Company
InformationSecurityAnalyst
Neural analysis suggests this role is
optimal for Mid candidates.
“Information Security Analyst. Skills: information security governance, security frameworks, security controls, PCI compliance, IT SOX compliance, risk management, patch management, vulnerability scanning, penetration tests. providing key development, design, integration, and enhancement of information security governance and frameworks. ensure security controls are defined, optimized, and remain consistent throughout the organization and meet regulatory requirements and industry best practices”
Industry & Context.
analytical and problem solving skills
Maintain a flexible work schedule to meet position demands for after-hours support
What They're Looking For.
Must Have
3+ years of experience in information security, Experience with developing security framework such as ISO, PCI, and IT SOX audit requirements and security attack vectors, Experience with data classification, access control, and security models, Experience with implementing and managing DLP, FIM, Application Whitelisting, and ERM tools, Experience with various authentication protocols and encryption algorithms, Thorough understanding of the TCP/IP suite
Nice to Have
CISSP, CISA, or CISM preferred
What You'll Do.
providing key development
and enhancement of information security governance and frameworks
ensure security controls are defined
and remain consistent throughout the organization and meet regulatory requirements and industry best practices
Develop and implement information security frameworks and controls
Manage a risk-based process for vendor risk management
PCI and IT SOX compliance efforts
Establish baseline hardening standards for IT systems across organization
Ensure all systems are monitored by QRadar
Enhance and expand patch management program
Periodically update policies and procedures
Participate in the development of Cyber Security awareness content
Conduct periodic vulnerability scanning process and penetration tests
How You'll Work.
Team & Collaboration
Ability to work effectively will people at various levels throughout the organization
Communication Scope
Excellent verbal and written communication and interpersonal skills
Full Job Description
**Location:** Lahore, ## ## **Job Summary:** The Information Security Analyst will be responsible for providing key development, design, integration, and enhancement of information security governance and frameworks necessary to manage the risks and cyber security for the company. This position will ensure security controls are defined, optimized, and remain consistent throughout the organization and meet regulatory requirements and industry best practices such as PCI and IT SOX. ## **Responsibilities:** **_**Key Accountabilities:**_** * Develop and implement information security frameworks and controls such as ISO27001:2013, SAN Top 20, and OWASP Top 10 * Manage a risk-based process for vendor risk management, including the assessment and treatment for risks that may result from internal customers, consultants, and service providers * Heavy responsibility on PCI and IT SOX compliance efforts * Establish baseline hardening standards for IT systems across organization * Ensure all systems are monitored by QRadar to aggregate logs, correlate events, and detect incidents * Enhance and expand patch management program, review the patches, evaluate the risk, and apply the patches using a risk based approach * Periodically update policies and procedures to ensure they accurately reflect business requirements an align to industry leading security practices * Participate in the development of Cyber Security awareness content * Conduct periodic vulnerability scanning process and penetration tests * Maintain a flexible work schedule to meet position demands for after-hours support ** _**Education and Experience:**_** * Bachelor’s degree in computer science or related field * 3+ years of experience in information security * CISSP, CISA, or CISM preferred * Experience with developing security framework such as ISO, PCI, and IT SOX audit requirements and security attack vectors * Experience with data classification, access control, and security models * Experience with implementi
Applying for this Information Security Analyst role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Workday
- Workday has a multi-step form — save your progress after every section.
- "Apply With LinkedIn" can fail or lose data; manual entry is more reliable.
- Watch for the "Submit for Review" final step — hitting "Save" alone does not submit.
- Job requisition numbers are useful when following up with HR by email.
ANONYMOUS · UNFILTERED
What do employees actually say about this company?
Real rants from real employees. Read before you apply.