M

Senior Information Security Analyst - Internal Security Review

Milliman

Remote · Full Time

Be the first to apply

Experience
7+ yrs
Salary
Openings
1
Posted
1 hour ago
Work mode
Work from home
Education
Bachelor's degree in Computer Science or Cybersecurity or equivalent experience
Resume
Required to apply

Job description

Job Overview

This role is focused on evaluating the security controls implemented at Milliman's global office locations to confirm adherence and promptly address security risks. Assessments can be conducted remotely or through onsite inspections involving coordination with local practice leadership and IT teams. Comprehensive reports with recommendations for remediation form a key deliverable. The position contributes as a team member of the Information Security department reporting to the manager based in India.

Key Responsibilities

  • Lead internal security reviews applying knowledge of security frameworks and Milliman policies to identify risks and optimize controls.
  • Analyze contracts and client security questionnaires to integrate requirements into security assessments.
  • Create detailed assessment reports with practical recommendations for both IT and senior leadership.
  • Track and ensure completion of remediation activities and follow up with practice offices.
  • Provide reports on aggregate risk to senior executives including the CISO and Audit Committee on a scheduled basis.
  • Maintain and update review tools such as templates and checklists in line with changes to policies or standards.
  • Support the Governance, Risk, and Compliance team by reviewing legal agreements, responding to security questionnaires, and assisting with GRC projects like policy updates, training, and process improvements.
  • Coordinate with legal and GRC teams to ensure alignment with security policies and meet service level agreements.
  • Assist with audit preparation for certifications such as HITRUST and SOC reports by providing relevant artifacts.

Qualifications and Experience

  • Over seven years of professional experience spanning IT, information security, or related audit roles.
  • Bachelor's degree in Computer Science, Cybersecurity, or equivalent relevant experience.
  • Strong command of English communication, both oral and written.
  • Experience with frameworks like ISO 27001/2, NIST 800-53, HIPAA, HITRUST, GDPR, SOC 2, and COBIT.
  • Skill in interpreting security data to detect compliance issues and applying AI tools to accelerate routine tasks such as data analysis and report creation.
  • Technical expertise covering networking, operating systems, access management, and information systems security.
  • Advanced proficiency in Microsoft Office Suite including Word, Excel, PowerPoint, and O365.
  • Project management capabilities allowing independent prioritization and execution of work.
  • Strong decision-making and problem resolution aptitude.
  • Ability to collaborate across global teams and managers to balance workload.
  • Willingness to travel approximately 20-25% annually mainly within Asia for onsite reviews.

Preferred Credentials

  • Certifications such as CISSP, CISA, CRISC, or CISM.
  • Motivated to pursue ongoing professional development including certifications and industry events.
  • Familiarity with secure software development lifecycles and cloud security controls.
  • Experience reviewing legal contracts and security clauses.
  • Industry experience in insurance, finance, or professional services sectors.
  • Knowledge of Microsoft SharePoint administration and automation/reporting tools like Power BI, Fabric, and Power Automate.

Work styles they’re looking for

Communication Decision making Problem Solving Collaboration Attention to Detail

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help