STIGroup

STIGroup

Company

Legal NameSTIGroup Ltd
HeadquartersGlen Rock, United States
Websitehttps://stigroup.net

About STIGroup

This position is for one of our global clients and is fuly remote. As a member of the Infrastructure Risk Assessment practice group, this poition will focus on analyzing and making recommendations to improve application, vendor, and information security controls The successful candidate will report to the Director of Infrastructure Risk Assessments and will conduct assessments of application and third-party security controls. The assessment process is designed to identify key and emerging risks, determine severity and impact, review the adequacy of existing and vendor controls, and recommend methods to eliminate or mitigate risks to an acceptable level. The key job responsibilities include, but are not limited to: Application risk assessments – perform architectural and security reviews of new in-house and SaaS applications or major enhancements to existing applications Vendor security assessments – conduct reviews of supplier security controls and determine whether they are adequate and consistent with/complement the company framework of controls; Conduct telephone and in-person interviews with IT and business stakeholders as well as vendor personnel Review vulnerability scanning and/or penetration test reports; analyze/validate results to determine potential impact; Document each assessment – risk areas, work done, findings, conclusions, recommendations, management action plans, and final decision/approval Provide guidance as needed to IT and Business partners to ensure secure implementation of processes, systems and services. Job Qualifications 2+ years of experience as an Information Security practitioner 2+ years of experience in an IT role; programming and/or network design experience is desirable Technical knowledge of Information Technology systems and the ability to analyze them for vulnerabilities, including: TCP/IP (IP addressing and commonly used port assignments) Windows/Linux Operating Systems Client-Server applications Cloud-based applications/infrastructure Remote Access technologies Mobile devices Applied experience with ethical hacking, penetration testing and vulnerability detection tools Working knowledge of security standards (e.g., ISO 27001 & 27002, ISF, NIST Cybersecurity Framework, NIST Security Controls and Assessment Procedures for Federal Information Systems and Organizations) Working knowledge of industry assessment methods (e.g., Share Assessments, SSAE 16, SOC 2 & 3) Information Security certification: e.g., CISSP, CISA, CISM, SANS Experience as a practitioner or evaluator of business continuity / disaster recovery controls Knowledge of law and regulations surrounding the financial services sector is a plus Skills: Strong analytical skills; the ability to determine the information necessary to complete a risk assessment and the interpersonal skills to identify the source and collect the information Excellent verbal and written communication skills. Ability to adjust communication style and message content to interact with IT and business professionals at many levels throughout the organization Strong interpersonal, problem-solving, prioritization, organizational skills and attention to detail Understanding of authentication, authorization, and auditing Advanced user of analytical tools such as Microsoft Excel, Microsoft Access, Splunk

Synonyms

stigroupstigroup ltd

Hiring Locations

CountryCityJob Ads
United StatesGlen Rock29

Headquarters

Loading map...

Company Info

Legal Form: Ltd

Company Type: Public

Company Size: 11 - 50

Revenue: 1 - 5 million (USD)

Job Ad Metrics

Job Ads found: 29

Job Ads per Month: 1.8

Hiring Locations: 1

Data Info

Date of first job ad01.02.2020, 18:34
Date of last job ad14.11.2025, 23:01
Date merged18.11.2025, 00:43
Date created01.02.2020, 18:34

Sources: Careerbuilder, Careerjet, Glassdoor, Indeed, Linkedin, Monster, Simplyhired
 — Date merged: 18.11.2025, 00:43