Information Security Analyst
About The Role
Participates in projects and assessments as a security consultant or advisor on risk. Researches general and industry specific security trends. Analyzes, defines security policies and information security standards. Provides detail to project teams regarding security requirements. Creates and presents risk reports, policies, results and deliverables. Performs penetration and vulnerability testing, including the delivery & explanation of results. Evaluates, documents and communicates vulnerability ratings and mitigation guidelines.
How does this role make an impact?
- Participates in projects and assessments on risk.
- Analyzes and defines security policies and standards.
- Monitors, alerts and responds to security events.
- Performs computer forensic and investigative activities; and penetration and vulnerability testing.
- Defines and administers identity & access roles and workflows.
Requirements
- Typically requires 7+ years of relevant experience or a combination of related experience, education and training.
- Experience performing information security risk assessments, including documenting risks, evaluating control gaps, and communicating mitigation recommendations to business and technology stakeholders.
- Experience supporting third-party risk management activities, such as vendor due diligence, ongoing monitoring, contract/security reviews, and assessment of supplier control environments.
- Working knowledge of cybersecurity governance, risk, and compliance practices, including the development or maintenance of security policies, standards, procedures, and control documentation.
- Familiarity with common security and regulatory frameworks, such as NIST CSF, NIST 800-53, ISO 27001, CIS Controls, PCI DSS, GLBA, HIPAA, or FFIEC guidance.
- Experience using governance, risk, and compliance platforms or risk assessment tools to manage assessment workflows, document evidence, track risks, and report status.
- Ability to translate technical security findings into clear business risk language for project teams, leadership, auditors, and non-technical stakeholders.
- Experience consulting on technology projects to identify security requirements, assess risk, and recommend practical control improvements.
- Experience supporting audit, compliance, or regulatory exam activities, including evidence gathering, control mapping, management responses, and remediation tracking.
- Strong written and verbal communication skills, with experience creating risk reports, assessment summaries, policies, standards, or executive-level deliverables.
Qualifications
- Professional security, risk, privacy, or audit certifications such as CISSP, CISM, CRISC, CISA, Security+, CEH, or similar.
- Experience assessing risks related to artificial intelligence, cloud services, SaaS platforms, data protection, or other emerging technologies.
- Demonstrated ability to work independently, manage multiple priorities, and collaborate across technology, business, legal, compliance, and vendor management teams.
Pay
Base Pay Range $94,400-$129,800. The base pay range represents the typical range of potential salary offers for candidates hired. Factors used to determine your actual salary include your specific skills, qualifications and experience. In addition to base salary, this position is eligible for a Short-Term Incentive plan.