Compliance & Risk AnalystSecurityBoston, MAAsset ManagementJO- Join a global compliance team for one of Boston's leading Asset Management Firms. This role will report to the Manager of IT Security and is part of the IT Production Control & Risk Management group. The IT Security Risk Analyst is a member of the IT Security Risk & Audit team, and has project, audit, reporting, and documentation responsibilities.
The individual also assists with staff action processing and security incident management, as well as day-to-day security support and operational tasks.Primary Responsibilities:Participates in IT security project managementGenerates and analyzes application, SQL, file system access audit documentationPerforms access analysis for staff actions (onboarding/transfers/terminations)Assists in data classification & protection projectsManages email security functionsParticipates in weekly meetings with other internal risk management teamsSupports the definition and implementation of security policies & proceduresMaintains documentation for processes and proceduresIdentifies and supports quality improvement initiativesAssists in performing product evaluations in support of data security initiativesPerforms IT security risk assessments of both new and existing in house and vendor based systemsContributes to company standards and policies related to IT security risksMaintains broad knowledge of best practices and trends in the field of Information SecuritySupports vulnerability management processesAssists in the adoption of new tools, processes and policies to enhance the firm's security posturePerforms various duties around the formation, delivery and maintenance of the firm's Information Security Awareness and Communication ProgramProvides after-hours coverage for Security Events and Incident ResponseProvides technical security support to Business Areas and IT staff on products, projects, applications and services as requiredParticipates and lead incidents as part of the Information Security Incident Response Team (ISIRT)Participates in Information Security meetings and activities as requiredPerforms any and all other assigned Information Security Program tasks and functionsProvides cross functional support for RFP generation by defining the security and compliance responses to appropriately address customer needs and leveraging the expertise of others to supportAssists in workflow enhancement for various supporting processesRequired Skills:Undergraduate with 3-5 years related experience, or graduate degree with information security specializationStrong written and verbal communications and interpersonal skillsMotivated and passionate about learning and developing your skillsStrong knowledge of information risk and security principles and practicesUnderstanding of various processes and regulatory standards including: MA Privacy Law 201 CRM 17.00, NIST Standards, SEC Standards; Risk Assessment Methodologies; Audit; Incident Response & ForensicsFamiliarity with Microsoft Active DirectoryExperience working with Active Directory and relevant operating system security (Windows, Linux, etc.)Experience with the following is desired: CMDB, SIEM, data leakage prevention and eDiscovery technologies, Varonis DatAdvantageA security-related certification would be a plus (CISSP, CISM, CISA, etc.)