Senior Cyber Security Analyst - Cloud, DevSecOps & AI Security

ISO New England
Holyoke, United States of America
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior
Compensation
$ 150K

Job location

Holyoke, United States of America

Tech stack

Training Data
Kubernetes Security
API
Artificial Intelligence
Amazon Web Services (AWS)
Azure
Cloud Computing
Cloud Computing Security
Configuration Management
Computer Security
Continuous Integration
Data Governance
Information Leak Prevention
Monitoring of Systems
Network Topologies
Identity and Access Management
Phishing
Security Information and Event Management
Software Engineering
Software Vulnerability Management
Data Logging
Enterprise Software Applications
Cloud Platform System
Data Classification
Large Language Models
Generative AI
HybridCloud
AI Platforms
Kubernetes
Information Technology
Machine Learning Operations
Terraform
Devsecops
Vulnerability Analysis

Job description

ISO New England is seeking an experienced Cyber Security Analyst to support and enhance enterprise cloud, infrastructure, AI, and DevSecOps security initiatives. This role is responsible for proactively identifying vulnerabilities, compliance gaps, misconfigurations, and security risks across enterprise systems, cloud platforms, AI/ML environments, CI/CD pipelines, and regulated CIP environments., * Conduct cloud security assessments across AWS and Azure environments, including CSPM, CIEM, IAM, and container security reviews.

  • Integrate and support security controls within CI/CD pipelines and DevSecOps environments.
  • Assess and secure AI/ML systems, generative AI applications, and AI-enabled business solutions throughout their lifecycle.
  • Evaluate risks associated with AI model usage, training data, third-party AI services, and Large Language Model (LLM) integrations.
  • Implement AI governance controls to protect sensitive data and prevent unauthorized disclosure through AI platforms.
  • Develop security guardrails for AI adoption, including data classification, access controls, prompt security, and responsible AI usage.
  • Perform AI threat modeling to identify risks such as prompt injection, data poisoning, model manipulation, model theft, and insecure AI integrations.
  • Perform vulnerability assessments, configuration reviews, and remediation tracking across enterprise and CIP systems.
  • Review and validate baseline configurations, logging requirements, and compliance controls.
  • Evaluate network topology and infrastructure changes to determine CIP impact and SOC visibility requirements.
  • Partner with application development, cloud platform engineering, infrastructure, enterprise architecture, IAM, network, SOC, and business teams to integrate security into system design, projects, and operational processes.
  • Support phishing simulations, security awareness initiatives, AI security awareness training, and audit evidence collection.
  • Provide security recommendations and risk mitigation strategies for cloud, AI, and enterprise environments.
  • Support and maintain enterprise security platforms including CNAPP, EDR, vulnerability management, SIEM, DSPM, and cloud security monitoring tools.
  • Monitor evolving AI security risks, industry standards, and regulatory requirements.

Requirements

The ideal candidate will have strong experience in cloud security, vulnerability management, DevSecOps, AI security, and security compliance, with the ability to collaborate across technical teams to implement and maintain enterprise security standards., * Experience in cybersecurity, cloud security, security engineering, or AI security roles.

  • Experience with AWS and/or Azure cloud platforms.
  • Experience with container orchestration technologies including Amazon ECS and Amazon EKS.
  • Experience implementing security controls within CI/CD and DevSecOps environments.
  • Knowledge of AI security concepts, including securing generative AI applications, LLMs, AI governance, and AI risk management.
  • Familiarity with AI threats such as prompt injection, data leakage, model poisoning, model theft, and insecure AI APIs.
  • Knowledge of vulnerability management, cloud security, IAM, CSPM, and configuration management practices.
  • Experience with security monitoring and logging platforms.
  • Familiarity with Terraform, infrastructure-as-code, and policy governance frameworks such as OPA.
  • Understanding of data governance, data protection, and responsible AI principles.
  • Strong analytical, troubleshooting, communication, and collaboration skills.
  • Self-starter with the ability to work independently in a fast-paced environment.

Desired not required

  • Bachelor's degree in information technology, Cybersecurity, Computer Science, or related field.
  • Advanced degree such as a Master's in Cybersecurity Management, Information Assurance, Artificial Intelligence, or related fields.
  • Industry cybersecurity, cloud security, and AI security certifications preferred, including

Benefits & conditions

Pulled from the full job description

  • Tuition reimbursement
  • AD&D insurance
  • 401(k)
  • Health insurance
  • Paid time off
  • Vision insurance
  • Health savings account, * Competitive compensation with a base salary + performance bonus
  • Robust benefits package, including:
  • Enhanced 401(k) and financial planning support
  • Tuition reimbursement and professional development
  • Wellness programs, including an onsite gym
  • Flexible work hours
  • Employee Business Networks
  • Free coffee at our onsite café
  • Hybrid work environment (3 days/week onsite)
  • Distance-based relocation assistance available
  • 5/6 person paid on-call rotation, * Amazon Web Services Certified Security - Specialty
  • Microsoft Azure Security Engineer Associate (AZ-500)
  • ISC2 Certified in AI Security (when available)
  • OWASP AI Security and LLM Security knowledge/training

This employer will not sponsor applicants for work visas for this position (ex: H-1B, F-1/CPT/OPT, O-1, E-3, TN, J, etc.).

The expected salary range for this position is $127,000 - $150,000 per year. This role is also eligible for an annual performance bonus, comprehensive health insurance (medical, dental and vision), flexible spending and health savings accounts, a 401(k) plan with generous employer contributions and a student debt benefit, life and AD&D insurance, disability insurance, critical illness and hospital indemnity benefits, paid time off, paid leave, a wellness program, an employee assistance program and other great company perks.

About the company

ISO New England is the independent system operator responsible for ensuring the safe and reliable flow of electricity in our region and planning for the future of the electric grid. We are at the forefront of New England's ongoing transition to clean energy.

Apply for this position