Senior Information Security Specialist
New
H
HalcyonCybersecurity
Remote, USFull-TimeSenior
Salary$120,000 - $160,000
Apply NowOpens the employer's application page
Job Details
- Experience
- 5+ years of experience in information security, GRC, or IT risk management.
- Required Skills
- Risk Management
Requirements
- 5+ years of experience in information security, GRC, or IT risk management.
- Strong understanding of cybersecurity concepts, controls, and risk frameworks.
- Demonstrated experience with third-party risk management processes and tooling.
- Proven ability to coordinate security testing and vulnerability management efforts.
- Excellent communication, documentation, and cross-functional collaboration skills.
- Ability to assess and implement technical and administrative controls across cloud and hybrid environments.
- Experience with regulatory compliance and audit support in fast-paced environments.
- Experience with compliance platforms (e.g., Drata, Vanta).
- Knowledge of security frameworks such as NIST 800-53 or CIS Controls.
- Experience with Microsoft 365 and/or Google Workspace security configuration.
- Certifications such as CISSP, CISA, CISM, or Security+ are a plus.
Responsibilities
- Perform and maintain third-party risk assessments and track vendor remediation activities.
- Support coordination and analysis of internal and external security testing, including vulnerability scans and penetration tests.
- Develop, track, and follow up on corrective action plans for identified security gaps or audit findings.
- Collaborate with managed security service providers and internal stakeholders to monitor and manage security events and escalations.
- Partner with engineering and operations teams to ensure implementation of security and compliance requirements across the organization.
- Assist in developing, maintaining, and communicating information security policies, standards, and procedures.
- Coordinate security incident response planning, disaster recovery testing, and business continuity exercises.
- Monitor and support enforcement of technical and administrative security controls across the enterprise.
- Stay current with evolving security and privacy regulations and frameworks (e.g., SOC 2, ISO 27001, TX-RAMP, FedRAMP).
View Full Description & ApplyYou'll be redirected to the employer's site