Information Security Analyst - GRC & Operations
Job in
Las Vegas, Clark County, Nevada, 89105, USA
Listed on 2026-07-25
Listing for:
WHSmith North America
Full Time
position Listed on 2026-07-25
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
As the Information Security Analyst, you will support and secure our current and future cyber infrastructure while playing a key role in our Governance, Risk, and Compliance (GRC) program. This hybrid role blends hands‑on security operations with compliance, training, and continuous control assessment responsibilities.
What You’ll Do- Secure the organization’s systems and information assets by applying cybersecurity best practices and protecting against unauthorized access, modification, or destruction.
- Partner with end users and department leaders to identify security needs and embed appropriate controls across business units.
- Deploy, integrate, and configure new and existing security solutions in line with standard operating procedures.
- Serve as a Tier 1 responder for cybersecurity alerts and remediations — triage, contain, elevate, document, and investigate problematic or anomalous activity.
- Support vulnerability assessments and penetration testing and coordinate timely remediation of identified weaknesses.
- Administer periodic access reviews to enforce least privilege.
- Support the global cybersecurity compliance program, maintaining alignment with frameworks such as NIST CSF, CIS Controls, ISO 27001, and PCI DSS.
- Perform continuous control assessments, document evidence, identify gaps, and report findings to key stakeholders.
- Maintain the risk register, control catalog, and supporting policies, standards, and procedures; assist with internal/external audits, third‑party risk reviews, and ongoing monitoring.
- Deliver corporate cybersecurity training — new‑hire onboarding, annual refreshers, role‑based training, and phishing simulations.
- Manage training and awareness metrics (completion rates, click/report rates, repeat offenders, behavioral trends), report results to leadership, and coordinate remedial training with HR, IT, and managers.
- Foster a culture of security consciousness across the organization.
- Education:
Bachelor of Science in Cybersecurity or a related field, or equivalent hands‑on experience. - Experience:
1–2 years of experience or internships in cybersecurity, IT, or GRC — or a strong academic background with relevant projects, certifications, or lab work. - Frameworks & standards:
Foundational understanding of common cybersecurity frameworks such as NIST CSF, CIS Controls, ISO 27001, or PCI DSS, and an interest in growing into continuous control assessments and compliance work. - Security operations & EDR:
Exposure to endpoint security or EDR tooling and a basic understanding of alert triage, escalation, and incident documentation; willingness to learn Tier 1 response workflows. - Vulnerability & access management:
Familiarity with vulnerability scanning concepts, remediation tracking, user access reviews, and least‑privilege principles. - Risk, policy & audit:
Awareness of risk management and policy concepts, with an interest in supporting control assessments, evidence collection, and audit activities. - Security awareness & training:
Interest in helping build and deliver cybersecurity awareness content (onboarding, annual, phishing simulations) and tracking basic training and phishing metrics.
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×