Data Privacy and Compliance Analyst
On-siteAtlanta, Georgia, United States
Job Summary
Assess business policies and operations to ensure compliance with privacy requirements and government regulations for sensitive information. Lead validation of security control configurations against NIST, DFARS, and CMMC standards while articulating privacy requirements into the product life-cycle. Conduct privacy impact analyses, review vulnerability reports from scans and penetration tests, and coordinate remediation plans with business units. Mentor cybersecurity professionals and provide regular briefings to senior management on risk mitigation activities and performance metrics.
Required Qualifications
- Experience in vulnerability management
- Ability to obtain a secret security clearance
- Practical knowledge of security applications and technologies, as well as operating system platforms including Windows, Mac, Linux, and Networking technologies
- Previous experience with vulnerability scanning, reporting, and management processes or tools
- Hands on knowledge of application and infrastructure vulnerability scanning tools (e.g., Rapid7, Nessus, Qualys, Fortify, etc.) in complex or large organizations
- Technical background to understand the characteristics and exploitation vectors for vulnerabilities being reported
- Strong knowledge of Splunk, Tenable Nessus, APIs, Excel and Power BI Platform for data analytics
- Experience with advanced Excel data manipulation and analysis including pivot tables, light macros, intermediate formulas
- Previous experience in analyzing data to present relevant metrics to remediation stakeholders and leadership
- Sound knowledge of common infrastructure vulnerability categorizations such as CVE, CVSS, and/or CWE
- Deep understanding of cybersecurity best practices and frameworks such as NIST 800-53/171, CMMC, RMF, MITRE, ATT&CK Framework, and OWASP top 10
- Risk management expertise with ability to translate technical risks for business leaders
- Experience judging the priority of a vulnerability based on risk and impact
- Excellent written and verbal communication skills
- One or more basic cybersecurity certifications such as: Security+, CEH, CND, CySA+, CCNA-Security or equivalent
Desired Qualifications
- Active Secret clearance
- 9 years of experience in vulnerability management
- Masters degree
- Experience leading or managing a Vulnerability Management program
- One or more advanced cybersecurity certifications such as: CISSP, CISM, CISA, CASP, GEVA, CCNP-Security or equivalent
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.