Jobs · Information Technology · California

Sr. Information Security Analyst

STAAR Surgical · Lake Forest, CA · 2 wk ago
Information Technology$125k–$160k/yrFull-time

About the role

As a Senior Information Security Analyst within STAAR Surgical’s Information Technology team, you will play a critical role working closely with the business and across the Information Technology organization to define, deliver, and support information security solutions and roadmaps. This position addresses diverse and highly complex information security problems, selects methods and techniques for identifying and advocating effective security solutions, develops approaches to critical issues, and administers schedules and performance requirements.

Responsibilities

  • Define and implement information security strategies and procedures.
  • Work with engineering teams to define and refine information security and systems management policies and settings.
  • Monitor and assess vendor and third-party information security reports and lists.
  • Evaluate new and emerging products and technologies; make recommendations to leadership concerning their introduction.
  • Coordinate, administer, manage, and monitor access control systems, security tools, and intrusion detection systems to identify anomalous events and security infractions that exploit system vulnerabilities.
  • Integrate information security controls into environments to identify risks and reduce their impact.
  • Provide analysis of potential risk to information security and recommend solutions.
  • Create and maintain information security documentation.
  • Communicate information security procedures to users.
  • Review and recommend changes to information security policies, including IT use policies, Data Sensitivity, and Personally Identifiable Information Security Policies and procedures.
  • Understand and apply principles, concepts, theories, technologies, and standards of the professional field.
  • Develop and apply specialized knowledge within the discipline; deepen knowledge through exposure to new assignments and continuous learning.
  • Lead or provide direction for information security projects.
  • Provide complex analysis of potential risk and recommend innovative solutions.
  • Recommend and implement changes to procedures and systems to enhance information systems security.
  • Mentor junior information security personnel.
  • Work on assignments requiring considerable judgment and initiative in resolving problems and making choices, recommendations, or decisions.
  • Regularly exercise discretion and independent judgment on business matters.
  • Perform other duties as assigned.

Requirements

  • Preferred: Undergraduate degree and 2-6 years of relevant experience or Graduate degree and 0-4 years of relevant experience.
  • Highly desirable: Security certifications such as CISSP, CySA+, GCIH, GSEC, Security+.
  • Preferred: 6-8 years of relevant experience or equivalent combination of education and work experience.

Skills

  • Apply research, information gathering, analytical, and interpretation skills to problems of diverse scope.
  • Develop solutions to a variety of problems of moderate complexity.
  • Screen, categorize, evaluate, reconcile, report, and resolve data integrity issues.
  • Interpret generally defined practices and methods; recognize and act on inconsistencies in data or results and escalate unusual problems.
  • Identify issues beyond the stated situation.
  • Competent in security best practices and defense in depth strategies for multiple platforms (e.g., Linux/Unix, Windows, Mac).
  • Competent in staying up to date on common cybersecurity threats, attacks, and TTPs (Tactics, Techniques, and Procedures).
  • Competent in intrusion detection and investigations.
  • Competent in incident handling and reporting.
  • Competent in analyzing host-based and network logs.
  • Competent in analyzing firewall rules and configuration.
  • Competent in public cloud computing platforms.
  • Competent in standard cybersecurity frameworks and implementing security controls.
  • Competent in managing privileged account management (PAM) solutions.
  • Competent in managing vulnerability scanning solutions.
  • Competent in methods of data protection, encryption, and data loss prevention (DLP) solutions.
  • Competent in identity and access management methodology.
  • Competent in automation scripting languages (e.g., PowerShell, Python, Bash).
  • Proficient in developing and managing a security awareness training program.
  • Proficient in managing endpoint protection solutions (EDR/XDR).
  • Proficient in multifactor authentication (MFA) technologies.
  • Proficient in managing email security gateway solutions.
  • Ability to analyze complex security issues, determine their cause and impact, and identify corrective actions to prevent future occurrences.
  • Familiar with database technology and query analysis.
  • Ability to recommend security standards and procedures.
  • Strong verbal and written communication skills; ability to adapt communication to the level and nature of the audience.

Pay

Pay range is $125,000 - $160,000. Final compensation will depend on experience.

Similar jobs

Information Security Analyst SR.

General Dynamics Information TechnologyPanama City, FL· 3 wk ago
Information Technology$78k–$106k/yrapply on gdit.wd5.myworkdayjobs.com