|
Cyber Governance Analyst - Internal Assessment - Ann Arbor Michigan
Company: KLA Location: Ann Arbor, Michigan
Posted On: 01/23/2025
Base Pay Range: $67,100.00 - $114,100.00 AnnuallyPrimary Location: USA-MI-Ann Arbor-KLAKLA's total rewards package for employees may also include participation in performance incentive programs and eligibility for additional benefits identified below. Interns are eligible for some of the benefits identified below. Our pay ranges are determined by role, level, and location. The range displayed above reflects the minimum and maximum pay for this position in the primary location identified in this posting. Actual pay depends on several factors, including location, job-related skills, experience, and relevant education level or training. If applicable, your recruiter can share more about the specific pay range for your preferred location during the hiring process.Company OverviewKLA is a global leader in diversified electronics for the semiconductor manufacturing ecosystem. Virtually every electronic device in the world is produced using our technologies. No laptop, smartphone, wearable device, voice-controlled gadget, flexible screen, VR device or smart car would have made it into your hands without us. KLA invents systems and solutions for the manufacturing of wafers and reticles, integrated circuits, packaging, printed circuit boards and flat panel displays. The innovative ideas and devices that are advancing humanity all begin with inspiration, research and development. KLA focuses more than average on innovation and we invest 15% of sales back into R&D. Our expert teams of physicists, engineers, data scientists and problem-solvers work together with the world's leading technology providers to accelerate the delivery of tomorrow's electronic devices. Life here is exciting and our teams thrive on tackling really hard problems. There is never a dull moment with us.Job Description/Preferred QualificationsThe Cybersecurity group at KLA is involved in every aspect of the global business. The KLA Cybersecurity group defends against cyber-attacks and provides cybersecurity tools, incident response services and assessment capabilities to safeguard the environments that support the essential operations of KLA. We are passionate about identifying adversarial activities and anticipating a wide variety of threats to strengthen our defenses and the overall protection of KLA Intellectual Property.We are in search of a Cybersecurity Governance Analyst to help mature our internal assessment program and support activities related to development and maintenance of policies, standards, procedures, and controls. Additionally, the qualified individual will work with the broader Cybersecurity team to mature our program, assess security risks, and communicate/facilitate remediation of those risks. - Develop and mature KLA's Cyber Security related policies, standards, and procedures in line with best known methods
- Conduct system, network, process, and software vulnerability assessments in accordance with established processes and procedures
- Apply frameworks and regulation guidelines to determine risk and recommend remediations
- Work with IT and business partners to perform successful assessments, build risk mitigation strategies, and review remediation plans
- Evaluate alignment with frameworks such as MITRE ATT&CK
- Assess IT risks through mergers and acquisitions and recommend mitigation strategies
- Conduct information system risk assessments and supports compliance documentation and system accreditation requirementsDesired Qualifications:
- Pursuit or completion of security related certification (CISA, GSNA, or similar)
- Ability to multi-task, adapt to changes quickly and handle heavy ticket volumes
- Self-motivated with the ability to work in a fast-paced environment
- Familiarity with various network and host-based security applications and tools, such as assessment/scanning tools, intrusion detection systems, and other security software packages
- Knowledge of vulnerability information dissemination sources (e.g., alerts, advisories, errata, and bulletins).
- Knowledge of the NIST CSF, ISO 27001, & CIS Top 20.
- Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacyMinimum Qualifications
|
|