empty

Information Security Analyst II

CSG Systems US

Job Description

Posted on: 
September 17, 2024

Summary and company overview

Hi, I'm Juhi Banerjee, your Recruiter and guide to joining CSG! We are excited to learn more about you and your unique background.

The Information Security Analyst II will support the implementation and administration of information security policies, practices, procedures, and technologies in order to ensure the protection of networks, systems, applications, and data. This role will be looked to as an information security professional within the organization, helping ensure compliance with all security policies and standards, as well as with industry regulations and laws. This role will also be involved with day-to-day security operations by responding to security events of interest and recommending corrective action by working with IT and non-IT team members.

Our Story

CSG empowers companies to build unforgettable experiences, making it easier for people and businesses to connect with, use, and pay for the services they value most. For over 40 years, CSG's technologies and people have helped some of the world's most recognizable brands solve their toughest business challenges and evolve to meet the demands of today's digital economy.

By channeling the power of all, we make ordinary customer and employee experiences extraordinary. Our people [CSGers] are fearlessly committed and connected, high on integrity and low on ego, making us the easiest company to do business with and the best place to work. We power a culture of integrity, innovation, and impact across our locations, representing the most authentic version of ourselves to build a better future together. That's just who we are. Learn more about CSG Inclusion & Impact here.

Responsibilities

  • Perform log collection, correlation, reviews, archival, retention, and monitoring of automated alerts for items such as, and not limited to IPS/IDS alerts, Application Firewall alerts, malware alerts, change detection (FIM) alerts, rogue wireless network alerts, security system health alerts, exploit attempt alerts, etc.
  • Perform security engineering tasks as required to include alert tuning, system maintenance, determining and capturing key information feeds, etc.
  • Support processes such as Managing web browsing protection, web content filtering, and website category whitelisting/blacklisting, support automated encryption/decryption and secure file transfer of sensitive business process files, manage internally generated SSL certificates and SSL certificates generated by a managed PKI vendor and internal Certificate Authority
  • Participate and be an integral component of audit, compliance, and regulatory functions, including and not limited to Payment Card Industry (PCI) Data Security Standard (DSS), Sarbanes-Oxley (SOX), emerging state and Federal privacy laws, and general security auditing
  • Participate in the organization's incident response plan and perform incident reporting on an as needed basis
  • Must be able to work outside normal business hours when needed in order to perform diagnosis and/or implementation of product releases or changes so that normal business workflow is not interrupted
  • This position requires domestic and/or international travel of up to 5%

Job Requirements

Required Qualifications

  • Bachelor’s degree in computer science, Information Security, related field, or equivalent experience.
  • Proficiency in English in a business environment.
  • Experience with various functions within the entire incident response life cycle including security system engineering, alert monitoring, triage, incident analysis (host and network forensics, malware analysis, etc.) and incident management.
  • Experience maintaining information security technologies, such as IDS/IPS, malware prevention, database activity monitoring, secure password repository, multi-factor authentication, SIEM, SPAM prevention, web content filtering, IdM/IAM, encryption and encryption key management, DLP, change detection, and vulnerability scanners.
  • Qualified and successful candidates will have at least 2-4 years of experience working extensively within security or highly technical IT fields.
  • Knowledge of TCP/IP: must be able to demonstrate technical understanding of all layers of the TCP/IP stack, including familiarity with major application-layer protocols such as HTTP, HTTPS, FTP, SFTP, FTPS, SMTP, DNS, etc.; must be able to read and understand a packet trace; must be able to read and interpret network access control lists.
  • A clear understanding of a variety of network and application attacks: examples include DoS/DDoS, buffer overflows, SQL injection, reconnaissance scanning, and evasive methods attackers use to avoid detection; must be able to demonstrate a minimum level of familiarity with well-known vulnerabilities and exploits.
  • Working knowledge with IT security, compliance, and regulatory requirements, such as Payment Card Industry (PCI) Data Security Standard (DSS), Sarbanes-Oxley (SOX), Healthcare Information Privacy Protection Act (HIPPA), state and Federal privacy laws.

Preferred Qualifications

  • One or more of the following certifications:
  • Global Information Assurance Certification (GCIH, GCFA, GREM, etc).
  • Offensive Security Certified Professional.
  • (ISC)2 SCCP.
  • (ISC)2 CISSP.

Additional commentary

NA

Summary and company overview

Hi, I'm Juhi Banerjee, your Recruiter and guide to joining CSG! We are excited to learn more about you and your unique background.

The Information Security Analyst II will support the implementation and administration of information security policies, practices, procedures, and technologies in order to ensure the protection of networks, systems, applications, and data. This role will be looked to as an information security professional within the organization, helping ensure compliance with all security policies and standards, as well as with industry regulations and laws. This role will also be involved with day-to-day security operations by responding to security events of interest and recommending corrective action by working with IT and non-IT team members.

Our Story

CSG empowers companies to build unforgettable experiences, making it easier for people and businesses to connect with, use, and pay for the services they value most. For over 40 years, CSG's technologies and people have helped some of the world's most recognizable brands solve their toughest business challenges and evolve to meet the demands of today's digital economy.

By channeling the power of all, we make ordinary customer and employee experiences extraordinary. Our people [CSGers] are fearlessly committed and connected, high on integrity and low on ego, making us the easiest company to do business with and the best place to work. We power a culture of integrity, innovation, and impact across our locations, representing the most authentic version of ourselves to build a better future together. That's just who we are. Learn more about CSG Inclusion & Impact here.

Apply now