Specialist Information Security
Must Have Skills
Preferred Skills
Job Overview
Our client is seeking an experienced and detail-oriented Specialist I – Information Security to support security governance, compliance assessments, and operational risk management activities within enterprise technology environments.
The ideal candidate will have hands-on experience in technology risk management, IT audit, cybersecurity operations, compliance assessments, and remediation coordination. This role requires strong collaboration with cross-functional teams, technology stakeholders, and asset owners to ensure compliance with internal controls, security standards, and regulatory requirements.
The candidate should possess a strong understanding of IT infrastructure, application security concepts, governance processes, and enterprise security operations while contributing to continuous process improvement and operational excellence.
Key Responsibilities
Operational & Compliance Support
- Coordinate with technology factory teams to execute assessments as part of BAU (Business-As-Usual) security processes
- Work closely with Technology Asset Owners (TAOs) to evaluate and implement required control processes
- Conduct security and compliance assessments based on defined SOPs, policies, and control frameworks
- Identify security risks, control gaps, and non-compliance issues across applications and infrastructure
- Track remediation activities and collaborate with stakeholders to ensure timely closure
- Perform periodic compliance reviews and proactive assessments to improve security posture
- Maintain accurate tracking, reporting, and status updates for ongoing assessments and remediation activities
- Support audit and regulatory compliance initiatives through documentation and evidence collection
Risk Management & Security Governance
- Understand and apply technology risk management principles and internal security control frameworks
- Analyze assessment deviations and prepare remediation plans aligned with documented procedures
- Assess applications and infrastructure components against established security controls
- Maintain inventory and documentation related to applications, controls, risks, and remediation activities
- Ensure compliance with organizational security standards and governance requirements
- Assist in identifying process optimization, automation, and operational efficiency improvements
Stakeholder & Process Management
- Communicate assessment findings and compliance results to business and technical stakeholders
- Collaborate with infrastructure, application, and security teams on remediation planning and execution
- Manage BAU workflow tickets using JIRA and related tools
- Maintain and update knowledge repositories in Confluence or similar collaboration platforms
- Support continuous improvement initiatives within security operations and governance processes
Mandatory Skills
- 5–10 years of experience in:
- Information Security
- Cybersecurity Operations
- Technology Risk Management (TRM)
- IT Audit
- IT Compliance
- Security Governance
- Strong understanding of:
- Information security controls and governance
- IT compliance and audit processes
- Technology risk management principles
- Security assessment and remediation processes
- Hands-on experience with:
- JIRA workflow management
- Confluence documentation
- ServiceNow and/or Archer platforms
- Security assessment tracking and reporting
- Functional knowledge of:
- Operating systems (Windows/Unix/Linux)
- Networks, firewalls, LDAP, Active Directory
- Databases and cloud environments
- Authentication and authorization concepts
- APIs, interfaces, logging, and monitoring
- Application architecture and design principles
- Data classification and application criticality
- Experience preparing reports, dashboards, and documentation using:
- MS Excel
- Word
- PowerPoint
- Visio
- PDF tools
- Strong analytical, documentation, and problem-solving skills
- Ability to understand and follow documented operational processes and SOPs
- Strong communication and stakeholder management capabilities
Good to Have Skills
- Exposure to cloud security and cloud governance
- Experience with automation or process optimization initiatives
- Knowledge of cybersecurity frameworks and standards
- Experience supporting audit or regulatory assessments
- Understanding of enterprise security architecture
- Project management or coordination experience
- Exposure to risk and compliance platforms
Preferred Candidate Profile
- Detail-oriented with strong organizational skills
- Ability to manage multiple assessment and remediation activities simultaneously
- Strong collaboration and cross-functional communication skills
- Self-driven learner with the ability to adapt to evolving security requirements
- Proactive mindset toward operational improvements and risk reduction
Tools & Technologies
- JIRA
- Confluence
- ServiceNow
- Archer
- MS Office Suite
- Visio
- PDF Tools
Certifications (Preferred)
Any industry-recognized certifications such as:
- Microsoft Certifications
- Cloud Certifications
- Cybersecurity Certifications
- IT Governance / Audit Certifications
Examples include:
- Security+
- CEH
- ISO 27001
- CISSP
- CISA
- AWS/Azure Security Certifications
Apply to this job
Required — upload a file or paste the text
