Information Security Analyst
Listed on 2026-02-09
-
IT/Tech
Cybersecurity, Information Security
As an Information Security Analyst for GEI, you will be responsible for designing, implementing, and managing the organization's information security program with a focus on compliance and risk management. This position requires deep expertise in industry-standard frameworks such as NIST, CMMC, SOC-2, or equivalent, and benefits from hands-on IT Systems Administration experience. The analyst will work cross-functionally to protect sensitive data, maintain regulatory compliance, and mitigate security risks in a dynamic technology environment.
The successful candidate will be well versed in the world of information security and the challenges that network security brings, including an in-depth understanding of a variety of cyber security threats and any other vulnerabilities that may affect GEI.
- Provide security administration for all aspects of network operations including firewalls, VPN, routing, switching, network segmentation, wireless, backups, IPSec and content filtering.
- Monitoring security administration to ensure best practices
- Develop, implement, and maintain information security policies, standards, and procedures in alignment with NIST, CMMC, SOC-2, or similar frameworks.
- Lead risk assessments, vulnerability analyses, and security audits to identify and address security gaps.
- Monitor, analyze, and respond to security incidents; coordinate incident response efforts and root cause analysis.
- Collaborate with IT, compliance, legal, and business teams to ensure security controls meet regulatory and organizational requirements.
- Manage and track remediation activities from internal and external audits.
- Oversee third-party vendor risk management and ensure compliance with security requirements.
- Maintain awareness of emerging threats, vulnerabilities, and regulatory requirements, providing recommendations for continuous improvement.
- Train and educate staff on security best practices, policies, and procedures.
- Prepare and present reports to senior management regarding security posture, risk, and compliance status.
- Leverage IT Systems Administration expertise to support security architecture, incident response, and technical troubleshooting across servers, networks, endpoints, and cloud environments.
- Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, or a related field; advanced degree or certifications (CISSP, CISM, etc.) preferred.
- 6+ years of experience in information security, with demonstrated expertise in NIST, CMMC, SOC-2, or equivalent compliance frameworks.
- In-depth knowledge of IT risk management, security controls, and incident response.
- Experience conducting security assessments, audits, and managing remediation activities.
- Strong analytical, problem-solving, and communication skills.
- Ability to work independently and collaboratively in a fast-paced environment.
- Strong attention to detail and organizational skills
- Strong understanding of Active Directory and Group Policy
- Working knowledge of Microsoft 365 environment
- Professional certifications such as CISSP, CISM, CISA, or similar.
- Prior experience as an IT Systems Administrator or similar technical role, with hands-on management of servers, networks, endpoints, and cloud platforms.
- Experience with cloud security, endpoint protection, and network security technologies.
- Prior experience supporting CMMC, NIST 800-171/53, or SOC-2 audits and compliance programs.
- Understanding of regulatory requirements in sectors such as healthcare, finance, or government contracting.
Some of the world’s most pressing problems – from climate change to sustainable development, to critical infrastructure and the future of our energy supply – need our brightest and diverse minds working together to create safer, more resilient communities for tomorrow.
We are technical experts, collaborators, and entrepreneurs who draw from diverse backgrounds to solve our clients’ most complex challenges.
With several offices across North America, we offer a range of engineering, science, and technical consulting services. Our range of expertise, project types, and culture make us the choice for top talent in…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).