Job description
Information Security Analysts
Job purpose
To plan, implement, upgrade and monitor the security measures protecting the organisation's computer networks and information, to assess system vulnerabilities and act on the risks found, and to respond to security breaches and viruses, so that digital files and vital electronic infrastructure are safeguarded against unauthorised access, modification, destruction or disclosure.
Skills
- Specialist command of computer hardware, software and programming, of telecommunications, and of the strategies used to protect data and systems — encryption, firewalls, access control, virus protection, risk assessment and system testing — with the law and regulation governing data access. Most incumbents hold a bachelor's degree, with a substantial minority holding a post-baccalaureate certificate and a smaller group an associate's degree, together with several years of related experience.
- Confers with users on data access needs and programming changes, reviews violations of security procedures and discusses procedure with the users concerned to prevent repetition, and interprets technical risk for management and for people without technical training.
- Performs risk assessments and tests the data processing system to confirm that processing activity and security measures function as intended, and determines from current virus reports when protection systems must be updated. The problems are adversarial: the threat adapts against the controls in place, so precedent is only partly reliable and a late judgement means data lost or disclosed.
- Develops the security and emergency data processing plans and coordinates their implementation with establishment personnel and outside vendors, and schedules risk assessments, tests and security updates. Determines own tasks, priorities and goals within organisational policy, under time pressure set by newly reported vulnerabilities and by the pace at which controls must be brought up to date.
- Work is carried out seated at a workstation using computer systems, with time spent using the hands to handle equipment and controls. No lifting or manual handling of substance.
Responsibilities
- No line management. Trains users and promotes security awareness, coordinates establishment personnel and outside vendors on system implementation, and discusses procedure with users who have breached it. Holds authority over what individual users may access, and the work outcomes of others depend on the controls set.
- No budget is held and no spend committed. Coordinates outside vendors on the implementation of system plans; purchasing decisions rest elsewhere.
- Responsible for the security state of the organisation's networks, servers and data processing systems: erects firewalls, maintains and updates virus protection and configures security files. Ordinary care of a workstation; no responsibility for premises or plant.
- Monitors the use of data files and regulates access to safeguard the information in them, encrypts data transmissions to conceal confidential information in transit, and modifies security files to change individual access status. Holds the controls governing access to the organisation's data, where a lapse permits unauthorised modification, destruction or disclosure at scale.
Effort required
- Sustained close attention to monitoring output, virus and vulnerability reports and test results, alongside analytical work on risk assessment and plan design. Exactness matters, decisions are taken under time pressure and on incomplete information, and the consequence of a late or wrong judgement falls on colleagues and on organisational results.
- Carries personal accountability for the security state of systems the whole organisation depends on, and discusses breaches of procedure with the users responsible for them. The field is a competitive one in which technical knowledge must be kept current.
- Prolonged sitting at a workstation, at a screen and keyboard, with some handling of equipment and controls. No lifting or exertion.
Working conditions
- An indoor, climate-controlled office environment with no physical hazard, seated at a screen and working in close proximity to colleagues. The demand is psychological rather than physical: watchfulness against a changing threat and responsibility for the confidentiality of the information protected.
- Most incumbents work a regular established schedule, a minority an irregular one, and the working week runs beyond forty hours for the majority. The work is time-pressured, decisions are frequent and their impact reaches colleagues and organisational results. Exercises considerable technical autonomy within organisational policy — determining what to test, when protection systems need updating and what access is permitted — while substantive system changes are coordinated with establishment personnel and vendors.