Sr Info Security Analyst - SOC Level 3

| San Antonio, TX
Sorry, this job was removed at 11:23 p.m. (CST) on Monday, March 27, 2023
Find out who's hiring in San Antonio, TX.
See all Data + Analytics jobs in San Antonio, TX
Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

Overview
H-E-B is one of the largest, independently owned food retailers in the nation operating over 420+ stores throughout Texas and Mexico, with annual sales generating over $34 billion. Described by industry experts as a daring innovator and smart competitor, H-E-B has led the way with creative new concepts, outstanding service and a commitment to diversity in our workforce, workplace and marketplace. H-E-B offers a wealth of career opportunities to our 145,000+ Partners (employees), competitive compensation and benefits program and comprehensive training that lead to successful careers.
Responsibilities
H-E-B is a leading innovator in technology, and our Digital Technology Team collaborates to design, construct, implement, and support solutions across the enterprise.
As a Senior Information Security Analyst, you'll collaborate with key H-E-B Partners on security programs used to implement corporate standards, procedures, and guidelines to align with various compliance and risk requirements.
Once you're eligible, you'll become an Owner in the company, so we're looking for commitment, hard work, and focus on quality and Customer service. 'Partner-owned' means our most important resources--People--drive the innovation, growth, and success that make H-E-B The Greatest Omnichannel Retailing Company.
Do you have a:
HEART FOR PEOPLE... skills to present complex technical and security-related info so it's easily understood by many?
HEAD FOR BUSINESS... ability to maintain / gain new technical knowledge?
PASSION FOR RESULTS... drive to advise on development / acquisition projects to ensure the best security-related outcomes?
We are looking for:
- 5+ years of experience as a full-time information security professional
- professional security certification
What is the work?
Management:
- Develops security configuration and operations standards for security systems and applications, including policy assessment / compliance tools, network security appliances, and host-based security systems
- Recommends / develops / implements / trains on / interprets Info Security control patterns, designs, procedures, policies, guidelines, and standards, including the IS awareness program
- Collaborates with business leaders to develop solutions that balance security / business needs
- Generates / maintains administrative documentation (e.g., architecture diagrams and admin manuals, and operational procedures and processes)
- Assists Project Managers in developing project plans, specifying goals, strategy, scheduling, identification of risks, contingency plans, allotment of resources for each project phase
- Monitors / drives project results against technical specifications
Security / Administration:
- Performs security administration services for enterprise security systems (UNIX, Certificate Services, Firewall, Mainframe, Antivirus, Active Directory, etc.)
- Responds to information security requests, incidents, and trouble tickets according to defined SLA
- Participates in an on-call rotation for information security; resolves service outages within SLA
- Conducts periodic security controls testing (e.g., penetration tests, vulnerability analysis)
- Leads incident response teams; performs forensic / investigation services
- Participates in disaster recovery and business continuity efforts
- Develops security processes / procedures; supports SLAs to ensure security controls are managed and maintained
- Plays advisory role in application development and acquisition projects to assess security requirements and controls; ensures security controls are implemented as planned
- Reports to H-E-B management on residual risk, vulnerabilities, other security exposures, including misuse of information assets and noncompliance
- Works with information security leadership to develop strategies and plans to enforce security requirements and address identified risks
- Maintains job knowledge; participates in educational opportunities and professional organizations; stays current on professional publications; maintains personal networks
Analytics:
- Serves as primary point of contact to execute risk assessment activities; analyzes audit results (performed by other groups) to recommend acceptable risk / risk mitigation strategies
- Provides monthly, quarterly, and ad-hoc strategic / operational risk reporting and analytics for trending, risk assessment, compliance, and active exception reporting
- Determines security requirements by evaluating business strategies / needs; researches information security standards; conducts system security and vulnerability analyses and risk assessments
- Researches/ evaluates / recommends information security-related hardware and software; develops business cases for security investments
- Develops solutions by analyzing information requirements, determining systems architecture, components, and technologies, and by studying business operations and user-interface requirements
Auditing / Compliance:
- Manages / coordinates internal and external audits (e.g., PCI, DSS, HIPAA)
- Performs physical site assessments of business partners; provides peer review of work product and deliverables; executes release of information analysis to third-party business partners
- Collaborates with business and IS teams to ensure solutions align with H-E-B - s security posture
What is your background?
- A related degree or comparable formal training, certification, or work experience
- 5+ years of experience working full-time as an Information Security Professional
- At least one professional security certification (e.g., CISSP, CISA, CEH, applicable SANs programs) or other industry certifications (e.g., Cisco, MSoft, VMware) (preferred)
- Experience developing info security standardized configuration guides / procedures; performing vulnerability assessments and penetration tests using automated /manual methodologies against infrastructure and applications; scripting languages / code development for task automation (e.g., Python, Perl, Bash, PHP, JavaScript, PowerShell); working with ticketing systems; configuring, deploying, and monitoring enterprise security tools; and working with Security Info & Event Management (SIEM) systems
- Experience in Operations Center or Security Operations Center
- Experience in secure coding standards and application security, cyber supply chain risk management, emerging technology risk management, and threat model development / management
- Experience in project management (creating project plans, budgeting, and resource allocation)
Do you have what it takes to be a fit as a Sr Information Security Analyst at H-E-B?
- Working knowledge of securing UNIX, Linux, Windows OS family, TCP/IP, and networking technologies, web application servers (e.g., Apache, Tomcat, Microsoft IIS), and databases, including MySQL, MS SQL, Oracle
- Understanding of Top 20 Critical Security Controls for Effective Cyber Defense
- Familiarity with Business Continuity and Disaster Recovery process / procedures / testing, and with retail environments
- Technical expertise in systems administration and security tools
- Strong interpersonal and communication skills
- Ability to communicate technical and security-related concepts to a broad range of technical and non-technical staff
- Ability to understand the customer's perspective and tailor solutions according to H-E-B's security posture
- Ability to influence others
- Service-oriented
Can you...
- Function in a fast-paced, retail, office environment
- Travel by car / plane with overnight stays
- Work extended hours, nights, weekends, and rotating shifts; sit for extended periods
10-2016

Read Full Job Description
Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.

Similar Jobs

Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about H-E-BFind similar jobs