Description:
The Information Security Systems Analyst is responsible for the security aspects of design, construction, test, and implementation for Infrastructure, support, and application development projects. The candidate will conduct assessments and identify information security risks to the enterprise associated with these areas. He/she will also facilitate the mitigation of these risks through security requirements and new/existing technologies. The Information Security Systems Analyst will define, track, and maintain standard baselines and configuration sets for all managed and/or monitored security devices and implement industry best practices with regards to IT Security controls.
Bright Horizons is a leading education and care company that helps employees thrive at work and at home by partnering with employers to offer high-quality child care, elder care, and educational support. Our workplace reflects this commitment—with collaborative environments, meaningful benefits, and a culture that supports both career growth and personal well-being. Whether you’re caring for children or powering the systems and partnerships that make it all possible, at Bright Horizons, you’re the difference.
What you will be doing:
- Establish an understanding of the Bright Horizons environment, from applications to infrastructure, keeping up to date with material changes and future direction.
- Develop and execute technological information security requirements and solutions to meet global regulations and policies and in conjunction with company standards.
- Developing early warning systems to detect, respond and mitigate risks to both the business and customer environments.
- Partnering closely within the security organization, infrastructure, and application development teams to harden accounts, platforms, and service structures to combat potential compromises.
- Provide guidance to other teams and contractors at varied implementation levels.
- Assist in the evaluation of 3rd party vendors involved in information security projects and processes; partnering with selected vendors where needed.
- Perform current system or platform security analysis and documentation.
- Produce a quality work product while addressing risks and meeting allotted completion timeframes.
- Perform vulnerability scanning and remediation efforts, coordinating with cross-functional teams
- Perform ad-hoc penetration testing targeting applications, networking equipment or a variety of endpoint operating systems to confirm status of vulnerabilities.
- Keep up to date with information security trends, driving appropriate changes through the enterprise.
- Conduct evaluations of new security technologies.
- Provide information security expertise in infrastructure platform support throughout all phases of break-fix (problem identification, resolution, test, deployment, and turnover).
- Review access logs and security alerts, promptly addressing issues where necessary.
- Participate in breach and information security related investigations, documentation, and remediation.
- Building and maintaining policies and reports for all security monitoring tools in corporate and public facing environments such as web and email DLP, SIEM, enterprise AV, IDS and AD.
- Encourage and guide teams in the adoption of security best practices.
- Participate in infrastructure strategic planning and budget process.
- Effectively communicate relevant security information to superiors.
- Resolve and/or escalate issues in a timely fashion.
- Understand how to communicate difficult/sensitive information tactfully in both written and verbal conversations.
- Keep teams well informed of security requirements and changes within the organization.
Minimum Requirements:
- Bachelor’s degree in Information Security, Cyber Security, Information Assurance, Computer Science, Network Security or a related field. 3+ years of additional experience would be considered in lieu of degree
- 3+ years System and/or Network Administration
- Able to travel to selected sites (1 or 2 trips per year)