CGI is seeking an Information Security Analyst to support cybersecurity compliance across cloud-based and on-premises systems. The role focuses on implementing and validating NIST SP 800-53 controls, managing vulnerabilities, reviewing audit logs, supporting incident response, and collaborating with system owners and engineering teams.
Lead efforts to ensure systems achieve and maintain compliance with NIST SP 800 53 controls, translating control requirements into actionable technical solutions
Advise system owners and engineering teams on the technical implementation and optimization of security controls, addressing gaps and ensuring effectiveness
Evaluate proposed system changes for security impacts, conducting Security Impact Analyses and recommending appropriate technical mitigations
Develop, validate, and maintain security documentation, including System Security Plans, Privacy Impact Assessments, Contingency Plans, Incident Response Plans, Configuration Management Plans, and information exchange documentation
Document system security procedures and ensure they are up to date and accessible to relevant stakeholders
Analyze vulnerability assessment findings from internal and external sources
Drive remediation activities by collaborating with technical teams, tracking progress, and verifying the effectiveness of implemented solutions
Manage Plans of Action and Milestones (POA&M) for identified vulnerabilities and assessment findings
Review and analyze audit logs using tools such as Splunk and Azure Sentinel to detect anomalies, investigate incidents, and support compliance reporting
Develop and refine log review processes, ensuring timely identification and escalation of security events
Support security incident response activities, including investigation, containment, eradication, and recovery
Create and deliver incident response training sessions and test exercises
Document and report on incidents, lessons learned, and improvement opportunities
Provide technical recommendations for system improvements and security optimization
Maintain strong customer focused relationships with CGI and c
Qualification
Required
Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a closely related technical discipline
Minimum 1 year professional experience or relevant education related to understanding, implementing, and troubleshooting technical security controls (e.g., firewalls, IDS/IPS, endpoint protection, encryption, access management) in enterprise environments
Exposure to NIST SP 800 53 controls, including practical experience mapping, deploying, and validating controls in real world systems
Experience analyzing vulnerability assessment findings using Tenable Nessus, Microsoft Defender, or similar tools and driving remediation activities
Proficiency in audit log review and analysis using Splunk, Azure Sentinel, or similar SIEM tools
Strong analytical, written, and oral communication skills and demonstrating a very high level of attention to detail
Ability to work collaboratively in a team environment