Information Security Analyst I
Colorado Public Employees' Retirement Association · Penn Center - Denver, CO 80203 ·
- Work mode
- Hybrid
- Category
- Security
Colorado Public Employees' Retirement Association · Penn Center - Denver, CO 80203 ·
camdennational · Remote Posting - Maine
Satellite Office · Pasig, PH
prismahealth · Greenville, SC
Empeople Credit Union · Moline, IL, US
Early-career information security analyst at Colorado PERA who monitors and responds to security alerts (SIEM, EDR, IDS/IPS, email security), investigates vulnerabilities, and supports day-to-day security operations including access management, GRC/audits, patching, and vendor security reviews. Core stack includes Windows domain/Active Directory, Linux, networking, and virtualization (VMware).
JOB SUMMARY
The Information Security Analyst I is responsible for monitoring and responding to security events, investigating vulnerability reports, planning and participating in system security reviews and audits, installing security software, configuring security products, assisting with platform upgrades, and supporting the day-to-day information security operations. Candidates should possess general knowledge of MS Windows domain environment administration, incident response, vulnerability scanning, script reading, network design principles, and virtualization technology. This is a technical, internal-facing role that requires a combination of communication skills, problems solving skills, and technical aptitude.
IDEAL CANDIDATE
Our ideal candidate is an early career professional with an information security background, or someone who has worked in a technical capacity in IT services. We are searching for a skilled technician and require someone with excellent technical and communication skills who can help solve complex information security problems and minimize risk for Colorado PERA. Our Ideal Candidate will have the following skills:
Demonstrated working experience in an IT discipline supporting any of Windows Active Directory, networking, security, virtualization, help desk, or other IT discipline.
Experience configuring devices and services for compliance with organizational security standards.
Familiar with reading and understanding configuration documents, security alerts, and log data. Comfortable proactively responding to security incidents.
Experience configuring and testing platform upgrades or performing new software rollouts.
Demonstrated ability to be resourceful, make sound decisions, balance multiple initiatives, and drive issue to closure.
Passion for information security in practice and a general desire to continuously learn and understand varying aspects of IT and technology.
ESSENTIAL DUTIES AND RESPONSIBILITIES
Employees are held accountable for all duties of the job. Individuals must be able to perform these duties with or without reasonable accommodations.
Responds to information security alerts originating from systems including SIEM, Firewall/Proxy, AV/EDR tools, IDS/IPS tools, E-mail security gateways, password vaults, and other systems as needed.
Assists with management and onboarding of new vendors into VRM portal. Addresses stakeholder concerns, conducts IRQ assessments, and facilitates vendor management throughout the VRM process.
Administers key technology within the information security program, acting as the first line of contact for platform user support. Assists users and administrators with investigations and incident response.
Effectively troubleshoots applications, servers, and key information security services to maintain IT security posture. Writes knowledge articles detailing results of troubleshooting or investigations.
Maintains and troubleshoots access management systems including assisting with upgrades and new feature planning. Serves as the backup to senior staff helping manage tasks related to PAM.
Assists with GRC tasks including audit review, data governance review, access review, and compliance.
Patches, maintains, and supports key information security systems under the guidance of senior staff.
Evaluates and mitigates security vulnerabilities, remains conscious of security posture improvements, and understands how to escalate security issues.
Participates in DR test processes, learning about DR principals and procedures in use at PERA.
Looks for opportunity to improve confidentiality, integrity, and availability in all supported systems.
Assists, under direction of senior staff, in projects, system integrations, and application upgrades.
Participates in vendor security reviews, identifying and resolving issues with vendor solutions or configurations.
Able to research and test work independently, seeking guidance from colleagues only after making conclusions and gathering evidence. Assists internal stakeholders with evidence gathering and analysis tasks.
Performs other duties as assigned.
JOB QUALIFICATIONS
Degree in technical (STEM) field or one year experience in technical role.
Experience working with systems and software within assigned technology domain preferred.
Knowledge of Windows operating systems, Linux operating systems, server administration, desktop administration, troubleshooting, and user support preferred.
Proven knowledge of administration tasks, including user/group/role administration, security permissions administration, access authentication and authorization schemes, and user provisioning preferred.
Self-starter in systems administration and patching including ability to track changes and provide security reporting on assigned systems preferred.
Experience supporting Windows virtual desktop environments, Windows server infrastructure, vmWare systems, Linux or vendor provided platforms preferred.
Understanding of network devices and principles to include routers, switches, gateways, physical access systems, and wireless access systems preferred.
Basic knowledge and understanding of computer networking protocols, authentication protocols, and secure communications in a windows domain environment preferred.
Exposure to monitoring and escalating computer, network, and infrastructure security events including email phish investigation and operating system security preferred.
WORKING CONDITIONS
Standard office environment with frequent telephone communication, computer operation, and other office productivity machinery, such as a copy and printer machine.
Occasional moving and positioning supplies in excess of 20 pounds
All employees are expected to present themselves in a professional manner in alignment with the financial services industry
Ability to sit for prolonged periods of time
Ability to operate standard PC equipment
Ability to manage frequent deadlines and tight schedules
HYBRID WORK OPTION
Opportunity to work from home up to three days per week. Eligibility dependent upon factors detailed in PERA's Work from Home Policy.
6bffc68e-662d-4c02-8375-b102bf145f00:19000101_000001 · Atlanta, GA, US