Gathering your results ...
10 days
Not Specified
Not Specified
Not Specified
<p>K2 Integrity is seeking an experienced Information Security Analyst who is passionate about secure software development and developer enablement. This is a contract role. This candidate will be responsible for the design, implementation, and management of ISO27001-compliant security controls within our software development process. The ideal candidate will have the ability to collaborate with a software development team, raise awareness of secure coding practices, and foster a security-focused culture. We are looking for someone with the expertise to integrate robust security measures seamlessly into the development process, ensuring that security becomes an integral part of our software development lifecycle.</p> <p>Responsibilities:</p> <ul> <li>Partner with software development teams to integrate security practices into the software development process. </li><li>Ensure that SDLC processes comply with ISO27001 and SOC2 audit standards within agreed timeframes. </li><li>Conduct internal audits of SDLC controls. </li><li>Manage secure code review processes, threat modeling, and application security assessments. </li><li>Develop and maintain policies, coding standards, and best practices for developers. </li><li>Maintain and support internal security systems relevant for secure software development. </li><li>Identify and correct issues with vendors, suppliers, and subcontractors as required. </li><li>Identify security gaps and manage gap mitigation. </li><li>Participation in audit, incident response and access review processes. </li><li>Serve as the primary point of contact for technology vendors, coordinating support activities, managing vendor relationships, and ensuring timely resolution of issues. </li><li>Champion good security practices and assist developers with questions. </li><li>Act as project manager for information security projects. </li></ul> <p>Qualifications:</p> <ul> <li>Bachelor's of science in cybersecurity required; master's preferred. </li><li>At least five years' experience in the information security field and at least 2 years within software development </li><li>Experience with Microsoft Azure, O365, and PowerShell. </li><li>Experience with software tools which facilitate secure SDLC. </li><li>Experience completing ISO27001, and SOC2 audits. </li><li>Experience with regulatory compliance (GDPR, CCPA, PCI). </li><li>Good understanding of information security principles. </li><li>Ability to explain complex theories to development staff. </li><li>Strong knowledge of operating systems and related security issues (Windows, Linux, mobile). </li><li>Strong knowledge of network security systems and practices. </li><li>Strong knowledge of encryption technologies and common issues. </li><li>Any security certification or progress towards a certification is a plus. </li><li>Strong desire to learn, research, and problem solving. </li><li>Excellent communication skills. </li></ul> <p>This role is work from home (USA).</p>
POST A JOB
It's completely FREE to post your jobs on ZiNG! There's no catch, no credit card needed, and no limits to number of job posts.
The first step is to SIGN UP so that you can manage all your job postings under your profile.
If you already have an account, you can LOGIN to post a job or manage your other postings.
Thank you for helping us get Americans back to work!
It's completely FREE to post your jobs on ZiNG! There's no catch, no credit card needed, and no limits to number of job posts.
The first step is to SIGN UP so that you can manage all your job postings under your profile.
If you already have an account, you can LOGIN to post a job or manage your other postings.
Thank you for helping us get Americans back to work!