Haystack
← Back to Jobs
Technology
ST

Business Impact & Information Security Analyst

StefaniniAtlanta, GA🇺🇸United StatesPosted 26 Aug 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Atlanta, GA, United States
Posted
23 hours ago
Stakeholder Management

Job Description

Stefanini Group is hiring!Stefanini is looking for Business Impact & Information Security Analyst in Atlanta, GAFor quick apply, please contact Sudhanshu Shrivastava; Ph: 248 582 W2 Candidates Only!

About Role: We are seeking a versatile Business Impact & Information Security Analyst to join our enterprise risk management team. This dual-focused role combines business continuity planning with cybersecurity operations, making it ideal for a well-rounded contractor who can bridge operational resilience and information security. The successful candidate will assess organizational vulnerabilities from both business impact and security threat perspectives, ensuring comprehensive protection of critical assets and operations.

Key Responsibilities: Organizational Risk & Impact AssessmentLead structured interviews and collaborative workshops with department heads and key stakeholders to identify critical business functions, security requirements, and risk exposureMap critical business functions, workflows, technical dependencies, and security control touchpoints across the organizationDocument operational interdependencies, assess security control effectiveness, and identify single points of failure from both continuity and security perspectivesResearch and analyze emerging cyber threats, vulnerabilities, and attack vectors; assess relevance to organizational operations and business continuity Impact Quantification & Risk AnalysisEvaluate and assign severity scores to potential disruption scenarios resulting from system failures, supply chain outages, or security incidentsAssess financial, operational, legal, and reputational consequences tied to business disruptions and security breachesDevelop integrated risk matrices and impact classification frameworks that address both continuity and security risksCorrelate security events and threat intelligence with business impact scenariosContribute to threat modeling exercises for critical systems and functions Security Controls & Recovery PlanningEvaluate effectiveness of existing security controls and countermeasures through testing aligned with frameworks (NIST, ISO 27001, CIS)Review system configurations against security baselines and hardening standardsAssess cloud security configurations and compliance (AWS, Azure, Google Cloud Platform)Define Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) for core applications and business units, factoring in security restoration requirementsEstablish prioritization criteria for recovery sequencing that incorporates security validation stepsCollaborate with IT, operations, and security teams to validate feasibility of recovery targets and security controls Compliance, Governance & ReportingAssist with security and business continuity audits; provide evidence of control implementationMaintain comprehensive documentation including policies, procedures, runbooks, security controls, and business impact profilesTrack and report on security metrics, business continuity KPIs, and integrated risk indicatorsSynthesize analytical findings into executive-ready dashboards and presentationsDeliver integrated continuity strategies and security recommendations to senior leadershipMaintain updated documentation in alignment with organizational and regulatory standards

Required Qualifications and Skills: EducationBachelor's Degree or 4 years equivalent experience; Bachelor's Degree preferred in Business Administration, Information Technology, Cybersecurity, Risk Management, Data Science, or related fieldMaster's degree or additional certifications preferred Experience3-5 years of experience Core Competencies:Business Continuity:Proven proficiency in business impact analysis methodologies and frameworksStrong understanding of risk assessment principles and practicesExperience with supply chain dependency analysis Information Security:Solid understanding of cybersecurity principles, frameworks, and best practicesKnowledge of common attack vectors, vulnerabilities, and mitigation techniquesExperience with security incident investigation and response proceduresUnderstanding of network protocols, system architecture, and security technologies Universal Skills:Exceptional analytical and critical thinking abilitiesOutstanding communication and stakeholder management skillsAbility to facilitate productive workshops with diverse audiencesStrong problem-solving skills and attention to detailAbility to translate technical concepts for non-technical audiences Technical Tools:Business Continuity:* Experience with enterprise continuity software (ServiceNow BCM or similar platforms)* Proficiency with advanced data collection frameworks and survey tools* Strong command of relational databases, SQL, and advanced spreadsheet functionsInformation Security:* Knowledge of firewall, IDS/IPS, and network security tools* Experience with cloud security tools and CSPM platforms Certifications:Business Continuity (Preferred):Certified Business Continuity Professional (CBCP)CBCI, MBCI, or similarInformation Security (One or more):Certified Information Systems Security Professional (CISSP)GIAC Security Essentials (GSEC)Certified Information Security Manager (CISM)Cloud security certifications (AWS Security Specialty, Azure Security Engineer) Experience3-5 years of combined experience in business continuity, risk management, and/or information securityDemonstrated experience conducting business impact analysesExperience working in regulated industries (finance, healthcare, government) a plusPrevious contractor or consulting experience beneficial Ideal Candidate:The perfect candidate for this role brings a unique combination of business acumen and technical security expertise.

You should be equally comfortable:Facilitating executive workshops on business continuity strategiesPresenting risk findings to C-level stakeholdersResponding to security incidentsDocumenting complex workflows and dependenciesImplementing security controls and conducting assessmentsThis position offers an excellent opportunity for a versatile professional seeking to make impact across both operational resilience and cybersecurity domains. #LI-SS3#LI-HYBRID Stefanini takes pride in hiring top talent and developing relationships with our future employees.

Our talent acquisition teams will never make an offer of employment without having a phone conversation with you. Those face-to-face conversations will involve a description of the job for which you have applied. We also speak with you about the process including interviews and job offers.

About Stefanini Group:The Stefanini Group is a global provider of offshore, onshore and near shore outsourcing, IT digital consulting, systems integration, application, and strategic staffing services to Fortune 1000 enterprises around the world. Our presence is in countries like the Americas, Europe, Africa, and Asia, and more than four hundred clients across a broad spectrum of markets, including financial services, manufacturing, telecommunications, chemical services, technology, public sector, and utilities. Stefanini is a CMM level 5, IT consulting company with a global presence. We are CMM Level 5 company

Similar jobs