Information Security Risk Assessor / Enterprise Security Architect

Posted 2 days ago

methodhubDenver (CO)

SENIORITY

Lead

Apply

About the role

Enterprise Security Architect / Information Security Risk Assessor
Location: Canton, MA(Remote)
Duration: Long-term Contract We are looking for folks who should be an enterprise architect for at least 5+ years and then moved into security. He/she should be able to build/develop applications and make them secure. He/She should be very technical. They should have developed applications in the cloud and on-prem and then becomes security experts Please revisit all your submitted candidates and qualify them as per need and let me know the candidates name will schedule internal discussions tomorrow or else look for additional profiles based on feedback. Day to Day job Duties: (what this person will do on a daily/weekly basis)• Providing advanced information security consultation for all aspects of information security, compliance, policy, risk management, and remediation• Identifying process improvements and developing plans to meet or exceed security best practices• Ensure the confidentiality, integrity, and availability of the information residing on or transmitted to/from/through the enterprise’s devices, servers, and other systems and data repositories.• Conduct risk assessments on various applications, systems, infrastructure, cloud-environments, and third-party arrangements. Document identified risk through a risk report to be effectively communicated shared with business and/or technical leadership• Confidently represent the Cyber & Information Security risk assessment services function with reviewing and assessing contracts, application designs, integration plans, etc.• Create documentation in support of the risk assessment services team• Self-directed; expected to identify and lead efforts to correct security controls and/or process improvements• Explain complex technical issues to non-technical colleagues and business executives• Troubleshoot and independently solve problems as they arise
Basic Qualifications: (what are the skills required to this job with minimum years of experience on each)• Min 5+ year of experience in at least 4 of these or similar disciplines: IT governance and operations; access control analysis; incident response; data analysis and auditing controls; data protection; advance threat protection; identity and access management; integrated technologies with cross-functional impact• Minimum 5+ year of experience with risk assessment frameworks• Broad knowledge of commonly used information security concepts, best practices, and standard• Strong collaboration, facilitation, and negotiation skills.• Strong communication skills, both written and verbal.• Familiarity with HIPAA Security Rule and other regulatory requirements• Proven analytical and problem-solving abilities• Project and program management planning and organizational skills• Customer service focused• Time management and prioritization• Certified Information Systems Security Professional (CISSP) or Certified Information Systems Auditor (CISA) or Certified Information Security Manager (CISM) or similar certification is required. Nice to Have; (But not a must)Hands-on experience with security tools

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this