technology - Security Engineer L3 (Endpoint Security)

Rackspace Technology

Gurugram, Haryana, India (Remote)
4 Months ago
PwC - Cyber Security Architect

PwC

Amsterdam, North Holland, Netherlands (On-Site)
7 Months ago

Get notifed when new similar jobs are uploaded

About The Company

CSG empowers companies to build unforgettable experiences, making it easier for people and businesses to connect with, use and pay for the services they value most. For over 40 years, CSG's technologies and people have helped some of the world's most recognizable brands solve their toughest business challenges and evolve to meet the demands of today's digital economy. By channeling the power of all, we make ordinary customer and employee experiences extraordinary. Our people [CSGers] are fearlessly committed and connected, high on integrity and low on ego, making us the easiest company to do business with and the best place to work.

United States (Remote)

United States (Remote)

Stockholm, Stockholm County, Sweden (On-Site)

Londrina, State Of Paraná, Brazil (Remote)

Londrina, State Of Paraná, Brazil (Remote)

View All Jobs

Get notified when new jobs are added by CGS Carrers

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug