Skip to main content
Loading
loadingbar
Loading, Please wait..!!

IT Info Security Specialist

  • Job type Posted on: Jul 20, 2026
  • Experience level Erie Insurance Group
  • Employment type Erie, Pennsylvania
  • Employment type Onsite
  • Salary Full-time

Point Apply Here APPLY LATER

Curious about compensation?

Explore the historical salary trends, average pay, and estimated compensation for IT Info Security Specialist roles in Pennsylvania.

View Salary Guide →

Job Title :

IT Info Security Specialist

Job Type :

Full-time

Job Location :

Erie Pennsylvania United States

Remote :

No

Jobcon Logo Job Description :

IT Info Security Specialist Working independently or as part of a team, contributes to the planning, implementation, and management of the Information Security program to safeguard ERIE's digital assets. Implements and maintains security systems and procedures to govern, identify, protect, detect, respond to, and recover from cybersecurity risks, threats, vulnerabilities, and incidents. Completes and may lead assignments of moderate complexity within the Information Security portfolio with minimal guidance. Performs duties in one or more of the following Information Security disciplines, including but not limited to: Application Security (AppSec); Cloud Security (CloudSec); Governance, Risk Management & Compliance (GRC); Identity & Access Management (IAM); Security Operations (SecOps), or Vulnerability Management. This opportunity is for a Professional Information Security Specialist on the Governance, Risk, and Compliance team. The Information Security Specialist will support cybersecurity governance, IT risk management, regulatory compliance, and control assurance activities across the enterprise. This role will focus on SOX/MAR IT attestations, including coordinating evidence collection, supporting control owners, reviewing control documentation, tracking control performance, and helping ensure IT and cybersecurity controls are operating effectively. The role will partner with technology teams, application owners, business stakeholders, internal audit, external audit, and risk management partners to support audit readiness and compliance objectives. The Information Security Specialist will also support broader GRC activities, including IT risk assessments, control testing, issue and remediation tracking, policy and standards governance, regulatory alignment, metrics reporting, and continuous improvement of the cybersecurity compliance program. Preferred Experience & Skills: Knowledge of IT governance, risk, and compliance processes Understanding of IT control areas such as access management, change management, system operations, cybersecurity governance, and third-party oversight Experience gathering, reviewing, and organizing audit evidence Ability to assess control effectiveness, identify gaps, and support remediation activities Knowledge of frameworks and regulations such as SOX/MAR, NIST CSF, NYDFS Part 500 or CIS Controls Strong analytical, documentation, communication, and stakeholder management skills Experience in GRC, IT audit, IT risk, cybersecurity compliance, or technology controls What Makes You Stand Out: Experience supporting SOX/MAR IT attestations, IT general controls, audits, or control testing Hands-on experience with control walkthroughs, evidence review, deficiency tracking, and audit support Familiarity with IT General Controls, control narratives, process flows, risk registers, GRC tools, and audit management platforms Ability to manage multiple priorities, meet audit deadlines, and drive accountability across teams Duties and Responsibilities: Installs, configures, administers, and analyzes information security technologies, controls, and practices that maintain the confidentiality, integrity, and availability of ERIE's information systems and data assets. Continuously detects, logs, monitors, alerts, and reports on information security controls, exceptions, vulnerabilities, threats, risks, and incidents. Executes actions to protect assets and detect vulnerabilities or threats. Executes actions to respond to and recover from vulnerabilities or threats. Develops and manages relationships with diverse groups of stakeholders at multiple levels. Partners and aligns with cross-functional risk assurance, IT, and business teams across the enterprise to implement, align, and ensure compliance with security measures. Establishes and ensures that security measures are in line with industry standards, best practices, and regulations. Measures and improves the operating rhythm of Information Security as well as the risk posture of ERIE. Advances Information Security controls through maturity assessments, continuous process and automation improvements, appropriate policies/standards/procedures, and capability development. Develops and presents reports, metrics, dashboards, and evidence to stakeholders across the enterprise up to and including leadership and corporate officers. Provides support to end-users on security-related issues. Effectively communicates to and influences stakeholders through oral and written communications. Provides discipline-specific knowledge in support of security awareness and outreach to ensure that information security best practices are understood and followed enterprise wide. Remains current on industry best practices, standards, frameworks, regulations, and emerging security threats through research, training, and participation in industry associations. Makes recommendations for improving the company's security posture. Shares recommendations, knowledge, and relevant content to inform, mentor, or trains others. Capabilities: Collaborates Cultivates Innovation Customer Focus Decision Quality Ensures Accountability Instills Trust Nimble Learning Optimizes Work Processes (IC) Self-Development Values Diversity Qualifications: Minimum Education and Experience Requirements: Bachelor's degree in relevant field and 2 years of related experience; or Associate degree in relevant field and 4 years of related experience; or High School diploma or equivalent and 6 years of related experience, required. Completion of a relevant IT-career preparation program approved by ERIE's Human Resources and IT Talent Optimization Departments if unrelated degree and/or less experience. Relevant certifications and/or military training/service may be considered for equivalent education/experience. Additional Experience: Foundational knowledge and skill associated with at least one Information Security discipline and in at least one IT domain (analysis, engineering, system administration), required. Experience with IT delivery or operational methodologies (agile delivery, SDLC, ITIL), preferred. Critical thinking skills and analytical mindset required. Persuasive communication and interpersonal skills, and ability to convey technical concepts to non-technical stakeholders, required. Ability to participate in on-call rotations and work outside of regular business hours to support cyber event and incident handling may be required. Physical Requirements: Ability to move over 50 lbs using lifting aide equipment; Rarely Climbing/accessing heights; Rarely Driving; Occasional (

Jobcon Logo Position Details

Posted:

Jul 20, 2026

Reference Number:

14660_26112857CC8C44B2819BFF814A0B9114

Employment:

Full-time

Salary:

Not Available

City:

Erie

Job Origin:

APPCAST_CPC

Share this job:

  • linkedin

Jobcon Logo
A job sourcing event
In Dallas Fort Worth
Aug 19, 2017 9am-6pm
All job seekers welcome!

