Information Security Analyst

USA The Nature Conservancy

Arlington, Virginia

JOB DETAILS
LOCATION
Arlington, Virginia
POSTED
11 days ago
What We Can Achieve Together:

The Information Security Analyst (ISA) is responsible for participating in information security-related activities. In pursuit of this mission, the ISA coordinates tactical information security activities with information technology and other staff in a complex, decentralized global organization.

The Information Security Analyst is responsible for supporting information security and risk management activities centered around external party information and application security. You will be a member of the Information Security Risk Management Team - the Yellow Team. This team helps safely implement systems and integrate third party organizations into TNC's technology landscape, tracks information security risk, and manages human information security risk through a staff information security education and outreach program.

The Information Security Analyst will participate in the implementation, and maintenance of an external party information security risk management program. You will assess the information security risk profile of the Nature Conservancy's vendors, contractors and other external parties that have access to our data and systems and will work with affected business units to mitigate or accept the risks those external parties pose.

This position requires routine contact with IT as well as non-technical staff. This position reports to a Director of Information Security and supervises no staff.

RESPONSIBILITIES & SCOPE
  • Act as a contact for all security review requests, both for internal and external party systems and services.
  • Work with Privacy, and Legal teams to complete external party risk assessments.
  • Perform technical assessments on both internal and external/third party systems and services.
  • Participate in the implementation, and maintenance of the external party information security risk management program as part of TNC's overall external party due diligence review process.
  • Participate in the assessment, monitoring, and documentation of the security posture and risk profile of external parties with access to TNC data, information, and records or to TNC systems.
  • Participate in the security-oriented reviews of contracting-related documentation and provide security guidance to RFI/RFP/RFQ processes.
  • Work with Privacy and Legal teams to document the classification of data, information, and records held or processed by external parties.
  • Work with Information Technology staff to document the specifics of implemented technology solutions.
  • Provide assessment of external party or internal system security based on provided architectural and operational documentation.
  • Perform technical testing to validate the security-related behavior of a system, service, or piece of software.
  • Work with business unit, IT staff, or external party to resolve any findings from security testing.
  • Provide other Information Security teams with documentation of system configuration and expected behavior for applications and services.
  • Provide advice and consultation to staff on information security-related policies, procedures, and best practices.
  • Write documents for and deliver presentations to both technical and non-technical audiences.
  • Participate in security incident response activities.
  • Resolve issues independently within program area.
  • Willing to work flexible hours.
  • Work environment involves only infrequent exposure to disagreeable elements and minor physical exertion and/or strain.

We're Looking for You:

Are you looking for work you can believe in? At TNC we strive to embody a philosophy of Work that You Can Believe in where you can feel like you are making a difference every day. We're looking for someone with strong experience with IT support.

The ideal candidate should have keen attention to detail, excellent communication skills, and be effective in working in a team environment. This is an exciting opportunity to contribute to the ongoing mission of conservation by being a part of our Business Unit!

The ideal candidate will have all or some of the qualifications. If you don't have all of them, please apply anyway and tell us about your skills and experience:

  • Experience working in a decentralized global organization, supporting staff and/or systems located in multiple states and/or countries.
  • Multi-lingual skills and multi-cultural or cross-cultural experience appreciated.
  • Time management and attention to detail.
  • Experience in defining

About the Company

U

USA The Nature Conservancy

The Nature Conservancy is the leading conservation organization working around the world to protect ecologically important lands and waters for nature and people. The mission of The Nature Conservancy is to conserve the lands and waters on which all life depends.

We address the most pressing conservation threats at the largest scale. Thanks to the support of our more than 1 million members, we’ve built a tremendous record of success since our founding in 1951:
  • We've protected more than 119 million acres of land and thousands of miles of rivers worldwide — and we operate more than 100 marine conservation projects globally.
  • We work in all 50 states and more than 72 countries — protecting habitats from grasslands to coral reefs, from Australia to Alaska to Zambia.
  • We address threats to conservation involving climate change, fresh water, oceans, and conservation lands.
COMPANY SIZE
2,500 to 4,999 employees
INDUSTRY
Nonprofit Charitable Organizations
FOUNDED
1951
WEBSITE
http://www.nature.org