
Security Analyst
Full Job Description
Overview The Security Analyst Experienced will be responsible for supporting the organization's Information Security and Information Security Management System (ISMS). The role combines hands-on information security activities with internal ISMS auditing, risk management, compliance, and continual improvement in alignment with ISO/IEC 27001 requirements.
Responsibilities Conduct internal ISMS and ISO 27001 audits and assess the effectiveness of security controls. Review information security policies, procedures, standards, and control evidence. Identify and document security risks, control gaps, observations, and non-conformities. Perform information security risk assessments and support maintenance of the ISMS risk register. Track audit findings and corrective actions and validate remediation evidence through closure. Support ISO 27001 certification, surveillance audits, and management reviews. Monitor security systems, networks, endpoints, and infrastructure for threats and suspicious activity. Support security incident identification, investigation, response, and documentation. Coordinate vulnerability management, patch management, and remediation activities. Support access management, privileged access, and periodic user access reviews. Configure, troubleshoot, and maintain security tools and infrastructure, including firewalls, endpoint security, authentication, and monitoring solutions. Support security logging, alerting, and investigation activities. Assist with data protection, information classification, and secure handling of sensitive information. Participate in third-party/vendor security assessments where required. Support business continuity and disaster recovery security requirements. Identify security requirements and recommend solutions to improve the organization's security posture. Develop and implement security improvements and automation for repeatable security tasks. Support security awareness and training initiatives. Prepare security, audit, risk, and compliance reports for management. Ensure compliance with organizational security policies and applicable information security standards. Contribute to the continual improvement of the organization's ISMS and overall security posture.
Qualifications Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field preferred. Minimum 2 years of experience in Information Security, ISMS, IT Audit, IT Compliance, GRC, or a related security role.