IT Info Security Specialist    Apply

Click on the below icons to share this job to Linkedin, Twitter!

IT Info Security Specialist Working independently or as part of a team, contributes to the planning, implementation, and management of the Information Security program to safeguard ERIE's digital assets. Implements and maintains security systems and procedures to govern, identify, protect, detect, respond to, and recover from cybersecurity risks, threats, vulnerabilities, and incidents. Completes and may lead assignments of moderate complexity within the Information Security portfolio with minimal guidance. Performs duties in one or more of the following Information Security disciplines, including but not limited to: Application Security (AppSec); Cloud Security (CloudSec); Governance, Risk Management & Compliance (GRC); Identity & Access Management (IAM); Security Operations (SecOps), or Vulnerability Management. This opportunity is for a Professional Information Security Specialist on the Governance, Risk, and Compliance team. The Information Security Specialist will support cybersecurity governance, IT risk management, regulatory compliance, and control assurance activities across the enterprise. This role will focus on SOX/MAR IT attestations, including coordinating evidence collection, supporting control owners, reviewing control documentation, tracking control performance, and helping ensure IT and cybersecurity controls are operating effectively. The role will partner with technology teams, application owners, business stakeholders, internal audit, external audit, and risk management partners to support audit readiness and compliance objectives. The Information Security Specialist will also support broader GRC activities, including IT risk assessments, control testing, issue and remediation tracking, policy and standards governance, regulatory alignment, metrics reporting, and continuous improvement of the cybersecurity compliance program. Preferred Experience & Skills: Knowledge of IT governance, risk, and compliance processes Understanding of IT control areas such as access management, change management, system operations, cybersecurity governance, and third-party oversight Experience gathering, reviewing, and organizing audit evidence Ability to assess control effectiveness, identify gaps, and support remediation activities Knowledge of frameworks and regulations such as SOX/MAR, NIST CSF, NYDFS Part 500 or CIS Controls Strong analytical, documentation, communication, and stakeholder management skills Experience in GRC, IT audit, IT risk, cybersecurity compliance, or technology controls What Makes You Stand Out: Experience supporting SOX/MAR IT attestations, IT general controls, audits, or control testing Hands-on experience with control walkthroughs, evidence review, deficiency tracking, and audit support Familiarity with IT General Controls, control narratives, process flows, risk registers, GRC tools, and audit management platforms Ability to manage multiple priorities, meet audit deadlines, and drive accountability across teams Duties and Responsibilities: Installs, configures, administers, and analyzes information security technologies, controls, and practices that maintain the confidentiality, integrity, and availability of ERIE's information systems and data assets. Continuously detects, logs, monitors, alerts, and reports on information security controls, exceptions, vulnerabilities, threats, risks, and incidents. Executes actions to protect assets and detect vulnerabilities or threats. Executes actions to respond to and recover from vulnerabilities or threats. Develops and manages relationships with diverse groups of stakeholders at multiple levels. Partners and aligns with cross-functional risk assurance, IT, and business teams across the enterprise to implement, align, and ensure compliance with security measures. Establishes and ensures that security measures are in line with industry standards, best practices, and regulations. Measures and improves the operating rhythm of Information Security as well as the risk posture of ERIE. Advances Information Security controls through maturity assessments, continuous process and automation improvements, appropriate policies/standards/procedures, and capability development. Develops and presents reports, metrics, dashboards, and evidence to stakeholders across the enterprise up to and including leadership and corporate officers. Provides support to end-users on security-related issues. Effectively communicates to and influences stakeholders through oral and written communications. Provides discipline-specific knowledge in support of security awareness and outreach to ensure that information security best practices are understood and followed enterprise wide. Remains current on industry best practices, standards, frameworks, regulations, and emerging security threats through research, training, and participation in industry associations. Makes recommendations for improving the company's security posture. Shares recommendations, knowledge, and relevant content to inform, mentor, or trains others. Capabilities: Collaborates Cultivates Innovation Customer Focus Decision Quality Ensures Accountability Instills Trust Nimble Learning Optimizes Work Processes (IC) Self-Development Values Diversity Qualifications: Minimum Education and Experience Requirements: Bachelor's degree in relevant field and 2 years of related experience; or Associate degree in relevant field and 4 years of related experience; or High School diploma or equivalent and 6 years of related experience, required. Completion of a relevant IT-career preparation program approved by ERIE's Human Resources and IT Talent Optimization Departments if unrelated degree and/or less experience. Relevant certifications and/or military training/service may be considered for equivalent education/experience. Additional Experience: Foundational knowledge and skill associated with at least one Information Security discipline and in at least one IT domain (analysis, engineering, system administration), required. Experience with IT delivery or operational methodologies (agile delivery, SDLC, ITIL), preferred. Critical thinking skills and analytical mindset required. Persuasive communication and interpersonal skills, and ability to convey technical concepts to non-technical stakeholders, required. Ability to participate in on-call rotations and work outside of regular business hours to support cyber event and incident handling may be required. Physical Requirements: Ability to move over 50 lbs using lifting aide equipment; Rarely Climbing/accessing heights; Rarely Driving; Occasional (

Loading
Please wait..!!