More jobs:
Information Security Analyst - Stamford, CT
Job in
Stamford, Fairfield County, Connecticut, 06925, USA
Listed on 2026-03-07
Listing for:
Vensure Employer Solutions
Full Time
position Listed on 2026-03-07
Job specializations:
-
IT/Tech
Cybersecurity, Information Security
Job Description & How to Apply Below
Position Summary
We're seeking a highly experienced Information Security Analyst to support a municipal-level cybersecurity program. This role reports to executive cybersecurity leadership and is responsible for strengthening enterprise security posture, ensuring regulatory compliance, and protecting critical systems and sensitive data.
Key Responsibilities- Develop and maintain information security policies, standards, and procedures
- Maintain IT risk taxonomy, risk register, and control inventory
- Align security program with NIST, FISMA, FedRAMP, ISO 27001, CIS Controls
- Lead Technology Risk and RCSA processes
- Conduct risk assessments, vulnerability scans, SOC testing, and audits
- Support audits, compliance reviews, POA&M tracking
- Monitor and respond to security events; lead incident containment/remediation
- Maintain SIEM, IDS/IPS, DLP, and endpoint protection tools
- Manage threat intelligence processes
- Advise leadership on cybersecurity risks and trends
- Provide security awareness training and executive-ready communications
- IT Risk Taxonomy (NIST RMF aligned)
- Enterprise IT Risk Register
- Risk Assessment Methodologies
- SOC Testing Framework & RCSA Model
- Threat Intelligence Process Documentation
- Compliance & remediation tracking
- 810 years in Information Security, Risk Management, or IT Security Operations
- Experience developing enterprise security programs in regulated environments
- Expertise with: SIEM, IDS/IPS, Firewalls, Endpoint tools, Vulnerability platforms
- Knowledge of Zero Trust architecture
- Understanding of NIST CSF 2.0, NIST RMF, ISO 27001, CIS Controls
- Cloud security experience (AWS, Azure, Gov Cloud)
- Strong analytical, investigative, and communication skills
- Experience in municipal, state, or federal environments
- Certifications:
CISSP, CISM, CRISC, CEH, GIAC - Experience with POA&M remediation and compliance reporting
- Enterprise Risk Management
- Security Governance & Compliance
- SOC & Control Testing
- Incident Response
- Threat Intelligence
- Zero Trust Architecture
- Cross-Functional Collaboration
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×