Sr. Information Security Analyst
Johnson & Quin, LLC · Niles, IL · 3 days ago
HybridAnalystFull-time
Responsibilities
- Maintains and enhances security operations, risk management, and security controls.
- Monitors, analyzes, and responds to/leads security events and alerts across security platforms.
- Investigates suspicious activity, determines root cause, and coordinates remediation efforts.
- Tunes and optimizes detection capabilities to improve alert quality and reduce false positives.
- Develops and implements automation to improve efficiency and consistency of security operations.
- Coordinates with security vendors to troubleshoot issues and improve tool effectiveness.
- Participates in/leads incident response activities, including containment, eradication, and recovery.
- Documents incidents, actions taken, and lessons learned.
- Assists in maintaining and improving internal incident response procedures and playbooks.
- Works with internal teams and external vendors to support remediation efforts.
- Conducts vulnerability scanning and risk assessments across systems and environments.
- Prioritizes remediation efforts based on risk and business impact.
- Coordinates patch management activities with IT teams to ensure timely remediation of vulnerabilities.
- Tracks and reports on remediation progress, including vulnerability and patch status across systems.
- Works with internal teams and external vendors to support remediation efforts.
- Supports internal and external audits by gathering evidence and validating controls.
- Develops, maintains, and updates security documentation, including policies, standards, procedures, and operational playbooks.
- Helps ensure alignment with applicable regulatory and industry frameworks.
- Manages day-to-day relationships with security vendors and service providers.
- Serves as a point of contact for vendor support, escalations, and technical discussions.
- Maintains vendor performance to ensure services meet organizational expectations.
- Evaluates and recommends improvements to existing security controls and processes.
- Aids in the implementation, configuration, and optimization of security technologies.
- Supports secure design and configuration of systems in partnership with IT teams.
- Identifies opportunities to automate repetitive security tasks and improve operational efficiency.
- Participates in evaluation and selection of security tools and vendors.
- Collaborates with IT, infrastructure, and business teams to identify and mitigate security risks.
- Provides guidance on security best practices and control implementation.
- Develops and delivers security awareness training programs to promote secure practices across the organization.
Qualifications
- Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field.
- Minimum of 5 years of experience in information security, with at least 3 years of experience in a senior role.
- Proven experience in security operations, risk management, and incident response.
- Experience with SIEM, EDR, email security, and network tools.
- Strong analytical and problem-solving skills.
- Excellent communication and collaboration skills.
- Knowledge of relevant compliance frameworks such as SOC 2, ISO, and familiarity with regulatory requirements.
- Ability to work independently and as part of a team.
- Proficiency in scripting and automation tools.
- Experience with vulnerability assessment and penetration testing.
- Understanding of cloud security principles and practices.
- Experience with security governance and risk management processes.
- Experience with security tool selection and evaluation.
- Experience with security policy development and documentation.