Nlets ยท 1 day ago
Information Security Auditor
Nlets is a not-for-profit organization focused on the interstate exchange of criminal justice information for public safety professionals. They are seeking a Security Auditor to assist in auditing information systems and ensuring compliance with security requirements, while collaborating with both internal and external customers to identify and mitigate risks.
Telecommunications
Responsibilities
Plans and leads both internal and onsite audits of customer network to include review of network topology, firewall, antimalware, management procedures, security controls, etc
Evaluates customer security policies and procedures to ensure compliance with corporate and federal security control requirement
Interfaces with new customers throughout Technical Security Assessment process
Prepares for audit of customer systems and facilities by interpreting customer provided documentation including floor plans, data-flow diagrams, network diagrams, and reviewing customer network topology and responses to audit questionnaire
Executes and documents the audit process within a variety of computing and application environments
Collaborates with internal business units to ensure security compliance, manage risk and bolster the corporate security posture
Accurately interprets gathered artifacts to advise customer of deficiencies and provides recommendations and guidance to support customer's adherence to corporate and federal security control requirements
Reviews audit findings with the security team and follows up with customer until all compliance issues have been met
Shared Responsibility to facilitate and maintain ongoing security awareness training and background compliance checks for both, internal staff and customer personnel
Produces Post-audit report for management and letter of compliance for customer
Qualification
Required
MUST PASS 10-PRINT FBI BACKGROUND CHECK
Excellent written and verbal communication skills
Confident, articulate, and professional speaking abilities
Bachelor's Degree in information security or related field or at least 4 years of related experience
Cisco Certified Network Associate Security (CCNA Security) Certification, GCNA (GIAC), or similar related Security Certification
At least 3 years hands on experience in one or more of the following Operating Systems: Windows Server, Linux and UNIX
At least 3 years practical experience in TCP/IP Networking
A diverse skill base in both Information Systems and Information Security which address organizational structure and administration practices, system development and maintenance procedures, system software and hardware controls, security and access controls, computer operations, environmental protection and detection, and backup and recovery procedures
Attack and Penetration experience in testing of Internet infrastructure and Web-based applications utilizing manual and automated tools
Knowledge of information system architecture and security controls (i.e. firewall and border router configurations, operating systems configurations, wireless architectures, databases, specialized appliances and information security policies and procedures)
Familiarity with one or more of the following Database Environments: Microsoft SQL Server, Oracle, Sybase, DB2 and MySQL
Experience with programming languages such as Java, C, C++, C#, and .NET
Knowledge of Industry Standards and best practices
Preferred
Prior experience with an audit/compliance framework (such as PCI or PKI), FedRAMP, and/or NIST SP800-53 and/or SP800-171 is strongly preferred
Benefits
Medical & Dental (employee + dependents)
Sick Leave Accrual
Vacation Leave Accrual
12 Paid Holidays
LTD and STD Insurance
Life Insurance (employee + dependents)
Employee Match Pension Plan
Employer Funded HSA and FSA
Company
Nlets
Nlets is a self-funded, private, not-for-profit corporation funded and governed solely by the 54 lead law enforcement agencies that make up the principal customers of Nlets.