74,900 - 77,000 / Annual
At CoreCivic, our employees are driven by a deep sense ofservice, high standards of professionalism and a responsibility to better thepublic good. CoreCivic is currently seeking a Cybersecurity Analyst I locatedat our corporate office in Brentwood, TN. Come join a team that isdedicated to making an impact for the people and communities we serve.
Thisposition requires 4 days (Mon- Thurs) onsite in Brentwood, TN.
The Cybersecurity Analyst I supports the development andmaintenance of the CoreCivic cyber regulatory compliance program to support thealignment of security architectures, plans, controls, processes, policies andprocedures with security standards and operational goals. Appliesacquired job skills, policies, and procedures to complete assignments,projects, and tasks of moderate scope and complexity.
- Assists with validating that Information Security Policy and Standard documents meet or exceed industry standards, compliance requirements and customer/client expectations.
- Maintains the Information Security Program documentation.
- Facilitates sessions with technology stakeholders to review requirements, determine applicable security controls, and analyze gaps between requirements and current capabilities.
- Assists in the creation and documentation of compensating and mitigating controls.
- Assists with automating business processes to improve efficiency, verifying that systems follow defined policy guidelines and that written policies are integrated into existing systems were applicable.
- Makes recommendations for mitigating findings and process improvement projects.
- Consolidates and analyzes the organization's critical cyber findings, vulnerabilities, and gaps to support and develop solutions and to provide a cyber-posture/picture.
- Maintains findings, vulnerabilities and gaps in a mitigation tracker.
- Performs control testing, documents results and provides detailed updates to stakeholders, including analysis of vulnerability scans and compliance scans.
- Performs level appropriate system tuning based on threat indicators; makes basic to intermediate recommendations to enhance security controls and mitigate risks.
- Assists in the maintenance and enhancement of internal processes and tools used to respond to external requests related to information security using GRC tools, MS Office and SharePoint.
- Conducts research on inquiries about information security using policies, internal tools, and internal Subject Matter Experts (SMEs) while building and maintaining relationships with technology and business stakeholders and responding to client and regulatory requests.
- Leads small to intermediate projects with internal partners to support initiatives and programs designed to enhance information security.
- Exercises judgment within defined guidelines and practices to determine appropriate action.
- Domestic U.S. travel may be required.