About the job
Role: Information Security Analyst
Location: Boston, MA
Contract Duration: 6 to 12+ Months
!! Open to Green Card Holders and U. S. Citizens Only !!
Required Qualifications:
Bachelor's degree in Business with IT audit or compliance experience, or a degree in Computer Science with a focus on business and IT Audit/Compliance is preferred.
5-7 years of overall IT experience.
A minimum of 3 years of experience in a Security Analyst role.
Familiarity with regulatory standards such as SOC, ISO, and Privacy Shield is advantageous.
Experience with diverse technologies, including SharePoint, various networks, platforms, and applications. Understanding of IT audit methodologies and control frameworks is essential.
Knowledge of Linux systems is a plus.
Familiarity with security scanning and penetration testing tools (e.g., OpenVAS, Qualys, Acunetix) is beneficial; CISSP certification is preferred.
Job Responsibilities:
Provide expertise in information security to support compliance with information systems (SOC2 Type 2, ISO27K). Engage with pre-sales, sales, and post-sales activities at eFront.
Propose and implement business processes to enhance overall security posture at eFront.
Conduct regular reviews of security and privacy policies.
Stay abreast of evolving security and privacy landscapes and propose relevant initiatives.
Collaborate with both internal and external stakeholders on security audits and remediation processes.
Monitor compliance against information security policies and standards through testing, internal control reviews, and risk assessments.
Maintain awareness of external regulations and new requirements within IT, and identify industry standards that inform core IT processes (e.g., ISO27001, NIST, SSAE16).
This role represents the company’s interests with customers, auditors, and third-party service providers.
Facilitate internal and external audits within IT and conduct periodic assessments to address specific risks.
Review IT audit findings with various IT functions, providing observations and recommendations while assisting in identifying control gaps and evaluating management action plans.
