Information Security AnalystWe are seeking an experienced Information Security Analyst to support and strengthen the City's cybersecurity, risk management, and compliance programs. This role will serve as a key contributor in developing security governance frameworks, conducting risk assessments, supporting security operations, and ensuring regulatory and standards alignment. The ideal candidate will bring deep expertise in cybersecurity analysis, risk management, incident response, and security technologies, along with the ability to collaborate across technical and non-technical stakeholders.Key ResponsibilitiesSecurity Governance & Policy Management Develop, review, and maintain information security policies, standards, and proceduresAlign governance practices with NIST CSF 2.0, ISO 27001, CIS ControlsSupport development of security control frameworksMaintain audit-ready documentationRisk & Control Management Conduct enterprise security risk assessmentsDevelop and maintain: IT Risk Taxonomy, IT Risk Register, Control InventorySupport Risk & Control Self-Assessments (RCSA)Identify control gaps and recommend remediation strategiesSecurity Operations & Monitoring Support and monitor security tools including: SIEM platforms, IDS/IPS systems, Data Loss Prevention (DLP), Endpoint Protection SolutionsAnalyze security events and alertsRecommend detection, tuning, and response improvementsVulnerability & Threat Management Perform vulnerability scans and assessmentsAnalyze findings and prioritize remediationSupport threat intelligence and proactive defense initiativesIncident Response & Investigation Detect, investigate, and respond to cybersecurity incidentsSupport breach analysis and containment activitiesDocument root cause analysis and corrective actionsCompliance & Audit Support Support SOC testing and security auditsEnsure alignment with: FISMA, NIST RMF, FedRAMP (as applicable)Prepare compliance artifacts and evidenceSecurity Awareness & Advisory Support cybersecurity awareness initiativesPromote best practices across City departmentsRequired Qualifications• 8–10 years of progressive experience in Information Security / Cybersecurity• Demonstrated experience in: security governance, risk management, security operations, incident responseRequired Technical Skills• SIEM technologies• IDS/IPS systems• Endpoint security tools• Vulnerability assessment platforms• Security event analysisRequired Knowledge Areas• NIST Cybersecurity Framework (CSF)• Risk Management Framework (RMF)• Security controls & governance• Incident response methodologiesPreferred Qualifications• Government / municipal cybersecurity experience• Cloud security exposure (AWS / Azure / GovCloud)• Experience supporting audits / SOC assessments• Industry certifications preferred: CISSP, CISM, CISA, CEHCore Competencies• Strong analytical and investigative skills• Excellent written and verbal communication• Ability to translate security risks for business stakeholders• High attention to documentation and compliance detail• Ability to operate independently and collaboratively