Skip to main content
S

Information Security Analyst

Seminole County
1 day ago
Full-time
On-site
Sanford, FL, United States
$30.16 - $36.21 USD hourly
Indeed

Description Establish, develop, monitor,andmaintain information security standards, procedures and practices based on the NIST framework for a more secure enterprise environment and safeguard the County’s digital assets, infrastructure, and data. Information Security Analyst is responsible for maintaining compliance with security policies and standards, supports audits and risk assessments, conducts vendor risk and access reviews, supports incident response efforts, and enforces security measures to ensure confidentiality, integrity, and availability of information assets. This position works closely with IT, compliance, and risk management teams to maintain a robust security posture across the County and lead security awareness and education initiatives to foster a culture of proactive security awareness and promote security best practices. Essential Functions Note : These are intended only as illustrations of the various types of work performed. The omission of specific duties does not exclude them from the position. Implement, monitor, administer, and maintain, information and cybersecurity standards, procedures, andtechnologiestoensure controlsare in place to protect enterprise informationsystems and data. Conduct risk assessments and recommend mitigation strategies. Ensure compliance with industry regulations and internal policies. Assist with externals audits and prepare documentation for regulatory bodies. Manage, configure, deploy and maintain risk assessment and compliance tools. Conduct security assessments of third-party vendors and service providers. Review vendor security questionnaires and evaluate risk based on data handling practices, access controls, and compliance posture. Collaborate with procurement, legal, and risk teams to ensure contracts include appropriate security and data protection clauses. Maintain a vendor risk register and track remediation efforts for identified issues. Reassess vendor risk periodically and monitor for changes in risk exposure. Develop and deliver security awareness training programs for employees, contractors, and stakeholders. Create educational materials such as newsletters, phishing simulations, and policy guides. Promote a culture of security through ongoing communication and engagement. Track participation and effectiveness of training programs and adjust content based on emerging threats and county needs. Create, implement, and enforce security standards and procedures and conduct audits to ensure compliance with regulatory policies and security frameworks, such as NIST CSF. Review and perform risk reviews and assessments on existing or new systems and recommend security improvements. Maintain a proactive role in understanding and evaluating current and emerging technologies, ensuring they alignwith County needs and security objectives. Continually improves job knowledge by tracking and understanding emerging security threats, standards, practices, and security products. Participates and supports security investigations, help mitigate security events, and coordinate remediation or recovery efforts. Review, test compliance, and recommend remediation for security practices, policies and procedures. Recommend implementation of processes or technology to improve security posture. Act as a security liaison on promoting security best practices, implementation of security frameworks, regulatory and policy implications for departments, and across separate business lines, constitutionals, other agencies. AdditionalDuties: Performs other related work as required. In the event of an emergency, all employees are considered essential personnel and may be required to perform alternate duties and work varying schedules. Minimum Qualifications Bachelor's Degree in an associated field and (3) years' experience in enterprise Information Technology security and cybersecurity roles. Preference will be given to those with information security or cybersecurity certifications. A comparabl…

View the full posting and apply