Information Assurance Analyst Job Description Template

The Information Assurance Analyst is part of a team in charge of identifying, developing, and reporting metrics in order to communicate the organization’s technology risk posture to the highest levels of management, including board level risk committees. They are accountable for upholding company security guidelines and procedures as well as serving as an operational arm for tracking threat information. The main operational risk-related tasks carried out on behalf of the business line are under the purview of this position. Basic qualities necessary for success in this role include the capacity to remain flexible and attentive under stress while handling several deliveries under strict goal delivery deadlines. You need to have a solid understanding of technology, risk, and security, in addition to strong organization skills and the ability to feel comfortable speaking to upper management and giving presentations.

Typical Duties and Responsibilities

  • Identify, develop, and report key risk indicators, key performance indicators, and other cyber security insights derived from multiple information sources
  • Support routine monthly reporting with an emphasis on control and final delivery of the written components of the report, maintaining high standards of output
  • Author report content from initial concept to finished product, including associated technological risk assessments, technical concept summaries in business terminology, information follow-ups, grammar and spelling format, etc.
  • Drive the metrics and reporting program to a higher degree of maturity by performing technological risk analysis and examining documentation in the development of new measurements and the maintenance of existing metrics
  • Support the creation of new reporting by taking the lead in developing new communication and reporting methods
  • Conduct the annual metrics inventory review
  • Deliver the quarterly risk dashboard, the annual operational risk assessment, and the maintenance of the risk profile statement
  • Build and manage metrics and reports in collaboration with business partners across the enterprise
  • Inform business and technology leaders of complex technological ideas and related risk analysis findings
  • Work together with key partners to advance projects and objectives by fostering consensus and influencing decision-making

Education

  • Bachelor’s degree in computer and information technology or a related field

Required Skills and Experience

  • 5+ years of experience with cybersecurity or information security governance 
  • Experience creating metrics (KPI/KRI) and reporting, including creating and displaying reports
  • Experience conducting technology and cybersecurity risk assessments and creating risk profiles
  • Knowledge of security policies, standards, and practices
  • Knowledge of the infrastructure, operations, and systems of information technology
  • Proficient in Adobe Acrobat, Microsoft Word, Excel, and PowerPoint
  • Adaptable with exceptional organizational skills
  • Ability to collaborate effectively with people at all levels of leadership
  • Excellent written communication skills, including the capacity to modify one’s writing style for various audiences and media and to express technical ideas using non-technical language
  • Strong verbal communication and presentation abilities

Preferred Qualifications

  • Experience with PowerBI, IBM Business Process Management, or SQL
  • Certification in CISSP, CRISC, or CISM
Contact us

Recruit with Nexus IT Group